The Ransomware Payment Ban Patchwork: What Security Leaders Need to Know as More States Restrict Payments

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
Security leaders at state agencies, counties, municipalities, school districts, and the vendors who serve them are operating under a patchwork of ransomware payment rules that varies by state and keeps shifting. Two states, North Carolina and Florida, have enacted outright bans on public-sector ransom payments since 2021. Several more states have introduced similar bills across multiple legislative sessions without enacting them. The result is not a single national rule but a jurisdiction-by-jurisdiction compliance question that has to be answered before an incident happens, not during one. This piece lays out what is actually law today, what is only proposed, and what both mean for incident response planning and cyber-insurance strategy.
The Baseline: Two States With Enacted Payment Bans
As of this writing, only two states have passed laws that flatly prohibit public-sector entities from paying a ransomware demand: North Carolina and Florida. Both bans are narrower than the framing they often get in trade press coverage, which is exactly why the details matter for anyone drafting a playbook.
North Carolina moved first. Its 2021 Current Operations Appropriations Act added a new article to Chapter 143 of the state's General Statutes (N.C.G.S. § 143-800), prohibiting state agencies and local government entities from paying a ransom demand and, notably, from communicating with the entity that carried out the attack. That second piece, the communication restriction, is the detail practitioners most often miss. It is stricter than every other state law that followed it.
Florida's version came a year later. Florida Statute 282.3185, part of the Local Government Cybersecurity Act enacted through HB 7055 in 2022, prohibits a state agency, county, or municipality from paying or otherwise complying with a ransom demand. Unlike North Carolina, Florida's law does not appear to prohibit communicating with a threat actor to gather intelligence about the scope of an attack or negotiate for time, and it carries a mandatory reporting obligation: covered entities must report a ransomware incident, including details of the ransom demanded, to the state's Cybersecurity Operations Center, the Cybercrime Office of the Florida Department of Law Enforcement, and the sheriff with jurisdiction, within 12 hours of discovery.
North Carolina (N.C.G.S. § 143-800, effective 2021)
Prohibits state agencies and local government entities from paying a ransom demand and from communicating with the threat actor. The broadest of the two enacted bans; the no-communication clause has no direct equivalent in Florida's law.
Florida (Fla. Stat. § 282.3185, effective 2022)
Prohibits state agencies, counties, and municipalities from paying or complying with a ransom demand. Does not appear to restrict communication with the attacker. Requires reporting to state cybersecurity and law enforcement authorities within 12 hours of discovery, including ransom-demand details.
The Broader Wave: Bills That Have Been Proposed, Not Enacted
The harder part of tracking this landscape is separating enacted law from the recurring wave of proposed bills that get media coverage every legislative session. Multiple states have introduced payment-ban legislation modeled on North Carolina's or Florida's approach, and as of this writing none of the following had been signed into law: Pennsylvania's SB 726 would bar the use of state and local public funds to pay a ransom, with a carve-out if the governor has declared a disaster emergency and authorizes payment in connection with it, and would separately require IT managed service providers serving state agencies to notify those agencies within one hour of discovering a ransomware incident. New York's S 6806 is broader in scope than either enacted law, proposing to prohibit not just governmental entities but business entities and healthcare entities from paying a ransom, alongside new incident-reporting obligations to the New York State Division of Homeland Security and Emergency Services. Texas HB 3892 would similarly restrict the use of state and local public funds for ransom payments.
Bills with a similar structure have also surfaced in Arizona and New Jersey in past sessions. The pattern across states considering this legislation is consistent: public-fund restrictions first, private-sector restrictions rarely, and reporting requirements attached more often than payment bans themselves. Treat any headline claiming a new state has banned ransom payments with a healthy dose of verification against the state's actual statute text and effective date before updating an incident response plan.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Reporting Requirements Are Spreading Faster Than Payment Bans
The practical trend that matters more than the ban count is how fast rapid-disclosure obligations are spreading independent of whether a payment ban exists. Florida's 12-hour reporting window to multiple state authorities, including a requirement to disclose the ransom amount demanded, is a meaningfully tighter clock than most organizations' existing breach notification procedures are built around. Proposed bills in other states follow the same shape: Pennsylvania's SB 726 would impose a one-hour MSP notification requirement to the client agency, and New York's S 6806 pairs its proposed payment ban with new state-level cyber incident reporting duties. Public-sector organizations and the managed service providers and incident response retainers that support them should assume that reporting-clock compliance, not payment-ban compliance, is the more immediate operational gap in most current incident response plans.
What This Means for Incident Response Planning
A jurisdiction-blind incident response plan is now a liability for any organization that touches state or local government work, whether directly as an agency or indirectly as a vendor, MSP, or contractor. The practical fix is to build jurisdiction awareness into the plan before an incident, not during one.
Map every jurisdiction you operate or contract in against enacted law, not headlines
Confirm whether your entity type (state agency, county, municipality, school district, contractor) is actually covered by North Carolina's or Florida's statute, or whether a proposed bill elsewhere has not yet been signed. The distinction between enacted and proposed changes what your legal counsel can authorize during an incident.
Build the no-payment branch into the playbook, including the no-communication branch where it applies
If North Carolina's statute applies to your entity, your playbook needs a decision path that never reaches a payment or negotiation step at all, since both are restricted. Most commercial incident response runbooks assume negotiation is always on the table; that assumption is wrong for covered North Carolina entities.
