5 urgent actions in the fightback against ransomware

(Credit: Unsplash)

This article is brought to you in association with the European Commission.

• Criminal organizations are using ransomware to exploit vulnerabilities during the pandemic.

• Ransomware attacks have both a financial and a human cost.

• 65 business, non-profit and government organizations have banded together to form the Ransomware Task Force.

With the world still reeling from the effects of COVID-19, bad actors are stepping up efforts to capitalize on the global unrest with varying degrees of success. None have found so much success – and caused so much damage – as the criminal enterprises that have employed ransomware to threaten industry, commerce, education and lives in ways that transcend geopolitical boundaries.

Members of the World Economic Forum are familiar with how ransomware works, as criminals deploy malware that encrypts data on a victim’s IT network, making it inaccessible to them until a ransom is paid – often in the form of cryptocurrency. What many are not aware of is just how pervasive this activity has become, and how destructive it is in terms that go well beyond financial losses.

The average ransom paid by victimized organizations has more than doubled in the COVID-19 era, reaching $312,493 last year, according to the 2021 Unit 42 Ransomware Threat Report. Those figures tell just part of the economic story, as the cost of system downtime and recovery often eclipses the ransom payment. And the human toll is even more dire. Ransomware stops hospitals, educational institutions and governments from operating effectively, or it sometimes shuts them down entirely for days or weeks.

During a ransomware attack, IT administrators often struggle to recover data and restore operations, while employees are idle. Meanwhile, senior leaders engage in intense internal deliberations, debating whether to pay the ransom or tough it out through the remediation process. In the interim, patients in hospitals lose access to chemotherapy doses and operations are delayed. Logistics providers find themselves unable to deliver COVID-19 vaccines. Children go uneducated. And municipal and regional governments stop providing basic services.

This toll on society is why global leaders must act.

Thankfully, they are doing so. More than 65 software companies (including some longstanding and fierce competitors), cybersecurity vendors, government agencies from US and European countries, non-profits and academic institutions have joined forces to tackle this insidious threat. Under the moniker of the Ransomware Task Force (RTF), this group of industry leaders has developed a clear, structured set of recommendations that, if resourced and implemented, could rapidly reduce the impact of ransomware on society.

Their names are familiar to anyone who has gathered in Davos: Microsoft, Amazon Web Services, Palo Alto Networks, Rapid7 and McAfee, just to name a handful. These businesses have provided workhorses, not show horses, collaborating to fight a problem that is simply too endemic for any one company, industry or government to mitigate on its own. The fact that they have come to that collective realization speaks volumes about the size of this effort.

The Task Force’s recommendations, published in a recent report entitled Combating Ransomware: A Comprehensive Framework for Action, outline actions that governments, businesses and non-profits can take to deter ransomware criminals and disrupt their business model. While the report directs many of its recommendations at the US government due to task force members’ strong connections there, the report also calls on other national governments and industries to work together as part of a global, collaborative effort to stem the tide of these attacks.

The primary objective of these actions is to deter ransomware criminals; help organizations prepare for and defend against attacks; undermine the practices that make ransomware so lucrative; and respond to ransomware attacks more effectively.

While there are too many recommendations in the 81-page report to list here, the RTF identifies five critical and urgent actions that form the backbone of its comprehensive framework:

1. International diplomatic and law enforcement agencies must declare ransomware a priority and carry out a comprehensive and resourced strategy, which would include measures to prevent nation states from providing safe haven to ransomware organizations.

2. The White House should coordinate an aggressive, sustained and intelligence-driven “whole-of-government” operational campaign, working more closely together with private industry and other governments, to fight ransomware.

3. Governments need to create cyber response and recovery funds; require that businesses and other organizations report ransom payments; and mandate that organizations consider alternatives before making payments.

4. The international community should coordinate efforts to develop a single, widely adopted Ransomware Framework that will help organizations prepare for and respond to ransomware attacks.

5. Governments must regulate the cryptocurrency sector more closely, and ensure exchanges, kiosks and over-the-counter trading desks comply with existing regulations, including know your customer, anti-money laundering, and combatting financing of terrorism laws.

If enacted together, these steps would result in immediate and longer-term benefits, and show cybercriminals that ransomware is no longer an easy and safe strategy for financial gain.

What is the World Economic Forum doing on cybersecurity

The World Economic Forum’s Centre for Cybersecurity is leading the global response to address systemic cybersecurity challenges and improve digital trust. We are an independent and impartial global platform committed to fostering international dialogues and collaboration on cybersecurity in the public and private sectors. We bridge the gap between cybersecurity experts and decision makers at the highest levels to reinforce the importance of cybersecurity as a key strategic priority. https://www.youtube.com/embed/3JY4BZfV_LA?enablejsapi=1&wmode=transparent World Economic Forum | Centre for Cybersecurity

Our community has three key priorities:

Strengthening Global Cooperation – to increase global cooperation between public and private stakeholders to foster a collective response to cybercrime and address key security challenges posed by barriers to cooperation.

Understanding Future Networks and Technology – to identify cybersecurity challenges and opportunities posed by new technologies, and accelerate forward-looking solutions.

Building Cyber Resilience – to develop and amplify scalable solutions to accelerate the adoption of best practices and increase cyber resilience.

