Ransomware's Challenges for Cyber Insurance, and How to Help Meet Them

Dr. Christopher Ford • November 7, 2021

In November 2021, Dr. Ford  published a new paper at MITRE on the challenges facing the cyber insurance industry as a result of the contemporary epidemic of ransomware.  The Executive Summary this paper is reproduced below, but you can download a PDF of his paper by using the button below. 



Ransomware Insurance Paper


Executive Summary


As the United States faces a veritable “feeding frenzy” of ransomware crime, the insurance sector risks contributing to the problem by subsidizing and encouraging ransomware crime by allowing victims to pass ransom costs on to insurance carriers. This paper outlines how this has been occurring, with the effect that spiraling costs associated with such crime have driven huge premium increases for cyber insurance policyholders and are leaving portions of the insurance sector “teetering on the edge of profitability.” To help meet this challenge and bring the ransomware epidemic under control, changes are clearly needed.


The adoption of a new model of sector-wide cybersecurity risk assessment and mitigation could contribute to this goal, but especially while we still await successful adaptation by the insurance sector, various public policy interventions also deserve evaluation. The following pages outline several such possibilities: banning insurance coverage for ransom payments; strengthening and better tailoring the cybersecurity reviews required for insurance coverage; increased government use of “primary” sanctions against ransomware threat actors coupled with “secondary” ones against those who pay ransoms to them; broader government regulation of the cyber insurance market; and the development of improved data-sharing within the industry and with government stakeholders. As an initial step, in advance of broad agreement upon one or more of those approaches, this paper advocates the development of a new public-private partnership (PPP) framework to facilitate the aggregation and analysis of cybercrime incident, threat activity, and ransom payment-related data in support of risk mitigation, improved actuarial management, law enforcement, and other shared objectives in the fight against cybercrime.




By Dr. Christopher Ford June 19, 2025
Below is the prepared text upon which Dr. Ford based his oral remarks at a conference sponsored by the Centre for the Study of Existential Risk (CSER) at Cambridge University on June 17, 2025. 
By Dr. Christopher Ford June 16, 2025
Below is the text upon which Dr. Ford drew in delivering his remarks at a conference on "Transatlantic Turbulence: What Next for European Defence?" held at the University of Birmingham on June 13, 2025.
By Dr. Christopher Ford June 12, 2025
Below are the remarks Dr. Ford delivered (virtually) to a conference in Beijing on June 12, 2025, sponsored by the Asia-Pacific Leadership Network (APLN) and the Grandview Institution .
By Dr. Christopher Ford June 11, 2025
The National Institute for Public Policy published Dr. Ford's article "Thinking About Russian Nuclear Weapons Thinking" in volume 5, number 2, of the Journal of Policy & Strategy (2025). You can find the whole issue on the NIPP website here , or use the button below to download a PDF of the article.
By Dr. Christopher Ford May 29, 2025
In this article in Volume 1, Issue 3 of the Missouri State Univeristy's online journal Defense & Strategic Studies Online (pp. 1-89), Dr. Christopher Ford, John Schurtz, and Erik Quam offer a detailed analytical account of how cybernetic theories of social control developed by the scientist Qian Xuesen and his disciples were adopted by the leadership of the Chinese Communist Party and are today critical to understanding the Party’s domestic governance and foreign relations. You can see the whole issue on DASSO's website here , read the Ford/Schurtz/Quam article here , or use the button below to access a PDF of the article.
By Dr. Christopher Ford May 24, 2025
Below are the prepared remarks upon which Dr. Ford based some of his contributions on a panel on “Tech for War or Tech for Peace? Science, Innovation, and Emerging Technologies in a New Geopolitical Era” at a conference in Reykjavik, Iceland, on May 22, 2025, sponsored by the Arms Control Negotiation Academy (ACONA) and the Peace Research Institute Frankfurt (PRIF).
By Dr. Christopher Ford May 22, 2025
Below is the prepared text upon which Dr. Ford based his opening remarks on May 21, 2025, when moderating the opening panel – entitled “NATO and Allied Perspectives on Multi-Domain Operations: A Common Understanding or Diverging Views?” – at the conference on Multi-Domain Operations sponsored by NATO’s Supreme Allied Command Transformation (ACT) in Ankara, Türkiye. (His remarks consisted only of his personal views, and do not necessarily represent those of anyone else.)
By Dr. Christopher Ford April 29, 2025
Below is the text upon which Dr. Ford based his remarks on a webinar organized by the National Institute for Public Policy (NIPP) on April 28, 2025.
By Dr. Christopher Ford April 23, 2025
Below is the prepared text upon which Dr. Ford drew in making his informal remarks on April 21, 2025, at the biennial nuclear policy conference held by the Carnegie Endowment for International Peace. You can find a video of the panel discussion here .
By Dr. Christopher Ford March 15, 2025
Below is the text upon which Dr. Ford drew in making his informal remarks to a March 13, 2025, workshop as part of the “Future of Arms Control Project” sponsored by the Geneva Graduate Institute’s Centre on Conflict, Development & Peacebuilding (CCDP).
More Posts