Pre-clear the reporting clock with named contacts, not generic hotlines
A 12-hour or 1-hour reporting window is unworkable if the first incident responder has to discover who the Cybersecurity Operations Center or Cybercrime Office contact is mid-breach. Name the recipients, phone numbers, and report template in the plan itself.
Get outside counsel involved in the decision tree, not just the aftermath
Because these statutes vary in whether they restrict payment only, or payment and communication, the legally correct next step after ransomware detonates depends on jurisdiction-specific statutory language that most internal IR teams are not positioned to interpret under pressure.
Cyber Insurance Strategy Implications
Payment bans intersect with cyber insurance in ways that are easy to miss when a policy was underwritten before the applicable statute existed or before the insured expanded into a newly covered jurisdiction. A policy that contemplates ransom reimbursement as a covered loss does not override a state law that makes the payment itself illegal for that insured; coverage for an illegal payment is not something an insurer can lawfully indemnify. That makes the payment-ban question a coverage-scoping conversation, not just an operational one: renewal reviews for public-sector-adjacent policyholders should explicitly confirm how the policy treats jurisdictions where payment is prohibited, what remains covered (forensics, notification costs, legal fees, business interruption) when the ransom line item is unavailable, and whether the insurer's own incident response panel and negotiation vendor are briefed on the no-communication restriction in states like North Carolina. Our related coverage on how the broader cyber insurance market is shifting as claims volume changes, and on the identity and MFA control requirements insurers are increasingly attaching to underwriting, are both useful companion reads when this jurisdiction question comes up during a renewal cycle.
A Practical Checklist Before the Next Renewal or Tabletop
The patchwork will keep changing one legislative session at a time, which means the checklist below is a process to repeat, not a one-time audit.
Confirm current statute text and effective date for every state you or your clients operate in
Do this against the state's own legislative or statute site, not a news summary, since bill numbers and section numbers change between introduction and enactment.
Re-run your next tabletop exercise with a covered-entity scenario
Script the ransomware tabletop so the simulated entity is explicitly subject to North Carolina's or Florida's statute, and confirm the response team reaches the correct no-payment (and, for North Carolina, no-communication) decision without prompting.
Ask your cyber insurance broker directly how the policy treats a legally prohibited payment
Get the answer in writing before a claim, not during one, and confirm which non-ransom costs remain reimbursable when payment is off the table.
Track proposed bills in your operating states without treating them as law
Pennsylvania, New York, Texas, and other states have reintroduced payment-ban and reporting bills across multiple sessions. Flag them for legal review on introduction, but do not update binding IR procedures until a bill is actually signed.
The bottom line
Only North Carolina and Florida currently ban public-sector ransomware payments outright, and their statutes differ on a detail that matters operationally: whether communicating with the attacker is also prohibited. Every other state with payment-ban headlines has a bill that has been proposed, not enacted, which means the honest planning posture is to verify jurisdiction-specific statute text directly, build the no-payment (and where applicable, no-communication) branch into incident response plans for covered entities, and confirm with your cyber insurance broker in writing how the policy treats a payment that state law makes illegal, before a claim forces the answer.
Frequently asked questions
Which US states currently ban ransomware payments by law?
As of this writing, only North Carolina and Florida have enacted outright bans, and both apply to public-sector entities such as state agencies, counties, and municipalities rather than private businesses.
Does North Carolina's ransomware law also prohibit talking to attackers?
Yes. North Carolina's statute, N.C.G.S. § 143-800, prohibits covered entities from both paying a ransom demand and communicating with the party that carried out the attack, which is stricter than Florida's law.
Are private companies banned from paying ransomware demands in any state?
No enacted state law currently bans private businesses from paying a ransom. A proposed New York bill, S 6806, would extend restrictions to business and healthcare entities, but it had not been enacted as of this writing.
What reporting requirements come with Florida's ransomware payment ban?
Florida requires covered state agencies, counties, and municipalities to report a ransomware incident, including the ransom amount demanded, to the state Cybersecurity Operations Center, the FDLE Cybercrime Office, and the local sheriff within 12 hours of discovery.
How should incident response plans account for state ransomware payment bans?
Plans should map every operating jurisdiction against actual enacted statute text, build a no-payment decision branch (and no-communication branch where applicable) for covered entities, and pre-clear named contacts for any mandatory reporting clock.
Does a state ransomware payment ban affect cyber insurance coverage?
It can. An insurer cannot lawfully reimburse a ransom payment that state law makes illegal for the insured, so policyholders in covered jurisdictions should confirm in writing which non-ransom costs, such as forensics and notification, remain covered.
Sources & references
- Nelson Mullins - Not in My Backyard: NC Becomes First State to Prohibit Public Entities from Paying Ransoms
- The Florida Bar - Florida Prohibits State Agencies from Paying Cyber Ransoms
- CPO Magazine - Patchwork of US State Regulations Becomes More Complex as Florida, North Carolina Ban Ransomware Payments
- The Record - An Inside Look Into States' Efforts to Ban Gov't Ransomware Payments
- MSSP Alert - Ransomware Payments: How Pennsylvania Legislation May Impact MSSPs, MSPs
- CSO Online - Four States Propose Laws to Ban Ransomware Payments
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
