Ransomware's Challenges for Cyber Insurance, and How to Help Meet Them

Dr. Christopher Ford • November 7, 2021

In November 2021, Dr. Ford  published a new paper at MITRE on the challenges facing the cyber insurance industry as a result of the contemporary epidemic of ransomware.  The Executive Summary this paper is reproduced below, but you can download a PDF of his paper by using the button below. 



Ransomware Insurance Paper


Executive Summary


As the United States faces a veritable “feeding frenzy” of ransomware crime, the insurance sector risks contributing to the problem by subsidizing and encouraging ransomware crime by allowing victims to pass ransom costs on to insurance carriers. This paper outlines how this has been occurring, with the effect that spiraling costs associated with such crime have driven huge premium increases for cyber insurance policyholders and are leaving portions of the insurance sector “teetering on the edge of profitability.” To help meet this challenge and bring the ransomware epidemic under control, changes are clearly needed.


The adoption of a new model of sector-wide cybersecurity risk assessment and mitigation could contribute to this goal, but especially while we still await successful adaptation by the insurance sector, various public policy interventions also deserve evaluation. The following pages outline several such possibilities: banning insurance coverage for ransom payments; strengthening and better tailoring the cybersecurity reviews required for insurance coverage; increased government use of “primary” sanctions against ransomware threat actors coupled with “secondary” ones against those who pay ransoms to them; broader government regulation of the cyber insurance market; and the development of improved data-sharing within the industry and with government stakeholders. As an initial step, in advance of broad agreement upon one or more of those approaches, this paper advocates the development of a new public-private partnership (PPP) framework to facilitate the aggregation and analysis of cybercrime incident, threat activity, and ransom payment-related data in support of risk mitigation, improved actuarial management, law enforcement, and other shared objectives in the fight against cybercrime.




By Dr. Christopher Ford November 22, 2025
Below is the prepared text upon which Dr. Ford based his shorter oral remarks to the U.S-China Nuclear Workshop on November 19, 2025, convened by the Protect on Managing the Atom and the Council on Strategic Risks, held at the Belfer Center at Harvard University’s John F. Kennedy School of Government.
By Dr. Christopher Ford November 20, 2025
Below is the prepared text upon which Dr. Ford based his (much) shorter remarks on a panel on geopolitical risk on November 18, 2025, sponsored by Forward Global and the Oxford University Alumni Network. 
By Dr. Christopher Ford November 17, 2025
Below is the text upon which Dr. Ford based his remarks at a conference in China on November 8, 2025.
By Dr. Christopher Ford October 21, 2025
Below is the text upon which Dr. Ford based his remarks to the Labs Nuclear Scholars Initiative at CSIS on October 20, 2025.
By Dr. Christopher Ford October 16, 2025
In October 2025, the Next Generation Nuclear Network at the Center for Strategic and International Studies released a long recorded interview with Dr. Ford as part of its Arms Control oral history project entitled “The Negotiator Files.” You can find Dr. Ford's interview here .
By Dr. Christopher Ford October 8, 2025
Below is the prepared text upon which Dr. Ford based his remarks at an event at Hudson Institute on October 2, 2025, on the U.S. Institute of Peace Senior Study Group on Strategic Stability’s recent report on “ Sustaining the Nuclear Peace .”
By Dr. Christopher Ford October 6, 2025
Below is the prepared text upon which Dr. Ford based his remarks at a briefing for Congressional staffers on September 30, 2025, organized by the University of Pennsylvania’s Washington Cente r and the Wilson Center .
By Dr. Christopher Ford October 1, 2025
Below is the prepared text upon which Dr. Ford based his remarks to the “arms control boot camp” program for young national security professionals organized by the CSIS Project on Nuclear Issues in Washington, D.C., on September 30, 2025.
By Dr. Christopher Ford September 26, 2025
Below are the remarks upon which Dr. Ford based his opening remarks in a webinar on September 23, 2025, sponsored by the National Institute for Public Policy (NIPP).
By Dr. Christopher Ford September 24, 2025
Below are the remarks Dr. Ford delivered on September 22, 2025, at a conference in Singapore sponsored by the Pacific Forum.