Gregg Wallace sacked by BBC: Businesses must take a strong stance against workplace misconduct

Posted on: July 9th, 2025 by Natasha Cox

Following the news that presenter Gregg Wallace has been sacked by the BBC over an inquiry into alleged misconduct, Solicitor Becci Collins comments on the importance of businesses taking strong and immediate action against inappropriate behavior in the workplace.

Becci’s comments were published in Personnel Today, 9 July 2025, and can be found here.

Becci Collins, a solicitor in the employment team at Lawrence Stephens, said Wallace’s dismissal was “a stark reminder that inappropriate workplace behaviour will not be tolerated.

“However it is concerning that individuals have reported concerns about his behaviour for many years without action being taken.

“Employers must do better in complying with their obligations to employees, particularly in relation to their obligation to prevent sexual harassment in the workplace.

“The reputation and seniority of the individuals about whom complaints are made must have no bearing on how those complaints are investigated, what outcomes are reached or the punishments meted out to those who violate the law on harassment and discrimination.”

To find out more about employer obligations and how we can help, please click here

Ban on non-disclosure agreements: victory or vanity?

Posted on: July 9th, 2025 by Natasha Cox

The government’s press release of 8 July 2025[1] sets out its proposal to amend the Employment Rights Bill (‘ERB’) to introduce a statutory ban on employers using non-disclosure agreements (‘NDAs’) in cases where an employee alleges harassment, sexual harassment or discrimination.

While the ERB already contained a variation to the Employment Rights Act 1996 to extend the scope of whistleblowing legislation to include allegations of sexual harassment, this new amendment could completely rewrite the rules on how employers deal with claims of harassment and discrimination by employees. But is it really the glorious victory campaigners make it out to be?

What is an NDA?

In employment law, NDAs are most commonly used in the form of a confidentiality clause. They are found in a number of employment-related documents, including contracts of employment.

It has also been standard practice for some time that settlement agreements entered into between employers and employees (either on termination of the employee’s employment or as part of the settlement of an ongoing Employment Tribunal claim) include a confidentiality clause preventing the disclosure of the existence of the settlement agreement. Crucially, they also prevent the disclosure of the circumstances leading up to the settlement agreement. This has traditionally been one of the biggest benefits for employers, allowing them to minimise the risk of adverse PR arising from Employment Tribunal claims. So why would the government take that benefit away?

The government’s rationale

The current proposal is not to ban NDAs in their entirety. However, their use will be severely curtailed in that they will be barred in cases of discrimination and harassment. 

There are existing mechanisms in place that restrict the use of NDAs. For example, any attempt to prevent an employee from making a protected disclosure under whistleblowing legislation (for example reporting a criminal offence to the authorities) is unenforceable. There has also been non-statutory guidance published by the Equality and Human Rights Commission[1] in place since 2019 on the use of confidentiality agreements in discrimination, harassment and victimisation cases. However, these protections have been criticised as too weak and that is why the government has tabled this amendment to the ERB. Campaigners say that NDAs have been misused for too long, ‘silencing’ victims of discrimination and harassment by preventing them from speaking about their experiences in the workplace. High profile cases such as that of Zelda Perkins (an ex-assistant of Harvey Weinstein) who has fought the NDA she signed for the last eight years, highlight why campaigners felt this change was needed.  

Effect on settlement agreements

If passed, the ban will mean that any NDAs that seek to prevent an employee disclosing an allegation of harassment, sexual harassment or discrimination will be unenforceable.

While this change will affect the use of NDAs in any employment documentation, the change will be most keenly felt in relation to settlement agreements.

These agreements have an important place in settling employment disputes, providing certainty and closure for both employees and employers. There is a risk that the government’s proposal will place employees at a disadvantage because employers may be less inclined to enter into settlements when they no longer have the comfort that the circumstances complained of, and any settlement reached, will remain confidential. This may force employees to pursue their claim via the Employment Tribunal, a process which is expensive and arduous, particularly due to the extreme delays within the Tribunal service. For these reasons, the government is unlikely to achieve its aim of ensuring that employees are no longer forced to suffer in silence because instead they may be forced to either walk away with nothing, or simply ‘put up and shut up’.

