Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»39 countries and global cyber insurance bodies endorse new ransomware guidance (Page 5)
Cyber resilience

39 countries and global cyber insurance bodies endorse new ransomware guidance

October 8, 20248 Mins Read
a faceless hacker works on code on a laptop

At the recent 2024 Counter Ransomware Initiative Summit 39 countries alongside international cyber insurance bodies backed new guidance which aims to support organizations experiencing ransomware attacks and to boost global resilience.

The new guidance encourages organizations to carefully consider their options instead of rushing to make payments to cybercriminals in an attempt to stop disruption and data loss. It makes clear that paying a ransom will often only embolden these criminals to target other victims, and there is no guarantee of data retrieval, malware removal, or the end of a ransomware attack. Instead, organizations are encouraged to report attacks to law enforcement authorities, check if data backups are available and get advice from recognised experts. They should also take action ahead of a possible attack by preparing policies, frameworks and communications plans as part of contingency planning. 

The endorsing countries and organizations are:

Countries

Albania, Argentina, Australia, Bahrain, Bulgaria, Canada, Chad, Colombia, Costa Rica, Denmark, ECOWAS Commission, France, Germany, Greece, Ireland, Israel, Japan, Kenya, Lithuania, Mexico, Moldova, the Netherlands, New Zealand, Nigeria, Philippines, Republic of Korea, Romania, Rwanda, Sierra Leone, Singapore, Slovakia, Slovenia, Spain, Switzerland, United Arab Emirates, United Kingdom, United States, Uruguay, Vanuatu, Vietnam. 

Organizations

American Property Casualty Insurance Association, Association of British Insurers, British Insurance Brokers’ Association, Dutch Association of Insurers, Insurance Council of Australia, Insurance Council of New Zealand, International Underwriting Association, Swiss Insurance Association.

The counter ransomware guidance reads as follows (verbatim):

Guidance for organizations during a ransomware incident

Organizations are encouraged to make preparation, as part of their business continuity plan, and develop and implement their policies, procedures, frameworks, and communications plans in advance of any ransomware incident.

Consider the correct legal and regulatory environment around payment

There are legal and regulatory considerations for organizations to consider before paying a ransom which experts can provide access to advice on. Cyber insurers can also direct victims towards legal counsel who can provide advice.

Payments may not be lawful in certain circumstances, for example, if a ransom payment is made to a sanctioned entity.

Reporting the incident to the authorities

Reporting incidents to the authorities at the earliest opportunity can support victims. Such reporting will allow the authorities to provide the necessary advice and support to victims, in turn strengthening their resilience and preventing future ransomware incidents. Timely reporting of attacks and any payment made is also necessary for the authorities such as law enforcement to conduct effective investigations, compile evidence for any future disruption of ransomware actor activities, and to improve the authorities’ overall understanding of ransomware criminal operations to better support future victims, and possibly stop future attacks, including through apprehension and prosecution of those responsible and seizure and disruption of their infrastructure and services.

Evaluate all options

In the immediate aftermath, a ransomware attack can feel overwhelming. Ransomware actors know the tactics to use to pressure organizations into making quick decisions. But slowing down to review the options available could improve decision-making and lead to a better outcome.

Due diligence, reasonable collection of information and analysis of the potential harms, should be a component of every organization’s incident response and recovery plans. Due diligence can provide the following benefits:

  • assurance that key pieces of information or evidence, will not be missed
  • clear, data-backed rationale behind decisions
  • ability to meet any relevant domestic legal requirements, such as incident reporting

Where possible, consult experts

External experts such as insurers, national technical authorities, law enforcement or cyber incident response (CIR) companies familiar with ransomware incidents can improve the quality of decision-making. Insurance providers will often provide recommended CIR companies to assist organizations. If organizations have cyber insurance, they should comply with the reporting provisions of the insurance policy.

Review alternatives to paying ransom

As a general approach, organizations are strongly discouraged from making payment, in line with the joint statement issued at the 3rd CRI Summit in 2023.

While the CRI statement strongly discourages organizations from making payments, in accordance with local laws and regulations, there may be occasions where a victim may ultimately consider paying a ransom.

Decisions about payment should be informed by a comprehensive understanding – as much as is possible – of the impact of the incident and whether payment is likely to change that outcome or not. Cyber criminals will try to convince victims that payment is the only way to recover, despite the downsides of paying ransoms.

