Ransomware Response: A UK CISO’s 72-Hour Reporting Checklist
UK CISOs facing a ransomware attack must contain it, notify the NCSC within 24 hours, and submit a full report within 72 hours once the Cyber Security and Resilience Bill takes effect. That timeline turns incident response from an internal judgement call into a regulated countdown.
The Bill, which cleared the Commons in June 2026 and is now moving through the House of Lords with Royal Assent expected later this year, extends NIS-style reporting duties to a far wider set of organisations, including managed service providers and data centre operators. Ransomware is explicitly named as a qualifying incident. Boards that treat this as a legal-team problem are missing the point: the clock starts the moment the security operations centre confirms an attack, not when lawyers are briefed.
What Changes Under the Cyber Security and Resilience Bill?
The Bill introduces a two-stage duty: a “light-touch” initial notification within 24 hours of detection, followed by a full report within 72 hours, submitted simultaneously to the sector regulator and the NCSC. Qualifying incidents include ransomware, data breaches, service disruptions exceeding four hours for critical services, and supply chain compromises. Non-compliance carries penalties of up to £10 million or 2% of global annual turnover, whichever is higher — comparable in scale to UK GDPR enforcement.
Notably, the Bill omits the ransom-payment ban for critical national infrastructure operators that government previously proposed. Reporting, not prohibition, is the mechanism ministers now intend to use to gain visibility over the true scale of ransomware losses across the UK economy.
Executive Action:
- Confirm which entities in your group fall in scope — the “essential” and “important” service designations extend well beyond the original NIS regulations.
- Name an individual accountable for the 24-hour notification before an incident occurs, not during one.
- Brief your regulator relationship manager on your reporting process ahead of Royal Assent.
What Should Happen in the First 24 Hours?
Detection triggers two parallel workstreams: technical containment and regulatory notification. Isolate affected systems, preserve forensic evidence before rebuilding anything, and activate your incident response retainer immediately — renegotiating one mid-attack costs time you do not have. The 24-hour notification does not require a root-cause finding; it requires enough detail for the NCSC and regulator to understand that a qualifying incident has occurred and triage its severity.
In parallel, legal counsel should assess data protection exposure. A ransomware attack involving personal data can trigger a separate 72-hour notification duty to the ICO under UK GDPR, running concurrently with the Bill’s own timeline — two clocks, not one.
Executive Action:
- Pre-agree a notification template with legal and the CISO function so the 24-hour filing is a fill-in-the-blanks exercise, not a drafting exercise.
- Confirm your cyber insurance policy’s incident response provisions before an attack — see our companion briefing on cyber insurance readiness.
- Establish who briefs the board within the first 24 hours and what they need to know.
What Must the Full 72-Hour Report Cover?
The full report goes further than the initial notification: scope of systems and data affected, likely root cause where established, remediation actions taken, and the organisation’s assessment of ongoing risk to service continuity. Regulators increasingly expect this report to demonstrate a functioning incident response plan was already in place, not one improvised under pressure.
According to the UK government’s Cyber Security Breaches Survey, 43% of UK businesses identified a cyber attack in the past 12 months, yet a much smaller share report having a formal, tested incident response plan. That gap between exposure and preparedness is precisely what the 72-hour report is designed to expose.
Executive Action:
- Map, in advance, which systems hold your organisation’s crown-jewel data so scope assessment during an incident is fast, not forensic guesswork.
- Run a tabletop exercise against the 24/72-hour timeline specifically — most existing IR plans were not built around it.
- Use our project review checklist to pressure-test whether your current plan would hold up against regulatory scrutiny.
Should the Organisation Pay the Ransom?
Law enforcement and the NCSC continue to discourage ransom payment, and the data increasingly supports that position. According to Sophos’s 2026 State of Ransomware report, only 17% of UK organisations hit by ransomware paid the ransom in the past year, down from 27% in 2024, with 57% recovering primarily from backups instead. Paying also does not guarantee full data recovery and can prolong regulatory scrutiny, since insurers and regulators alike now ask harder questions about why payment was the chosen path.
The decision sits with the board, not IT, and should be pre-agreed in principle — including thresholds, sign-off authority, and law enforcement liaison — long before an attacker forces the question. For the connection between this decision and the wider payment debate, see our earlier briefing on the UK ransomware payment ban.
Executive Action:
- Agree, in advance, who has authority to approve a ransom payment and under what circumstances — do not decide this for the first time mid-incident.
- Test backup recovery time objectively, not theoretically; a backup that takes three weeks to restore is not a real alternative to paying.
- Engage the National Crime Agency early if payment is under consideration; law enforcement liaison is a mitigating factor regulators look for.
How Should CISOs Prepare Before the Bill Takes Effect?
Royal Assent is expected before the end of 2026, but the operational gap is closing faster than most incident response plans are being updated. CISOs should treat this quarter as the deadline, not the eventual commencement date, given how long meaningful tabletop testing and retainer renegotiation actually take.
Executive Action:
- Update your incident response plan explicitly against the Bill’s 24/72-hour structure and circulate it to the board, not just the security function.
- Schedule a board-level tabletop exercise before year end — our tools and assessments can help structure the scenario.
- Revisit third-party and managed service provider contracts to confirm they can meet your notification timeline, not just their own.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
The Bill cleared the Commons in June 2026 and is in the House of Lords, with Royal Assent expected later in 2026. Commencement dates for specific duties typically follow months after Royal Assent, so CISOs should prepare now rather than wait for a firm date.
Qualifying incidents include ransomware attacks, data breaches, service disruptions exceeding four hours for critical services, and supply chain compromises affecting essential or important service providers, including managed service providers and data centres.
No. The Bill omits the ransom-payment ban for critical national infrastructure operators that government previously proposed. Instead, it mandates reporting of qualifying incidents, giving regulators and the NCSC visibility into ransomware activity without prohibiting payment outright.
Non-compliance with the notification duty carries penalties of up to £10 million or 2% of global annual turnover, whichever is higher. Regulators are also likely to view a missed deadline as evidence of an inadequate incident response plan during any subsequent investigation.