That said, if the ban on NDAs does come into force, settlement agreements will remain an important mechanism for employers in dealing with employment disputes because:

  • With the current Tribunal backlog, the average time from issuing a claim to a final hearing is over a year (and more commonly, over 18 months in cases of discrimination). This means that seeing cases all the way through the Tribunal process will result in significant legal costs.
  • In addition, litigation is distracting and time consuming, sucking up resources that could be used elsewhere.
  • Key witnesses may have left the business prior to a final hearing, meaning the company won’t be best placed to defend itself.
  • The ERB is a significant overhaul of employment legislation and creates several ‘Day 1’ rights for employees, including protection against unfair dismissal, which will further increase the wait time for Employment Tribunal claims.
  • In matters not involving allegations of harassment, sexual harassment or discrimination, the ban has no effect.

When will this be implemented?

The government’s July 2025 roadmap for implementing the ERB[2] describes a phased approach to implementation. Some changes will take effect on the day the ERB is given Royal Assent, while others will take effect from April 2026 and October 2026. It is not yet known when this amendment, if passed, will take effect, but it would be no later than 2027.

Get in touch if you require further guidance on the use of NDAs or in relation to allegations of harassment, sexual harassment or discrimination.

[1] Government Press Release: Press release: Ban on controversial NDAs silencing abuse

[2] Implementing the Employment Rights Bill – Our roadmap for delivering change

 

 

 

DEI in Real Estate Finance: How Diversity, Equity & Inclusion Are Reshaping the Sector

Posted on: July 9th, 2025 by Ella Darnell

Director Rachel Coulthard comments in Private Equity and Real Estate (PERE) Magazine on diversity, equity, and inclusion in the real estate finance space.

Rachel’s comments were published in PERE, 1 July 2025, and can be found on page 69 of the issue, here.

“There has been a massive increase in the prevalence of DEI awareness. Many organisations have implemented regular training and promoted conversations about the impact of language towards women and minority groups, for instance knowing not to use infantilising language towards women.”

“Investors and managers are now accepting that DEI is not just important to promote inclusive workplaces, but also vital to attract and retain employees. The best want the best, and by any measure, equality is what is best. For instance, we have created a Gender Equality Network, which seeks parity between the sexes. This includes goals such as increasing our proportion of women directors and striving for equal pay for employees, regardless of gender.

“I lead our Women in Real Estate Finance initiative, which spotlights the incredible work being done by women in the sector and creates further opportunities for women, both by building networks of like-minded individuals and by giving more junior women in the field mentoring and educational growth opportunities.”

“While progress has been achieved, it has not been without hurdles and occasional setbacks. Most notably, there has been a social and political backlash to DEI in the United States, and many major law firms, corporations, and other non-government bodies have either lessened their emphasis on DEI or removed it entirely. Furthermore, the increase and normalisation of toxic masculinity among influencers has shifted the landscape for younger generations. These trends are deeply troubling, and all those who believe in and fight for equality and inclusion need to stand their ground amidst the current climate.” 

Why Agile Leadership Is Key to Law Firm Culture and Expansion

Posted on: July 3rd, 2025 by Natasha Cox

Chief Operating Officer Johnny Nichols comments in Legal Practice Management magazine on how Lawrence Stephens’ strong people-first culture, and focus on developing an effective leadership model, has enabled the firm’s continued growth and development.

Johnny’s comments were published in People Management Magazine’s July edition, and can be found here.

How would you describe your firm’s current leadership model? 

“Our leadership model is both flat and lean. Flat in that we have a number of departments focused on particular legal disciplines and markets, but all with a say in the management and direction of the firm. Lean in that there are few lawyers who have time targets devoted to this.

