Ransomware reporting duties are expanding: why backup restore tests matter more than backup promises

UK cyber incident reporting requirements are becoming stricter, but the proposed rules do not yet apply to every business. The Cyber Security and Resilience (Network and Information Systems) Bill has completed its Commons stages and received its second reading in the House of Lords. It would require organisations within the reformed Network and Information Systems regime to send an initial notification within 24 hours and a fuller report within 72 hours after certain significant incidents. As of July 2026, the Bill has not received Royal Assent.

A separate ransomware regime is also being developed. The proposals include a targeted ransom-payment ban for the public sector and regulated critical national infrastructure, a payment-prevention process for other victims and wider mandatory incident reporting. These measures are not yet in force, and their final scope and timetable have not been confirmed.

Existing duties may still require a business to report an incident to the Information Commissioner’s Office, a sector regulator, insurers, customers or law enforcement. Paying a ransom is not generally prohibited for every UK organisation, but making or facilitating a payment to a sanctioned person or entity may breach financial sanctions and lead to civil or criminal penalties.

Why recovery planning matters

The Cyber Security Breaches Survey 2025/26 found that only 40% of businesses identifying a breach or attack reported their most disruptive incident outside the organisation. Just 25% of businesses had a formal incident response plan, while 45% had none of the surveyed formal response measures.

Recent incidents demonstrate the operational cost. The June 2024 ransomware attack on pathology provider Synnovis delayed more than 11,000 outpatient and elective appointments. Synnovis reported a financial impact of approximately £32.7 million. Marks & Spencer initially estimated that its 2025 cyber incident could affect operating profit by around £300 million before mitigation, insurance and trading actions. Its 2026 results later recorded £131.3 million of incident-related costs and £100 million of insurance proceeds.

Why a restore test beats a backup policy

The backup promiseWhat a restore test proves
We back up every nightThe job completed successfully and the stored data is readable
Everything important is protectedCritical databases, configurations, applications and credentials are included
We can recover quicklyThe actual recovery time meets your recovery objectives
Our backups are safe from ransomwareAttackers cannot alter, encrypt or delete every available copy
Our team knows what to doStaff can access the backups and restore systems in the correct order

Restore a representative system into an isolated environment and measure the process from start to finish. Check data integrity, application dependencies, permissions, encryption keys and whether restored services can communicate safely.

The NCSC recommends keeping regular backups of important files, ensuring you know how to restore them and testing them regularly. The popular 3-2-1 approach means retaining at least 3 copies across 2 devices or media types, with 1 copy stored offsite. For ransomware resilience, at least one version should also be protected from alteration or deletion through offline, segregated or appropriately configured immutable storage.

Build testing into the wider recovery plan

A tested business continuity plan should identify which services return first, who can authorise shutdowns and restores, and how customers and regulators will be informed.

Detection limits the amount of data an attacker can encrypt. A managed SOC service can monitor for suspicious activity, while MDR services provide investigation, containment and response.

Recovery remains the final layer rather than the only control. Regular vulnerability management reduces exposure to known weaknesses, particularly in unsupported or legacy systems. Practical cyber security awareness training can also reduce the likelihood of stolen credentials and successful phishing.

Frequently asked questions

Do all UK businesses have to report ransomware within 72 hours?
No. The Bill’s proposed 24-hour and 72-hour duties apply to organisations within its regulatory scope. Other businesses may have separate data-protection, contractual or sector-specific reporting duties.

Is paying a ransom illegal?
Not in every case, but payment may breach sanctions. A broader targeted ban and payment-prevention regime are proposed but are not yet law.

How often should backups be tested?
There is no universal statutory interval. Test them regularly, after major infrastructure changes and often enough to demonstrate that recovery objectives can be met.

Northern Star’s managed IT support services in London can test backup restoration, document recovery times and build a practical ransomware recovery plan. Call 0800 319 6032 to get started.

Focus on Modern Workforce Productivity and Security

Operating safely in today’s digital landscape requires a balance between seamless productivity and robust defence. At Northern Star, we optimize your operations using Microsoft Azure services in London and custom Microsoft 365 services in London, keeping your daily tools running flawlessly. We also help your team work smarter with Microsoft Copilot consulting in London and stay secure through practical cyber awareness training.

To protect your infrastructure, we deploy advanced email security services in London alongside proactive vulnerability management in London. Our continuous managed SOC services and rapid MDR services in London detect threats instantly. If an issue arises, our expert cyber incident response and dedicated business continuity services keep your organization running smoothly. Contact us to start.