Blog Layout

Ransomware's Challenges for Cyber Insurance, and How to Help Meet Them

Dr. Christopher Ford • Nov 07, 2021

In November 2021, Dr. Ford  published a new paper at MITRE on the challenges facing the cyber insurance industry as a result of the contemporary epidemic of ransomware.  The Executive Summary this paper is reproduced below, but you can download a PDF of his paper by using the button below. 



Ransomware Insurance Paper


Executive Summary


As the United States faces a veritable “feeding frenzy” of ransomware crime, the insurance sector risks contributing to the problem by subsidizing and encouraging ransomware crime by allowing victims to pass ransom costs on to insurance carriers. This paper outlines how this has been occurring, with the effect that spiraling costs associated with such crime have driven huge premium increases for cyber insurance policyholders and are leaving portions of the insurance sector “teetering on the edge of profitability.” To help meet this challenge and bring the ransomware epidemic under control, changes are clearly needed.


The adoption of a new model of sector-wide cybersecurity risk assessment and mitigation could contribute to this goal, but especially while we still await successful adaptation by the insurance sector, various public policy interventions also deserve evaluation. The following pages outline several such possibilities: banning insurance coverage for ransom payments; strengthening and better tailoring the cybersecurity reviews required for insurance coverage; increased government use of “primary” sanctions against ransomware threat actors coupled with “secondary” ones against those who pay ransoms to them; broader government regulation of the cyber insurance market; and the development of improved data-sharing within the industry and with government stakeholders. As an initial step, in advance of broad agreement upon one or more of those approaches, this paper advocates the development of a new public-private partnership (PPP) framework to facilitate the aggregation and analysis of cybercrime incident, threat activity, and ransom payment-related data in support of risk mitigation, improved actuarial management, law enforcement, and other shared objectives in the fight against cybercrime.




By Dr. Christopher Ford 29 Mar, 2024
Below appears the text upon which Dr. Ford based his remarks to the Center for Strategic and International Studies (CSIS) Project on Nuclear Issues (PONI) “PONI Scholars” group on March 28, 2024. 
By Dr. Christopher Ford 28 Feb, 2024
Dr. Ford's paper "Nuclear Posture and Nuclear Posturing: A Conceptual Framework for Analyzing China's Nuclear Weapons Policy" was published in February 2024 by the National Institute for Public Policy . You can read the paper on NIPP's website here , or use the button below to download a PDF.
By Dr. Christopher Ford 14 Feb, 2024
Below is the text of Dr. Ford's comments at an event the American Enterprise Institute on February 13, 2024, on U.S. outbound investment screening.
By Dr. Christopher Ford 11 Feb, 2024
 Below are the remarks Dr. Ford delivered at Columbia University’s School of International and Public Affairs on February 8, 2024.
By Dr. Christopher Ford 24 Jan, 2024
For a roundtable on December 13, 2023, sponsored by the Society for Risk Analysis and the Stimson Center , Dr. Ford participated in a discussion with Stimson's Debra Decker about nuclear risk reduction and the challenges of leadership in a complex national security environment. You can find materials on the roundtable here , and a video of Dr. Ford's discussion with Ms. Decker here .
By Dr. Christopher Ford 14 Jan, 2024
Below is the prepared text upon which Dr. Ford drew in making brief remarks at the Carnegie Endowment for International Peace’s “Targeting Workshop” on January 12, 2024.
By Dr. Christopher Ford 08 Jan, 2024
With 2023 now in our collective rear-view mirror, I thought I’d offer you a handy compilation of my public work product from the last year. The list is heavy on strategic competition with China, of course, but doesn’t omit other topics ( e.g., morality and nuclear weapons policy, nuclear nonproliferation, and North Korea).  Keep checking New Paradigms Forum for new material as we move into 2024!
By Dr. Christopher Ford 07 Dec, 2023
Below are the remarks delivered by Dr. Ford at the “Strategic C ompetition Educators Conference” held on December 7, 2023, at the U.S. Foreign Service Institut e in Arlington, Virginia.
By Dr. Christopher Ford 06 Dec, 2023
Below are the remarks Dr. Ford delivered at a conference sponsored by the  Center for Global Security Research (CGSR) at the Lawrence Livermore National Laboratory (LLNL), on December 5, 2023.
By Dr. Christopher Ford 07 Oct, 2023
Below are the remarks Dr. Ford delivered at Bacon House in Washington, D.C., on October 6, 2023, to DACOR ’s annal conference. This text has been supplemented with amplifying references to the original (longer) text Dr. Ford prepared for the event.
More Posts
Share by: