Cyber security and data watchdogs ask lawyers to help stop ransomware payments

15 July 2022, 11:13

A laptop screen showing a computer virus warning
Computer virus stock. Picture: PA

The NCSC and ICO have written to the Law Society, asking it to remind its members that the firms do not condone paying ransomware demands.

Solicitors have been asked by the UK’s cyber security agency and data protection watchdog to not encourage clients to pay ransomware demands.

The National Cyber Security Centre (NCSC) and Information Commissioner’s Office (ICO) said they are concerned by a recent rise in ransomware payments – where victims of cyber attacks pay a fee in the hope that their data will be released back to them.

The two organisations have written to the Law Society to ask it to remind members of their official cybersecurity guidance, which is that paying a ransom will not keep data safe or be viewed by the ICO as a mitigation in regulatory action.

The NCSC and ICO said they believe that in some cases solicitors may have advised clients to pay a ransom in the belief that it would ensure any affected data was safe or that it could lead to a lower penalty from the data regulator – both of which are not the case.

The watchdogs said they do not encourage or condone paying ransoms because they can further incentivise criminals and do not guarantee that files are returned.

Ransomware is a type of cyber attack that involves criminals gaining access to an organisation or individual’s files and encrypting them before demanding money in exchange for their return.

NCSC chief executive Lindy Cameron said: “Ransomware remains the biggest online threat to the UK and we do not encourage or condone paying ransom demands to criminal organisations.

“Unfortunately we have seen a recent rise in payments to ransomware criminals and the legal sector has a vital role to play in helping reverse that trend.

“Cyber security is a collective effort and we urge the legal sector to work with us as we continue our efforts to fight ransomware and keep the UK safe online.”

The two firms said if an organisation is hit by a cyber attack it should report any ongoing incident to Action Fraud and the ICO and NCSC as appropriate, with law enforcement then able to mitigate the impact of the attack.

Information Commissioner John Edwards said: “Engaging with cyber criminals and paying ransoms only incentivises other criminals and will not guarantee that compromised files are released.

“It certainly does not reduce the scale or type of enforcement action from the ICO or the risk to individuals affected by an attack.

“We’ve seen cyber crime costing UK firms billions over the last five years. The response to that must be vigilance, good cyber hygiene, including keeping appropriate back-up files, and proper staff training to identify and stop attacks. Organisations will get more credit from those arrangements than by paying off the criminals.

“I want to work with the legal profession and NCSC to ensure that companies understand how we will consider cases and how they can take practical steps to safeguard themselves in a way that we will recognise in our response should the worst happen.”

By Press Association

More Technology News

See more More Technology News

LG AeroCatTower (Martyn Landi/PA)

The weird and wonderful gadgets of CES 2025

Sinclair C5 enthusiasts enjoy the gathering at Alexandra Palace in London

Sinclair C5 fans gather to celebrate ‘iconic’ vehicle’s 40th anniversary

A still from Kemp's AI generated video

Spandau Ballet’s Gary Kemp releases AI generated music video for new single

DragonFire laser weapon system

Britain must learn from Ukraine and use AI for warfare, MPs say

The Pinwheel Watch, a smartwatch designed for children, unveiled at the CES technology show in Las Vegas.

CES 2025: Pinwheel launches child-friendly smartwatch with built in AI chatbot

The firm said the morning data jumps had emerged as part of its broadband network analysis (PA)

Millions head online at 6am, 7am and 8am as alarms go off, data shows

A mobile phone screen

Meta ends fact-checking on Facebook and Instagram in favour of community notes

Mark Zuckerberg

Meta criticised over ‘chilling’ content moderation changes

Apps displayed on smartphone

Swinney voices concern at Meta changes and will ‘keep considering’ use of X

sam altman

Sister of OpenAI CEO Sam Altman files lawsuit against brother alleging sexual abuse as child

OpenAI chief executive Sam Altman with then-prime minister Rishi Sunak at the AI Safety Summit in Milton Keynes in November 2023

OpenAI boss Sam Altman denies sister’s allegations of sexual abuse

A super-resolution prostate image

New prostate cancer imaging shows ‘extremely encouraging’ results in trials

Gadget Show

AI will help workers with their jobs, not replace them, tech executives say

Zuckerberg said he will "work with President Trump to push back on governments around the world that are going after American companies and pushing to censor more”.

Meta’s ‘chilling’ decision to ditch fact-checking and loosen moderation could have ‘dire consequences’ says charity

Twitter logo

X boss Linda Yaccarino praises Meta’s decision to scrap fact checkers

People walk by the Las Vegas Convention Centre

Smart home tech, AI and cars among central themes as CES 2025 prepares to open