From Ransomware Payment Bans to Payment Governance: A Risk-Based Regulatory Framework for the EU
Jersain Zadamig Llamas CovarrubiasAbstract
The European Union’s cybersecurity framework treats ransomware as a vulnerability problem and an incident reporting problem, but not yet as a payment problem. NIS2, DORA, GDPR and PSD2 govern incidents; the Cyber Resilience Act governs products; the Union cyber sanctions framework governs listed persons. None of these regimes provides a comprehensive, payment-specific governance framework for ransomware payments as regulated events. Drawing on the risk regulation, responsive regulation and cyber governance literatures, this article argues that the Union should fill the gap with a three-pillar, risk-based architecture: pre-payment notice, post-payment report and targeted bans for defined covered entities, supported by ancillary safeguards, including safe harbours, a structured harm-assessment and cost-benefit matrix, and victim-support mechanisms. The Commission’s 2026/0012(COD) NIS2 reform proposal makes a first move on the reporting side but leaves the deeper governance question unaddressed. The architecture proposed here would complete it without committing the Union to a universal ban whose operational fragility has been documented in comparative practice and discussed in the emerging empirical literature.