“There are essentially three layers of leadership: the Senior Directors, who own the firm, Directors, who lead on the legal services we offer, and the Executive Committee who take day-to-day decisions on behalf of the firm.

“A flat and lean organisational structure, with fewer management layers, offers several benefits including faster decision-making, improved communication, increased employee autonomy, and a more agile response to changes with little need for consensus building. This makes us more agile and able to take advantage of opportunities where other firms may struggle. A recent example of this was the recruitment of a Real Estate team from Memery Crystal during its recent crisis, from under the noses of several larger firms. We were able to meet with and agree terms quickly and decisively, which resonated well with those teams affected.

“However, we recognise that this flat structure may become unwieldy as the firm grows and more streamlining may be required.”  

Have you considered or introduced new roles to lead certain aspects of your firm?

“Having recognised the need for growth and the limitations of Directors undertaking these roles (with neither the time nor the expertise) the firm took the decision to firstly recruit a Chief Operating Officer (me) to take the lead on the establishment of a fully functioning and appropriately empowered Business Services team. This included a new Head of Learning and Development, Head of Risk and Compliance, and more recently a Chief Finance Officer. As law firms become more sophisticated and the level of compliance and regulation has increased, law firms have had to recruit specialists into these roles in order to meet these. Having these people on board also relieves fee earners from tasks they were fundamentally ill-equipped for anyway, allowing them to focus on their fee earning roles.”

What steps is your firm taking to develop business and leadership skills among fee earners?

“Fee earners are not taught this at law school and to expect them to be able to just pick this up ‘on the job’ is unrealistic. Developing business and leadership skills through formal programmes is then really important and we are providing more training for line managers on their role, enabling them to better support and motivate staff.

“Formal programmes now exist to offer firmwide DEI training, and regular ‘lunch and learn’ events foster a collaborative, knowledge sharing environment. These often involve using existing expertise at the firm to upskill others, which in itself is a developmental activity. On top of these firmwide approaches, targeted groups now have new training programmes to support through crucial periods of their career, for example at Senior Associate level. More bespoke training is also available, including targeted coaching for staff where required.”

Succession planning is a common challenge among SME firms – how is yours preparing the next generation of leaders? 

“Recognising the limitations of the lockstep model, our firm has already moved away from this and is now constituted as a limited company. A limited company provides a more structured framework for managing the business, with clear roles for directors and shareholders, which is beneficial in a larger firm with complex operations.

“In terms of diversity, we work hard to ensure that everyone at our firm is treated fairly and equally. This includes our recruitment processes, career development, recognition and reward. As part of this initiative, the firm has agreed a target of 25% females in Directorship by 2026, and we look set to achieve this target by next year.”

How important is it for firms to shift focus away from individual performance exclusively? What practical steps are you taking to encourage effective collaboration?

“We have hosted a number of training sessions over the last year for cohorts at different stages of their careers which included discussions on the themes raised in the DCM Insights research.  We recognise the need for effective collaboration across all our activities and our own efforts to encourage this include a move away from purely  ‘X times salary’ targets for individuals. These are now considered at department level and budgets set to support work being fed down to more junior levels and to allow time for more managerial/strategy work for those more senior.

“When it comes to feeding back, individual reviews are still seen as important, but should always be considered in the wider picture, and 360 degree feedback is encouraged.”

Looking ahead to 2030, what defining leadership qualities or frameworks will separate thriving firms from struggling ones?

“Many firms talk about their unique culture being the key to their success. There is considerable evidence to support the view that a strong and distinct culture can lead to increased revenue, employee satisfaction, and improved client satisfaction. Against this positive backdrop, there is also growing evidence of increasing consolidation of law firms and potentially increasing external investment in law firms in the lead up to 2023. Both these themes introduce a level of change and potential disruption and it’s my view that only firms with a strong and engaged leadership will be able to maintain and develop a positive culture in the light of such change in what is regarded as vital to a thriving firm.

