Instituting regulations that benefit everyone is not a punishment. Do you consider the privacy laws, that protect everyone's data, punishment? It was also claimed that those privacy laws would 'punish' businesses by causing them to go out of business (they did not). It was fear mongering because people didn't want to change.
Right now, companies are not investing in sufficient prevention or recovery. They are instead relying on cyber-insurance to pay the ransom. That helps nobody but the attackers. Change must occur. What you are proposing is to remain with the status-quo. That only benefits the cybercriminals, cybersecurity firms, and insurance companies. It harms businesses and citizens.
For every way you can think how a company can get around such a law, I can find a very plausible way they get caught and someone goes to jail. Executives generally won't risk that. Again, look at previous regulation that companies then adopt as the 'norm' of doing business. This too would happen with an anti-ransomware payment law. They would simply adjust their policies and processes. It becomes the norm.
RE: Paying Ransomware Should be Illegal