Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Former acting U.S. National Cyber Director Kemba Walden told Congress on April 16, 2024, that banning ransomware payments remained a long-term policy goal—but that an immediate prohibition could leave hospitals, small businesses and other essential services unable to recover from attacks. The Ransomware Task Force likewise set out a multi-year path to a possible ban, built around making organizations more resilient and improving disruption of criminal groups first.
What Walden told Congress—and what “a ways off” meant
Walden served as acting U.S. national cyber director from February through November 2023. At the time of her April 2024 testimony, she was president of the Paladin Global Institute, a cyber-policy and critical-infrastructure initiative within Paladin Capital Group. She appeared as a witness and policy expert; her remarks should not be read as a current White House position. CyberScoop’s April 16, 2024 report covered her warning.
Her argument connected three points: a payment ban could remain the eventual objective; the economy and critical sectors were not yet resilient enough for an immediate prohibition; and reaching that point meant making attacks less profitable while improving victims’ ability to withstand and recover from them. Walden’s economic framing was that criminal profits remained too high while the costs imposed on attackers remained too low.
“A ways off” meant a lengthy preparation period, not that the idea had been abandoned. The Ransomware Task Force’s April 10, 2024 roadmap said that even aggressive progress would leave several years before a prohibition could reasonably be considered. That is a forecast in the roadmap, not a current enactment timetable. The task force roadmap describes the proposed milestones and approach.
#1 Best Overall
Why an immediate prohibition could put victims at risk
Essential services may not be able to wait out an outage
A payment ban would not prevent an intrusion, encryption, data theft or disruption. It could instead remove one possible response after an attack, before every victim has a workable way to restore systems. Hospitals, local governments, schools, utilities and financial institutions may face serious consequences when essential systems remain unavailable.
Walden specifically warned that small and medium-sized organizations—including rural hospitals serving several municipalities—could be pushed into bankruptcy if they were barred from paying before they had adequate recovery capacity. That is a stated risk, not proof that every ban would bankrupt a hospital. The impact would depend on the organization’s alternatives, the duration of the outage and the services affected.
The burden would fall unevenly
A large company may have redundant systems, emergency liquidity, cyber insurance and an incident-response retainer. A small municipality, school district, rural hospital or manufacturer may lack those buffers. A rule that applies equally on paper can therefore impose very different costs in practice.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallEven a victim that chooses not to pay still needs to contain the incident, preserve evidence, restore clean systems, assess legal and regulatory duties, communicate with affected people, reset credentials and monitor for renewed access or data publication. A prohibition would not supply those capabilities by itself.
Rushed restrictions could undermine reporting
If organizations fear penalties for paying, they may conceal transactions rather than report them. That could deprive investigators of information about attackers, infrastructure and payment flows. The Institute for Security and Technology identified voluntary reporting and payment transparency as possible casualties of a rushed ban; this is a policy risk, not an outcome established for every organization. Its discussion of the issue appears in the Institute’s webinar on payment-ban options.
What the Ransomware Task Force roadmap proposed
The task force’s April 2024 roadmap set out 16 milestones across four lines of effort. Its sequence was intended to make a future prohibition more workable by strengthening the conditions around it—not simply to defer a ban to a later date.
Rank #3
| Workstream | Purpose | What it means in practice |
|---|---|---|
| Ecosystem preparedness | Make organizations and essential services better able to withstand attacks. | Improve defenses, backups, recovery and continuity; address sectors that cannot sustain long outages. |
| Deterrence | Reduce the expected payoff and raise the costs for ransomware criminals. | Make attacks less profitable and increase the risks associated with conducting them. |
| Disruption | Improve the ability to investigate and interfere with criminal operations. | Strengthen investigations, international cooperation and action against groups and enabling infrastructure. |
| Response | Improve how victims and authorities handle incidents and learn from them. | Build incident and payment reporting mechanisms, response capacity and support for affected organizations. |
The roadmap’s core logic was to improve resistance and recovery, increase pressure on attackers, strengthen cooperation and investigations, and reassess whether a prohibition was necessary and workable after those conditions improved. The April 2024 roadmap PDF sets out the task force’s rationale and proposed process.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →The hearing treated ransomware as a financial-system risk
The House Financial Services Subcommittee on National Security, Illicit Finance, and International Financial Institutions held its April 16, 2024 hearing, “Held for Ransom: How Ransomware Endangers Our Financial System.” The witness list included Jacqueline Burns Koven of Chainalysis, Daniel Sergile of Unit 42 by Palo Alto Networks, Megan Stifel of the Institute for Security and Technology, and Walden of the Paladin Global Institute. The House hearing page records its title, date and witnesses.