“So, looking ahead, I think that the most important quality for successful law firm leaders will be the ability to not only maintain and manage an existing culture, but be able to adapt to external influence brought about through combining teams and firms, and the involvement of any external investors along the way.”.

To find out more about our story, values and management approach, please click here

 

FCA Widens Scope of Non-Financial Misconduct Rules

Posted on: July 3rd, 2025 by Natasha Cox

Senior Associate Emma Cocker comments on the FCA’s announcement that it will treat bullying and harassment as serious ‘non-financial misconduct’ across all regulated firms – not just banks.

Emma’s comments were published in Personnel Today, 2 July 2025, and can be found here.

“For too long there has been a mismatch between what the FCA’s rules say about non-financial misconduct and what has actually been said and done about such behaviour.

“Under these new guidelines, poor personal behaviour will be treated in the same way as financial misconduct, meaning it will need to be shared in regulatory references to the FCA. As such, it will be much harder for individuals to move from firm to firm to escape their disrepute.

“In addition to the implications on individuals, the new rules will help the regulator to spot cultural failings in firms, which in turn helps to identify instances of poor decision making and risk management, both of which are vitally important qualities in this industry.”

For more information on our employment services, please click here

How to Protect Your Reputation During Major Legal Disputes

Posted on: July 3rd, 2025 by Natasha Cox

Director Dominic Holden comments in City AM on how managing media narratives during litigation can be crucial in helping clients protect their reputation and limiting commercial damage.

Dominic’s comments were published in City AM, 3 July 2025, and can be found here.

“Complex and high-stakes litigation often involves serious allegations being made which are then reported on by the press long before any Judgment is handed down. Winning in court is important, but so too is managing the court of public opinion.

“Letting the narrative run against a client in the lead up to trial can be incredibly damaging to senior management, stakeholders and share price. The adverse news (which may have been generated with the aid of the other side’s PR advisors) can even find its way into evidence and be used to support the other side’s arguments.

“Careful use of PR advisers to ensure the client’s position is fairly reflected in the media is a valuable tool to help avoid a client’s claim from being unfairly prejudiced, and to protect the client’s wider commercial interests.”

To find out more about our litigation and dispute resolution services, please click here

Sports Law Spotlight: Lions Warn Rugby Australia Over Potential Contract Breach

Posted on: June 30th, 2025 by Ella Darnell

Senior Associate William Bowyer comments on the dispute between the British and Irish Lions and Rugby Australia, and discusses whether this could escalate into legal action over breach of contract.

Will’s comments were published in City AM, 23 June 2025, and can be found here.

“If, as Lions CEO Ben Calveley states, the formal tour agreement between the British and Irish Lions and Rugby Australia includes a specific clause governing which Test players must be released to participate in fixtures leading up to the Test series, not just the Tests themselves, then the Lions would likely have grounds for a breach of contract claim.

“An international sports dispute would have to be carefully considered from a jurisdictional standpoint and the contract will likely contain a clause dealing with which laws and courts or private arbitration house would consider the issue.

“With major commercial stakes – from broadcast rights to sponsorship and ticketing – both parties are under pressure to find a swift, negotiated resolution, while leveraging their respective contractual positions.”

For more information on our Sports law services, please click here.

How toxic masculinity can be harmful for businesses

Posted on: June 11th, 2025 by Natasha Cox

Senior Associate Emma Cocker discusses how toxic masculinity is increasingly infiltrating the workplace, with legal and cultural consequences for both employees and employers, in People Management. 

Emma’s article was published in People Management, 10 June 2025.

Toxic masculinity: a hidden cost to employers?

Following the huge success of recent Netflix drama Adolescence, the issue of toxic masculinity has been the subject of much debate. The prime minister has admitted to being worried about toxic behaviour on social media influencing young men, telling the BBC that the UK “may have a problem with boys and young men that we need to address”. Former England football manager Sir Gareth Southgate also recently aired his thoughts in a BBC lecture in which he said “toxic influencers… tricky young men”.

