Ransomware's Challenges for Cyber Insurance, and How to Help Meet Them

Dr. Christopher Ford • November 7, 2021

In November 2021, Dr. Ford  published a new paper at MITRE on the challenges facing the cyber insurance industry as a result of the contemporary epidemic of ransomware.  The Executive Summary this paper is reproduced below, but you can download a PDF of his paper by using the button below. 



Ransomware Insurance Paper


Executive Summary


As the United States faces a veritable “feeding frenzy” of ransomware crime, the insurance sector risks contributing to the problem by subsidizing and encouraging ransomware crime by allowing victims to pass ransom costs on to insurance carriers. This paper outlines how this has been occurring, with the effect that spiraling costs associated with such crime have driven huge premium increases for cyber insurance policyholders and are leaving portions of the insurance sector “teetering on the edge of profitability.” To help meet this challenge and bring the ransomware epidemic under control, changes are clearly needed.


The adoption of a new model of sector-wide cybersecurity risk assessment and mitigation could contribute to this goal, but especially while we still await successful adaptation by the insurance sector, various public policy interventions also deserve evaluation. The following pages outline several such possibilities: banning insurance coverage for ransom payments; strengthening and better tailoring the cybersecurity reviews required for insurance coverage; increased government use of “primary” sanctions against ransomware threat actors coupled with “secondary” ones against those who pay ransoms to them; broader government regulation of the cyber insurance market; and the development of improved data-sharing within the industry and with government stakeholders. As an initial step, in advance of broad agreement upon one or more of those approaches, this paper advocates the development of a new public-private partnership (PPP) framework to facilitate the aggregation and analysis of cybercrime incident, threat activity, and ransom payment-related data in support of risk mitigation, improved actuarial management, law enforcement, and other shared objectives in the fight against cybercrime.




By Dr. Christopher Ford & Dr. Craig Wiener September 5, 2025
Dr. Ford's article on "Thinking About Strategy in an Artificial Superintelligence Arms Race" -- co-authored with Dr. Craig Wiener -- was published in Defense & Strategic Studies Online (DASSO), vol. 1, no. 4 (Summer 2025). You can find the whole issue on the DASSO website here , or use the button below to download a PDF of the Ford/Wiener article. (Also, the home page for DASSO can be found here .)
By Dr. Christopher Ford August 29, 2025
Below are the remarks Dr. Ford delivered to a webinar sponsored by the National Institute for Deterrence Studies on August 29, 2025.
By SSG Members (including Dr. Ford) August 6, 2025
Over much of last year, Dr. Ford participated in the Senior Study Group (SSG) on Strategic Stability at the U.S. Institute of Peace (USIP). Ably chaired by Brad Roberts of the Center for Global Security Research at the Lawrence Livermore National Laboratory and Rebeccah Heinrichs of Hudson Institute, the SSG completed its report in February 2025, only to immediately run into publication problems as a result of the government's effort to shut down the USIP. The litigation associated with that effort remains ongoing, but the SSG is pleased to be able now to publish its report. The report is not available on the USIP website, but you can use the button below to download a PDF.
By Dr. Christopher Ford August 3, 2025
Below is the prepared text upon which Dr. Ford drew in his remarks to and discussions with a nuclear deterrence study group in London on July 28, 2025.
By Dr. Christopher Ford July 24, 2025
Below is the text upon which Dr. Ford based his remarks on July 22, 2025, to a conference sponsored by the Center for Global Security Research (CGSR) at the Lawrence Livermore National Laboratory.
By Dr. Christopher Ford June 19, 2025
Below is the prepared text upon which Dr. Ford based his oral remarks at a conference sponsored by the Centre for the Study of Existential Risk (CSER) at Cambridge University on June 17, 2025. 
By Dr. Christopher Ford June 16, 2025
Below is the text upon which Dr. Ford drew in delivering his remarks at a conference on "Transatlantic Turbulence: What Next for European Defence?" held at the University of Birmingham on June 13, 2025.
By Dr. Christopher Ford June 12, 2025
Below are the remarks Dr. Ford delivered (virtually) to a conference in Beijing on June 12, 2025, sponsored by the Asia-Pacific Leadership Network (APLN) and the Grandview Institution .
By Dr. Christopher Ford June 11, 2025
The National Institute for Public Policy published Dr. Ford's article "Thinking About Russian Nuclear Weapons Thinking" in volume 5, number 2, of the Journal of Policy & Strategy (2025). You can find the whole issue on the NIPP website here , or use the button below to download a PDF of the article.
By Dr. Christopher Ford May 29, 2025
In this article in Volume 1, Issue 3 of the Missouri State Univeristy's online journal Defense & Strategic Studies Online (pp. 1-89), Dr. Christopher Ford, John Schurtz, and Erik Quam offer a detailed analytical account of how cybernetic theories of social control developed by the scientist Qian Xuesen and his disciples were adopted by the leadership of the Chinese Communist Party and are today critical to understanding the Party’s domestic governance and foreign relations. You can see the whole issue on DASSO's website here , read the Ford/Schurtz/Quam article here , or use the button below to access a PDF of the article.