Ransomware is no longer just a cyber issue - it encompasses business continuity, regulatory exposure and legal risk at board level. In many jurisdictions, ransomware payments are already restricted under sanctions, anti-money laundering and counter-terrorism laws. Some governments are now considering explicit payment bans.
Response strategies must reflect these evolving legal constraints and the increased exposure they create in a crisis. Organisations should consider in advance how they would respond, including whether they would pay a ransom, who would authorise it and how a payment would be executed in practice.
In an increasingly interconnected economy, a single ransomware incident can disrupt operations, impact supply chains and damage customer trust at scale and materially affect market value. Ransomware activity continues to increase, with significant financial and operational consequences for organisations worldwide.
As attacks grow in scale and complexity, regulatory scrutiny is intensifying. New legislation and technical standards are raising compliance thresholds, expanding reporting obligations and increasing the risk of enforcement including, in some cases, direct legal liability for senior management. Boards and senior management must understand their responsibilities and be prepared to make rapid, high-impact decisions under significant time pressure.
The first hours of an incident are often decisive, triggering critical operational, legal and regulatory decisions.
What the handbook covers
- Anatomy of a ransomware attack
Understand how attacks develop, including emerging threats such as double and triple extortion. - Preparation and resilience
Some practical steps to strengthen cybersecurity, governance and incident readiness and supply chain resilience. - Response and recovery
Some key actions to take after becoming aware of an incident in order to manage disruption and legal exposure including containment, communications and regulatory engagement. - Global legal considerations
An overview of key legal and regulatory obligations across a number of jurisdictions.
Ransomware Handbook
The full handbook provides a detailed legal analysis and practical guidance to help organisations navigate ransomware risk across jurisdictions.
❯
Ransomware: key questions
- What is a ransomware attack?
A ransomware attack is a form of malicious activity where attackers disrupt access to systems or data and demand payment, often combining encryption with data theft and extortion. - Why is ransomware a legal and regulatory issue?
Incidents frequently trigger reporting obligations, regulatory scrutiny, enforcement risk, contractual liabilities and potential sanctions issues for organisations across multiple jurisdictions. - Should organisations pay a ransom?
There is no simple answer. Organisations must assess legal restrictions, sanctions risks, regulatory obligations, reputational impact and whether viable recovery alternatives exist. Payment does not remove regulatory obligations and offers no guarantee of data recovery or non-disclosure. - What should organisations do after an attack?
Immediate priorities include activating incident response plans, containing the threat, preserving evidence and assessing and complying with legal and regulatory obligations (including in relation to incident reporting) across affected jurisdictions. Public communications should be carefully considered in advance and controlled at the time in order to avoid prejudicing legal claims or creating inconsistencies with regulatory disclosures.