While discussions on this topic have so far focused on the impact of toxic masculinity generally, it is important to recognise the specific workplace challenges that are becoming more prevalent as a result of the corrosive impact of social media and misogynist influencers such as Andrew Tate.

Workplaces are increasingly reporting a subculture of negative behaviours rooted in out-of-date, and often harmful, masculine values. An overabundance of these traditional masculine norms can lead to behaviours including excessive aggression, emotional repression and a constant need to prove dominance. These behaviours can manifest in negative workplace practices; for example, a long-hours, ‘work first’ culture that prioritises work over personal or family life and individual wellbeing. Equally, overly competitive behaviour – such as a focus on winning at all costs, often at the expense of others – can have a negative impact on teamwork, collaboration and innovation. Diversity, inclusion, a healthy work-life balance and employee wellbeing also invariably tend to suffer. Instances of bullying may also increase in workplaces particularly prone to toxic masculinity.

These negative effects are being fuelled by the mandated scrapping of EDI programmes through a series of executive orders issued by President Trump. Across corporate America, EDI is now in sharp retreat with companies as diverse as IBM, Warner Bros, Coca-Cola, Goldman Sachs, McDonald’s and Amazon having scrapped, scaled back or renamed their EDI programmes.

Given that these are large, multinational companies, and many others like them have taken similar steps, the threat to EDI programmes in the UK is significant. While according to a recent survey by the Institute of Directors, 71 per cent of business leaders have no plans to alter their organisation’s approach to EDI following the scaling back of programmes in the US, that still leaves 29 per cent that might.

There are clearly other factors beyond Trump’s anti-EDI agenda affecting the UK’s position, not least the gender pay gap, which has remained stubbornly high. However, the negative effects of toxic masculinity on workplace culture should not be underestimated. As a consequence of the growth of toxic masculinity, businesses face increasing levels of risk, including the risk of legal claims by employees who have been subject to discrimination or harassment because of their sex. Fostering, or even just tolerating, a work environment that is hostile to women can violate employment law. Where successful, legal action against employers can result in costly settlements or awards of damages, as well as reputational damage to the organisation and a knock-on effect on employee morale.

Sensible organisations will heed warnings about toxic masculinity and take steps to mitigate these risks. These steps mostly come down to common sense and include having robust EDI policies, comprehensive training on appropriate workplace behaviours and a resolute commitment to challenging harmful workplace behaviours whenever they appear. However, where a workplace is already seeing significant negative consequences of allowing a toxic culture to persist, more drastic actions, such as disciplinary investigations, may be necessary. 

For further information on our employment services, please click here.

How to protect your crypto assets

Posted on: May 30th, 2025 by Natasha Cox

Director and Head of Blockchain and Digital Assets, Matt Green, comments on the recent series of attempted kidnappings of crypto entrepreneurs and discusses how to best protect assets stored on the blockchain, in The Next Web.

Matt’s comments were published in The Next Web, 29 May 2025, and can be found here.

“Despite the industry pining for decentralisation, much of the data points towards identifiable individuals with either massive wealth or access to third parties’ wealth. Simple blockchain analytics openly identifies addresses holding fortunes, and once those addresses are associated with named individuals (data triaging and clustering can unmask a pseudonymised  address), then criminals can see very clearly that a person holds significant wealth. Imagine your bank balances are posted online and through analysing open source data, the world can see it’s your account.

“In terms of crypto holders, the only thing stopping criminals gaining access is human error or force so kidnapping aims to break down the integrity of that human led security.

“The nature of blockchains means balances and addresses are public. In the same way van stickers read “no tools are kept in this vehicle”, it might be worth making a conscious effort to show a single person under duress is incapable of giving access to crypto holdings. Having clear statements about Multi-Sigs (Multi-Signature wallets) would likely deter kidnappers, who would have to pursue multiple individuals to make gains.”  

