There's some interesting game theory at play here.
The idea is to make the public sector and CNI (which includes utilities and datacenters these days) less attractive targets for financially motivated attackers.
Indeed it's about time a major country try out if this works. Should it prove successful, others could follow suit. However, it's exactly this prospect which could make it all fail. Why? Once the UK enacts its law, the major ransomware gangs (and the occasional government backing them) could have a major incentive to target the UK's systems extra hard. This would not make the gangs any money, of course. Rather, the purpose would be to deter the rest of the world from employing the same approach, lest this source of income dry out, too.