In December 2023, the UK’s Joint Committee on the National Security Strategy (JCNSS) published a report entitled โA hostage to fortune: ransomware and UK national securityโ. It gave the UK Government two months to respond to criticism that responsibility for ransomware strategy should be moved from the Home Office where โclear political priorityโ was โgiven instead to other issues, such as illegal migration and small boatsโ.
Instead, the report said, ransomware strategy should switch to the Cabinet Office, in partnership with the National Cyber Security Centre (NCSC) and National Crime Agency (NCA).
The UK Government has now responded – and it’s fair to say that the JCNSS is not impressed. In its published response, Dame Margaret Beckett MP, the chair of the JCNSS committee, accused the Government of operating an โostrich strategyโ and not knowing โthe extent or costs of cyberattacks across the countryโ.
UK Government response to the JCNSS
That Government response runs to some 6,000 words, and its rebuttal to the JCNSS recommendations is clear throughout.
Take, for example, the transfer of responsibility for ransomware strategy away from the Home Office.
โThe Home Office leads the cross-government ransomware work under the Threat Pillar of the National Cyber Strategy which is overseen by the Deputy Prime Minister, and works very closely with the MoD and FCDO and the wider community, including law enforcement and the UK intelligence agencies, who also play a significant role in the response to ransomware,โ the response states.
It concludes: โThere are currently no plans to change this arrangement, and the Home Office remains the lead Department for overall crime.โ
JCNSS response to the UK Government
Safe to say that the JCNSS is not swayed by the UK Government’s arguments.
Beckett states: โIf the Government insists on operating the ostrich strategy for national cyber-security based on legislation made before the internet arrived, centered on a Department that seems to have difficulty mustering much interest in the issue, and in stark contrast to the cyber-attackers who are so fantastically well co-ordinated and resourced, where is the pro-active national security response to protect the UK supposed to come from?โ
A good question. So what do the experts think?
โThis was a damning report on the Government, and the response to its findings raise further alarms,โ says Mike Newman, CEO of My1Login. โIf the findings in the report are correct, it sounds like the UK is highly vulnerable to a devastating ransomware attack.โ
Newman warns that an attack targeting utilities, for example, would be a cyber-wake-up-call. โWhile some public sector and government organisations are leading the way in prioritising their defences against cybercriminals, there is still a long way to go. Burying heads in response to the threat is not the answer.โ
Related: UK law enforcement agency issues warning about AI-aided ransomware
Payment of ransoms
The Government response to the JCNSS report also addresses concerns over payment of ransoms. It states that both the NCSC and the NCA will โcontinue to support the Home Office in developing proposals to achieve a reduction in ransom paymentsโ.
However, this stops short of the recommendations of some leading cybersecurity experts, including Ciaran Martin, the founding CEO of the NCSC and current professor of practice at the Blavatnik School of Government, University of Oxford, to ban ransomware payments by law.
Writing in The Times, Martin compared ransomware actors to the โheyday of al-Qaeda, Islamic State and their murderous thugsโ when ransom payments to terrorists were banned by the UK and US. โThis hard-headed approach stands in contrast to the apparently sanguine attitude of British policymakers to the computer thugs hanging out in Russia. Their business is not kidnapping humans, but computer networks and data.โ
However, that this is a complex problem cannot be denied and a ransomware ban could be painful to more than just the ransomware gangs.
โBeing stuck between a rock and a hard place is no position any company wants to be in but if the law is directing only one way, then companies can easily fold and the potential of livelihoods lost can make this a damming and forced decision,โ warns Jake Moore, a Global Cybersecurity Advisor at ESET. โAlthough the long-term effects of banning ransom payments may sound idyllic, the path needed to navigate all companies to this ideal is going to be challenging, if not impossible.โ
You might also be interested