Commons Sense

House of Commons · General Debate

Cyber Extortion and Ransomware (Reporting) 2025-10-21

21 October 2025 · 1 other contributor

Opened by Bradley Thomas Con Bromsgrove

Summarised by AI from the official record, so it can contain mistakes.

At a glance

Bradley Thomas raised concerns about cyber extortion and ransomware (reporting) 2025-10-21 in the House of Commons. Other MPs contributed to the debate.

Key points

  • The National Cyber Security Centre reported a 50 percent increase in highly significant British cyber-incidents over the past year.
  • Hostile states such as China and Iran are cited as major concerns by UK IT leaders.
  • The proposed Bill would require companies to report cyber extortion or ransomware attacks within 72 hours and disclose any payments made.

How the debate unfolded

MPs spoke in turn to share their views and ask questions. Here's what each person said.

Opened the debate

Bradley Thomas Con Bromsgrove

I beg to move, That leave be given to bring in a Bill to require a company that meets a specified criteria to report any cyber extortion or ransomware attack on the company to the Government within a specified time after the attack; to make provision about the content of such reports, including a requirement to provide information about any payments made; and for connected purposes. The National Cyber Security Centre has reported a 50% increase in British cyber-incidents deemed “highly significant” over the past year. Among the threats are hostile states like China and Iran. UK IT leaders cite these nations as major concerns, with recent espionage trials highlighting state-sponsored cyber-operations. Current legislation lacks requirements for companies to disclose ransomware payments. The Bill would mandate reporting of attacks within 72 hours and any payment made thereafter, capturing approximately 78% of medium-sized businesses and all large corporations. It includes legal protections for companies reporting incidents.

Other contributors (1)
  • Bradley Thomas Con Bromsgrove

    The threat from cyber-attacks is undeniable, with a 50% increase in significant incidents reported by the NCSC and major concerns raised by UK IT leaders about hostile states like China and Russia. Current legislation has gaps that allow ransom payments to go unreported, potentially fuelling greater threats. The Bill aims to mandate reporting of attacks and payments within strict timeframes, providing vital intelligence for security agencies while offering legal protections against reputational damage. Non-compliance would face civil penalties.

Get updates like this by email
▸ Assessment & feedback
Summary accuracy