To out more about our work on blockchain, crypto and digital assets, please click here

The legal definition of ‘sex’ and its impact on employer obligations and employee benefits

Posted on: May 29th, 2025 by Natasha Cox

Senior Associate Emma Cocker explores the recent Supreme Court ruling on the definition of ‘sex’, and discusses how this ruling will impact employers’ obligations under the Equality Act 2010, in REBA.

Emma’s article was published in Reward and Employee Benefits Association (REBA), 29 May 2025.

In April, the landmark Supreme Court case of For Women Scotland v The Scottish Ministers held that ‘sex’ within the Equality Act 2010 refers exclusively to biological sex. Though this judgment did not create new law, it has fiercely reignited tensions regarding the interplay between the rights of trans people and those of biological men and women. In particular, the divide between supporters of trans rights who believe a person’s sex can be changed, and those with ‘gender critical’ beliefs who believe that sex is biological and immutable.

There has been a significant amount of online misinformation about the implications of the judgment, particularly with regards to the workplace. However, the law today is the same as it was before the clarificatory judgment, with discrimination against trans people for reasons relating to gender reassignment and discrimination against those holding ‘gender critical’ beliefs being unlawful. Yet, because of the misrepresentation of the law on this highly emotive topic, many organisations are confused and fearful of falling foul of their employment law obligations.

So, what should employers be doing in light of the judgment?

Firstly, inclusion is for everyone and there is nothing discriminatory in recognising that the protected characteristics of sex and gender reassignment relate to groups that have different needs and vulnerabilities. Making toilets and changing rooms ‘gender neutral’ with no single sex provision will breach workplace health and safety legislation, as recognised by the Equality and Human Rights Commission’s interim guidance[1]. It may be tempting to take situations on a case-by-case basis, but this could lead to employment tribunal claims by workers who expect to be able to access single sex spaces for reasons of privacy and dignity.

It is also recommended that employers review their policies and training to assess and act on the risk that what they currently have is unlawful. Policies and training not based on the Equality Act 2010’s definition of sex are likely to result in unlawful conduct for which employers may be sued in the employment tribunal.

In relation to employee benefits, it is normally prudent for employers to ensure equal access for all, however this general rule should be qualified by the intended purpose of the benefit. For example, it would be difficult for employers to justify providing death in service benefits at unequal levels between trans and non-trans people. It would not normally be advisable to provide benefits exclusively for trans workers, though support geared towards those with gender dysphoria or transitioning individuals need not be excluded.

However, there will be situations in which benefits ought not to be offered equally. Providing group-based menopause support to a cohort including transwomen could, for instance, lead to claims of sex-based discrimination or harassment and would offer little benefit to transwomen who will not experience menopause.

If there is any difference in the benefits provided to men and women, they should be provided to employees based on their biological sex. For example, if an employer chooses to offer IVF or other ‘family building’ support, it should be made available to all staff. However, it would not be discriminatory to provide women with more paid leave than transwomen, in recognition of the physical impact of fertility treatments on women.

While some will say this is ‘new’ or ‘developing’ law, that is not the case. In order to remain compliant with the Equality Act 2010 and avoid claims of harassment and discrimination, employers must apply commonsense when considering the purpose for which employee benefits are provided, and the impact of blindly applying a blanket ‘equality rule’.

For more information on our employment services, please go here

[1] An interim update on the practical implications of the UK Supreme Court judgment | EHRC

Matt Green co-authors article on crypto-asset recovery for Oxford Law Pro’s Expert Essentials, Oxford University Press

Posted on: May 28th, 2025 by Natasha Cox

Writing for peer reviewed Oxford Law Pro’s Expert Essentials, Head of Blockchain and Digital Assets Matt Green and Outer Temple Chambers’ barrister Henry Reid provide a practical guide on the recovery of misappropriated crypto-assets.

Matt and Henry’s article was published in Oxford Law Pro, 14 May 2025, and can be found here.