Gather relevant information to assess the impact and legal obligations

We recommend that organizations consider the following:

Take time to consider the technical situation, including availability of back-ups, alternative sources for decryption keys, time estimate for restoring functionality once decryption keys are obtained. Some of these tools may be available from cybersecurity firms, law enforcement agencies, or other commercially available or open-source tools.

Put in place workarounds to manage business disruption, and determine how long these workarounds can be sustained. When reviewing the organizational impact, organizations need to assess its system functionality, impact to business operations, impact to customers and employees (including indirect impact on the supply chain where applicable), and the likelihood of further data exfiltration.

Assess the impact of the incident

Taking steps to assess the impact of the incident helps organizations to be better prepared and for insurance coverage discussions. It is important to note that some costs – notification to impacted individuals, regulatory penalties related to safeguarding data and others – may already be incurred as a result of data exfiltration during the ransomware incident, regardless of whether the information is ultimately leaked. The impact of these costs should therefore be considered separately from the determination of whether to pay. Considerations may include:

  • examining what insurance coverage you may have
  • estimating the revenue loss from business interruption, security improvement work, staff overtime, legal expenses or regulatory penalties
  • identifying any potentially stolen data or intellectual property and estimate the potential damage to the organization, customers and clients if applicable, from any stolen data being released

Finally, in many ransomware incidents, cyber criminals now also steal data. Therefore, victims should not trust a promise to delete the stolen data once a ransom is paid. It is good practice for organizations to carry out an assessment to determine what data was compromised and how sensitive it is. Legal advice is helpful to ensure compliance with laws and regulations, and with regard to reporting to and seeking assistance from the relevant authority. Organizations should also evaluate the risks to life, personal data or national security, if data were published. We recommend verifying that any claims about the nature and amount of data stolen are true.

Record your decision-making

Maintaining a careful record of the incident response, decisions made, actions taken, and data captured (or missing) is important for post-incident reviews, lessons learned or presenting evidence to a regulator. During an incident, it is sensible to record decision-making offline, or on systems that are not impacted by the incident.

The goals of this process are to create an auditable trail for decisions; develop succinct explanations for decisions; and reduce the likelihood of another successful attack.

These efforts may look different in different jurisdictions, as regulatory processes, legal systems, and internal organizational requirements vary.

Involve the necessary stakeholders across the organization in decisions, including technical staff and senior decision makers

Few scenarios will engage senior business owners and decision-makers as quickly as deciding whether to pay a ransom. However, organizations should make sure the options are not presented prematurely and that the strongest possible evidence base is provided.

Be aware that payment does not guarantee access to your devices or data

Even where a decryption key is acquired, it’s unlikely to result in an immediate return to business as usual. Running a decryption key across complex networks can take time. If a victim organization has access to both backups and a decryptor, it may prove quicker to use backups.

It is important to keep in mind that making payments and acquiring the decryption key may not guarantee the end of the incident. A victim should not presume that a compromised system that has been restored—either from a back-up copy or after using a decryption key—is secure. A back-up copy may also have been compromised, and malicious actors may have ensured that a system restored from an encryption key remains vulnerable to future exploitation.

It is also important to consider that the malicious actors may not fulfil promises to delete stolen data and that you will be unlikely to have any means of confirming whether the malicious actors have, in fact, deleted stolen data.

Post incident evaluation: Investigate the root cause of the incident and make the necessary preparations to avoid a repeat attack

Making a payment without clarifying the original source for the compromise, and then taking appropriate mitigation actions, leaves an organization open to further incidents. Organizations should seek to independently validate how the compromise happened and remediate any flaws.

Organizations should also assess if the initial breach and associated vulnerabilities have been remediated. Assessing how the compromise happened would help organizations to strengthen their defences against future ransomware attacks. This includes implementing prevention and risk-mitigation measures such as credential management, network segregation and segmentation and having offline/disconnected back-ups.

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleWater security risks increase in a third of countries
Next Article Mental Health at Work: employee resilience and organizational resilience are intrinsically linked

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A digital twin test bay showing a large screen displaying a virtual boiler model synchronised with the physical unit during operational testing.

International cyber agencies publish guidance for isolating critical infrastructure systems during times of crisis

July 29, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?