Skip to main content

Proceeding contribution from Baroness Bennett of Manor Castle (Green Party) in the House of Lords on Monday, 7 September 2026. It occurred during Debate on bill on Financial Services and Markets Bill [HL].


Financial Services and Markets Bill [HL]

My Lords, I speak to Amendment 97, which appears in this group in my name. I commend the noble Baroness, Lady Kramer, and the noble Lord, Lord Vaux, for providing us with powerful arguments, particularly for Amendment 17. I echo the noble Lord’s comments as, if the noble Baroness wishes to put this to the vote, the Green Party will certainly support it. We need to see the tech companies being made to pay for the huge profits they are collecting while continuing to allow illegality to operate in their spaces.

However, I will primarily speak to Amendment 97. I begin by acknowledging the work of Joshua Tjeransen, who is my King’s College London intern. He has identified this issue for me and done a great deal of work on this amendment. This amendment is about a different sort of fraud from that covered by the amendment from the noble Baroness, Lady Kramer; it is about ransomware. I am sure noble Lords have come across many cases of this; it is a great concern to businesspeople, individuals and institutions, particularly the NHS. It is where a computer system or database is locked and access is prevented. The ransomware takes it over, and companies are told, “Pay up or you will never get this back”.

It is worth thinking about the circumstances of this. Very often, payment is demanded in cryptocurrency. People are told, “If you don’t do this in the next hour, the figure will double and double again” and so on, through alerts appearing on someone’s computer screen. These are tremendously frightening, difficult, challenging circumstances to face.

The figures we have for this come from Report Fraud. In the year from April 2025, 323 UK organisations reported such an attack. More than half of them were small and medium-sized enterprises, and the average loss was £270,000, which for SMEs is a huge sum of money. I said “reported” because it is generally acknowledged by experts in the field that there is a real issue of stigma here. Companies and organisations do not want to admit that they have fallen victim to such a fraud, and it is generally agreed that those figures are the tip of the iceberg. The accepted advice from law enforcement is “Don’t pay”, but it is generally acknowledged, although it is very hard to put figures on it, that a lot of people are paying right now, and this must be very lucrative for some very nasty criminals.

I come to the amendment, which would insert a new clause that would place a duty on the Financial Conduct Authority to make rules within 12 months of Royal Assent prohibiting the firms it regulates from

“making, offering, authorising or facilitating a ransom payment”

and would prevent the insuring or indemnifying of anyone against such a ransom payment. Firms would have to notify the FCA within 72 hours of becoming aware of a ransom demand. The only exception provided is where the payment is needed to prevent an imminent risk to life or serious injury, and then only with the prior approval of the Secretary of State. It covers authorised persons and firms supervised by the FCA under the Payment Services Regulations and the Electronic Money Regulations.

I think it is worth going back over how we have got to the point where we still do not have any action. In January 2025, the Home Office consulted on three proposed measures on ransomware: a targeted ban on ransom payments by public sector bodies and operators of critical national infrastructure; a payment prevention regime under which other organisations would have to notify the Government before paying; and mandatory incident reporting. The response was reported on 22 July 2025 and recorded 72% support for a targeted ban. There was an announcement that all public sector bodies and CNI operators would be banned from paying, and there would be a notification requirement.

On 14 October 2025, answering a Question from the noble Lord, Lord Fox, on the Jaguar Land Rover attack, the noble Lord, Lord Leong, told the House:

“The Home Office is progressing a new package of measures to protect UK businesses, and we will update the House accordingly

”.—[Official Report, 14/10/25; col. 169.]

In December 2025, the Security Minister said that the ban remained a priority and would progress—noble Lords know the dreaded phrase—when parliamentary time allowed. You might think that there would be coverage of this in the Cyber Security and Resilience (Network and Information Systems) Bill, but my understanding is that there is no coverage of such issues.

Why does this amendment work? Why can we do this through the Financial Services and Markets Bill? Nearly every payment will pass through a financial company. If there is any kind of scale to this at all, whoever the victim is, the money will go through a firm that the FCA supervises. A rule on these firms therefore reaches most payments made from the UK, not just payments by financial firms themselves. I think the amendment is elegant. It would not create a new offence or a general ban on businesses as the Public Bill Office said that that would be outside the scope of the Bill. Instead, it would place a duty on the FCA to create the rules within 12 months. This is a step forward in dealing with a critical issue that is affecting businesses and organisations right now and on which the Government have promised to act. It follows the Government’s own design.

I am not expecting the Minister to accept the amendment, and I am not going to put this to a vote because we have not had the time or capacity to work through the detail of exactly how this is written, but none the less I hope that we will hear from the Minister that there is going to be significant progress in this area very soon. I am really hoping not to hear the phrase “when parliamentary time allows” because the Government have done the consultation on this and have promised to act. We need to see protection in this fraud capital of the world—the UK—for firms. If ransoms cannot be paid, it will not be in the interests of criminals to put the effort in to try to get ransoms.


Secondary information

Type
Proceeding contribution
Reference
859 cc527-9 
Session
2026-27
Chamber / Committee
House of Lords chamber
Subjects
Consumers Advertising Bank of England Cybercrime Fraud Liability Financial services Innovation Insurance Intellectual property Internet Economic growth Northern Ireland Protection Money laundering Regulation Payment methods Claims management services Financial Conduct Authority Prudential Regulation Authority Trade competitiveness Digital service providers
Legislation
Financial Services and Markets Bill (HL) 2026-27
Link
View this Proceeding contribution on hansard.parliament.uk