Following the $1m loss of the stablecoin Tether, Matt and Henry explore the practical issues of asset recovery – including the use of blockchain analytics reports, dealing with crypto exchanges and pursuing persons unknown – as well as the legal considerations.

The article begins by discussing an example of a scam in which the claimants transfer one million Tether to persons unknown, considering the movement of these assets across the blockchain and their subsequent deposit at crypto exchanges. 

Matt and Henry then analyse the viability of potential legal proceedings, discussing potential routes to recover the misappropriated assets, and outline how to approach cryptocurrency exchanges at a pre-action stage.

Their article concludes with a narrative on preparing an ex parte application against these persons unknown, as well as seeking a worldwide freezing injunction to prevent the dissipation of the stolen crypto and seeking disclosure from the crypto exchanges to identify customers who have received the traceable proceeds.

Dominic Holden discusses proposed ransomware ban in Law 360

Posted on: May 23rd, 2025 by Natasha Cox

Director Dominic Holden discusses the UK government’s proposals for a ransomware ban in Law 360.

Dominic’s article was published in Law 360, 22 May 2025, and can be found here. 

Ransomware ban move could push hackers to private sector

The government’s bid to crack down on ransomware payments could heap pressure on companies in crisis without any guarantee that it will pull the plug on the billion-pound cybercrime industry, lawyers say.

Proposals by the Home Office to ban public entities from making ransom payments and to require other bodies to consult with the authorities before they consider sending money to their attackers are intended to undermine the ransomware business model by making the U.K. a less profitable target.

But lawyers warn that the proposals, set out in a wide-ranging government consultation, appear to underestimate the opponents.

“Deceptively simple and undoubtedly well-intentioned, the proposal borders on the naive,” Julian Hayes, a partner at BCL Solicitors LLP said. “Even if it worked, it would simply drive ransomware attackers to softer targets.”

Ransomware pulled in more than £1 billion ($1.3 billion) from victims worldwide in 2023, according to the Home Office. It has become a lucrative source of cash for cybercriminals and state-sponsored actors able to infiltrate businesses and government agencies and take control of their networks and data.

Law enforcement agencies and the government see it as the biggest cyber risk facing businesses in Britain. But it is also perceived as a direct threat to national security because of the ability of criminals to shut down hospitals, energy suppliers and grocery chains.

The National Cyber Security Centre helped to manage 317 ransomware incidents in the 12 months to August 2024. They included 13 separate attacks deemed to be “nationally significant” that “posed serious harm to essential services or the wider economy.”

They include Russian hackers who stole private medical data in June 2024 in a ransomware attack on a medical testing company, Synnovis Services LLP, that disrupted London hospitals. And hackers demanded £600,000 from the British Library to prevent publication of stolen files, a demand it refused to pay, in October 2023.

What to do about the problem divides opinion. Some experts say that paying the ransom puts money in the pockets of organized crime, terrorists and sanctioned individuals — with no guarantee that the stolen data will be returned or services resumed. Paying helps to create a business model, encouraging more attacks.

Many organizations targeted do not pay. Most victims interviewed by the National Crime Agency said they did not want to reward their attackers.

But principles come at a cost.

Marks & Spencer the grocery and clothing chain, continues to lose money following a recent ransomware attack that has disrupted service and will cost it an estimated £300 million. And the Legal Aid Agency, which revealed in May that data dating back to 2010 had been stolen, warned anyone who had applied for legal support in criminal cases that they face the risk of being scammed.

But some companies see no other option. LockBit hackers hit Allen & Overy with a ransomware attack in 2023, but later retracted its threat to release the stolen data. Cyber-experts have interpreted this as a sign that A&O paid out to avoid sensitive client information from being released, although the firm never publicly commented.

Against this backdrop, the Home Office said in March that it was consulting on a range of proposals. They include a limited ban on publicly owned bodies and operators of critical national infrastructure making payments, mandatory reporting of all ransomware attacks by companies that meet thresholds and even approval by the government before they make any payment.