That framing matters: ransomware is not only a technical incident for an individual victim. It can threaten the continuity of critical services and involve financial flows, investigative capacity and international cooperation. The Institute’s testimony page provides additional context on the hearing’s financial-system focus.
What a ban could—and could not—accomplish
Supporters argue that prohibiting payments could cut a major revenue stream, weaken ransomware’s appeal as a criminal business and encourage organizations to invest in resilience. Those are policy arguments, not demonstrated outcomes in the cited hearing materials. A ban would not, by itself, prevent criminals from breaking into systems, stealing data, threatening disclosure or disrupting services. Ransomware campaigns can involve several forms of extortion, not just encryption followed by a demand for a decryption key.
Opponents of an immediate blanket ban focus on the risks of denying victims a last-resort option before recovery alternatives are reliable. Criminals operating from jurisdictions beyond effective law-enforcement reach may also be difficult to arrest or deter. A ban might lead some victims to hide payments, and exceptions could make rules harder to enforce. The policy trade-off is therefore not simply whether ransom payments are desirable; it is whether organizations can survive without them and whether enforcement can reduce attackers’ ability to extract money.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
“Payment ban” can mean different policies
Proposals often get grouped under one label, but their scope and consequences differ. These are possible policy designs, not claims about enacted U.S. law:
Best Value
- A blanket prohibition: bars private organizations from paying any ransom.
- A government-only or sector-specific ban: starts with public agencies or selected critical sectors rather than every private victim.
- A sanctions-based restriction: bars transactions involving designated actors or wallets; sanctions compliance is a separate legal issue from a general ransom-payment ban.
- Mandatory disclosure: requires reporting an incident or payment without prohibiting payment itself.
- Approval or licensing: allows payment only after review, potentially with narrowly defined emergency waivers.
- Limits on insurance reimbursement: restricts whether insurance can cover a payment, which is different from making the victim’s payment itself unlawful.
These options raise different questions about exceptions, enforcement, reporting and the treatment of organizations facing immediate threats to public safety. The 2024 materials describe a staged policy debate; they do not establish which model, if any, has since been adopted.
What organizations should prepare for now
The policy debate does not change the practical need to plan for a ransomware incident. Preparation is especially important for organizations that cannot tolerate a prolonged outage.
- Build recoverable backups. Keep backups isolated or otherwise protected from the same compromise as production systems, and test restoration rather than assuming a backup will work.
- Plan for operating without key systems. Identify which services must continue, what manual procedures are possible, and how long they can be sustained.
- Set decision roles before an incident. Name the leaders, technical responders and legal advisers who will assess options and coordinate communications.
- Know reporting and legal obligations. Determine which regulators, law-enforcement agencies, customers or other parties may need to be notified. Payment legality cannot be assumed: sanctions and other obligations can apply depending on the parties and circumstances.
- Engage qualified responders and law enforcement. Preserve evidence, assess the scope of compromise and coordinate response before making irreversible decisions.
- Do not treat payment as a recovery guarantee. A payment may not restore data correctly, prevent publication, stop a repeat attack or resolve regulatory and reputational consequences.
The 2024 hearing and roadmap explain why Walden regarded resilience as a prerequisite: a policy that removes the payment option is more consequential for organizations without reliable recovery capacity. The available sources establish what she and the task force argued then; they do not establish the complete legal or legislative status of a federal payment ban as of August 18, 2026.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

