Summary
This guidance has been jointly developed by the insurance industry bodies ABI, BIBA, IUA and the NCSC. It is for organisations experiencing a ransomware attack and the partner organisations supporting them. It aims to minimise the overall impact of a ransomware incident on an disruption and cost to businesses the number of ransoms paid by UK ransomware victims the size of ransoms where victims choose to pay The NCSC and the insurance industry bodies recommend victim organisations review the following guidance before paying a ransom to a criminal group. This guidance is general in nature and does not override specific laws and regulations that may apply. The ultimate decision whether to pay the ransom is Being prepared for any incident is key and will help lessen the impact if one happens. The NCSC offers comprehensive guidance, including how to develop an incident management capability and prevent ransomware in the first place.