But lawyers warn that the proposals are risky. Payments are already widely viewed as the last resort, a drastic step for companies to take only when backup files restoring their operations fail or there is a risk that the stolen data is not encrypted.

James Longster, a partner in the technology and commercial transactions practice at Travers Smith LLP, said that private sector clients, particularly financial services firms, are concerned that putting restrictions on public-sector targets will simply push criminals to intensify their attacks on them.

“There isn’t a magic answer,” Longster said. “People want to do something because it’s a problem. It’s hard to work out exactly what that is.”

There was also doubt among observers about how the proposals would work in practice. When would companies, trying to get to grips with resuming service, be required to notify the government of the attack? How would a ban, if it was extended to the private sector, affect global companies in countries where there was no bar to payment?

The government has already introduced compulsory reporting of cyberattacks in the Cyber Security and Resilience Bill, which is making its way through Parliament. Victims would be required to report an incident only once. But lawyers say a lack of detail means it is unclear how the proposals would sit alongside existing notification requirements, potentially delaying payment during talks with authorities — and prolonging the disruption.

Business leaders fear the proposals might also lead to expensive red tape when they are already under pressure. Companies already face a race against the clock to disclose cyberattacks to their regulator, the Information Commissioner’s Office — and, potentially, to individuals if personal data was stolen.

Longster predicted that the ban on public sector bodies making payments might not make it into legislation if there was resistance during the consultation. But he said that the reporting obligations to the central government “could meaningfully turn the dial” by equipping law enforcement agencies with the best information possible.

Another proposal would require businesses to gain government clearance to ensure that money would not go to sanctioned individuals or terrorists. Christopher Whitehouse of Reynolds Porter Chamberlain LLP said that limited legislation introducing a reporting requirement – but not going as far as an outright ban – would be a good compromise.

“Save for those extreme cases, if there’s something companies could do to survive, but aren’t allowed, it’s going to be a tough sell,” Whitehouse said.

Britain would become one of few Western governments to introduce the ban – perhaps the only one – if it did so. Many countries have pledged not to pay ransomware, but none have actually made it illegal, even if it involves paying a sanctioned entity.

Some U.S. states have passed legislation banning public authorities from paying ransoms, but experts have warned that the results have been mixed.

Hayes of BCL Solicitors also said that the potential ban on government agencies making payments overlooks the fact that hackers, particularly those backed by hostile governments, are often more interested in causing chaos than making money.

Outlawing ransomware payments “risks making hostages of us all,” Hayes said.

“Such sophisticated threat actors are highly unlikely to surrender without a struggle,” Hayes continued. “Far from being deterred, such groups are more likely to fight tenaciously to protect their lucrative business models, with ‘big game’ ransomware groups intentionally targeting the U.K. essential services on which we all rely, both to break the government’s will and serve as a warning to like-minded countries not to follow suit.”

Some lawyers advocate for a more aggressive policy to help ensure that does not happen.

Dominic Holden of Lawrence Stephens said that hackers would look abroad if it was illegal for public and private sector entities to pay out.

Support for small and midsized businesses in the form of tax breaks or subsidized insurance premiums would also mean that the incentives to target the U.K. would vanish, Holden said.

“If the government is going to do this, I don’t think they should do it in half measures,” Holden said. “If you’re going to eradicate the problem, and disincentivize the hackers so they go overseas in jurisdictions where they can be paid, then grasp the nettle and ban all payments.”

Mark Jones, a partner at Paynes Hicks Beach LLP, said there were also concerns that the mandatory reporting requirement could then trigger regulatory scrutiny. The government would have to assure companies that the information would remain confidential if it wants to win support for legislation, Jones said.

“I would also hope to see measures to support those who are victims of ransomware, rather than simply add to the stress of the situation,” Jones added.

For more information on our cryptoassets expertise, please click here.