Initiatives include building a partnership to address the global cyber enforcement gap through improving the efficiency and effectiveness of public-private collaboration in cybercrime investigations; equipping business decision makers and cybersecurity leaders with the tools necessary to govern cyber risks, protect business assets and investments from the impact of cyber-attacks; and enhancing cyber resilience across key industry sectors such as electricity, aviation and oil & gas. We also promote mission aligned initiatives championed by our partner organizations.

The Forum is also a signatory of the Paris Call for Trust and Security in Cyberspace which aims to ensure digital peace and security which encourages signatories to protect individuals and infrastructure, to protect intellectual property, to cooperate in defense, and refrain from doing harm.

For more information, please contact us.

The ongoing efforts within the World Economic Forum’s Partnership Against Cybercrime strongly position members to lead the implementation of many of these recommendations. Indeed, World Economic Forum members are uniquely positioned to do so, and have the means and influence to help wage this battle. The RTF’s report should be the beginning of a global conversation that extends through the World Economic Forum Special Annual Meeting 2021 in Singapore, with the world joining forces to mitigate a problem that threatens us all.

the sting Milestones

Featured Stings

Can we feed everyone without unleashing disaster? Read on

These campaigners want to give a quarter of the UK back to nature

How to build a more resilient and inclusive global system

Stopping antimicrobial resistance would cost just USD 2 per person a year

European Commission increases support for the EU’s beekeeping sector

More protection for our seas and oceans is needed, report finds

Which country offers the cheapest mobile data?

INTERVIEW: ‘Defend the people, not the States’, says outgoing UN human rights chief

10 ways central banks are experimenting with blockchain

Can the US-Iran rapprochement change the world?

DR Congo elections: ‘historic opportunity’ for ‘peaceful transfer of power’ says Security Council

What can be done to avoid the risk of being among the 7 million that will be killed by air pollution in 2020?

Is there a de facto impossibility for the Brexit to kick-start?

How trust and collaboration are key in India’s last mile response to the COVID-19 crisis

Investors must travel a winding road to net-zero. Here’s a map

Engaging women and girls in science ‘vital’ for Sustainable Development Goals

‘No steps taken’ so far to end Israel’s illegal settlement activity on Palestinian land – UN envoy

In visit to hurricane-ravaged Bahamas, UN chief calls for greater action to address climate change

Illegal fishing plagues the Pacific Ocean. Here’s how to end it

How AI and machine learning are helping to fight COVID-19

EU tells Britain stay in as long as you wish

Financing fossil fuels risks a repeat of the 2008 crash. Here’s why

Here are 4 tips for governing by design in the Fourth Industrial Revolution

How curiosity and globalization are driving a new approach to travel

Coronavirus (COVID-19): truth and myth on personal risk perception

The battle for the 2016 EU Budget to shake the Union; Commission and Parliament vs. Germany

Innovation can transform the way we solve the world’s water challenges

#WorldBicycleDay: 5 benefits of cycling

Missile strike kills at least 12 civilians, including children, in Syria’s Idlib: UN humanitarians

4 steps to developing responsible AI

Mental health and suicide prevention – What can be done to increase access to mental health services in my region?

UN chief outlines ‘intertwined challenges’ of climate change, ocean health facing Pacific nations on the ‘frontline’

New US President: MEPs hope for a new dawn in transatlantic ties

Desires for national independence in Europe bound by economic realities

European Union and African Union sign partnership to scale up preparedness for health emergencies

Yemen war: UN chief urges good faith as ‘milestone’ talks get underway in Sweden

Spring 2019 Standard Eurobarometer: Europeans upbeat about the state of the European Union – best results in 5 years

Coronavirus: Commission approves contract with CureVac to ensure access to a potential vaccine

Outbreak of COVID-19: The third wave and the people

A day in the life of a Venezuelan migrant in Boa Vista, Brazil

EU Copyright Directive: Google News threatens to leave Europe while media startups increasingly worry

3 ways to fight short-termism and relaunch Europe

Accountability in Sudan ‘crucial’ to avoid ‘further bloodshed’, says UN rights office

UN committed ‘to support the Libyan people’ as Guterres departs ‘with deep concern and a heavy heart’

Antarctica: the final coronavirus-free frontier. But will it stay that way?

Mario Draghi didn’t do it but Kim Jong-un did

UN chief welcomes G20 commitment to fight climate change

MEPs: Access to adequate housing should be a fundamental European right

More countries are making progress on corruption – but there’s much to be done, says a new report

Mountains matter, especially if you’re young, UN declares

EU food watchdog: more transparency, better risk prevention

Young activists share four ways to create a more inclusive world

The European Sting @ the European Business Summit 2014 – Where European Business and Politics shape the future

More than one million sexually transmitted infections occur every day: WHO

These countries spend the most on education

How a new approach to meat can help end hunger

MEPs cap prices of calls within EU and approve emergency alert system

Electronic cigarettes: is it really a safe alternative to smoking?

China confirms anti-state-subsidy investigation on EU wine imports

Century challenge: inclusion of immigrants in the health system

Here’s how we reboot digital trade for the 21st century

Britain and Germany change attitude towards the European Union

UN, global health agencies sound alarm on drug-resistant infections; new recommendations to reduce ‘staggering number’ of future deaths

Ten new migratory species protected under global wildlife agreement

More Stings?

Speak your Mind Here

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s