Calling on All Companies to Report Ransomware Attacks
High-impact ransomware attacks have provoked calls for more transparency and reporting by companies that get hit. But it’s complicated.
- Government and industry groups are calling for the mandatory reporting of ransomware attacks.
- Making companies report attacks could help global efforts to analyze and combat the current wave of cybercrime.
- But companies are often wary that reporting could cause more problems than it solves.
Government and industry are rallying against ransomware amid an ongoing wave of attacks with national and international impact. Among a wide range of anti-ransomware initiatives, immediate attention has turned toward getting companies to report ransomware attacks to authorities rather than trying to remediate or negotiate their own way out.
Calls for greater transparency are coming from several quarters worldwide. These include an action plan from the private-sector Ransomware Task Force, directives from the U.S. government, proposals from leaders in Australia and appeals from Europol.
Lack of Reporting Thwarts Anti-Ransomware Efforts
Companies are often reluctant to report ransomware attacks for a variety of reasons, whether to protect their brand’s reputation, limit liability, preserve their share price, avoid the attention of regulators or stave off disruptive law enforcement investigations. Some are required to inform regulators (and, less often, law enforcement agencies) under data privacy laws such as Europe’s General Data Protection Regulation (GDPR), the Health Insurance Portability and Accountability Act (HIPAA) and the California Consumer Privacy Act (CCPA), which all require timely reporting of breaches that expose personal information.
Still, experts see gray areas and gaps in reporting requirements — for example, when cybercriminals target infrastructure operations or companies’ trade secrets rather than personal information. Another issue is the current patchwork of state, national and international cybercrime reporting policies, rules and systems from myriad regulatory and enforcement agencies. A third problem: Companies sometimes doubt the value of reporting because law enforcement agencies have limited resources, according to Europol.
Dutch research recently showed that only one in seven victims (businesses and consumers) reported cybercrime of any kind, whether ransomware, data theft or another type of attack. When it comes to ransomware, specifically, another report found about half of the surveyed companies in the U.S. and Europe would notify law enforcement agencies of an attack, and 45% said they would report it to data protection regulators. Yet other experts point out that even companies with the best of intentions ultimately decide against reporting.
“Corporate ransomware victims are discreetly paying the ransoms and are (lawfully) sweeping the incidents under the rug,” according to a former official with the U.S. Securities and Exchange Commission (SEC).
In turn, the lack of reporting hinders the ability to create an accurate overview and mount effective countermeasures, Europol says, adding: “There is the need to foster a culture of acceptance and transparency when organizations or individuals fall victim to cybercrime.”
Below is a brief survey of new anti-ransomware reporting recommendations, requirements and information-sharing efforts.
Federal Contractors Must Report Attacks
A new executive order will require U.S. government contractors to report ransomware and other cyber incidents, both to the agency with which they have contracted and to other regulatory and enforcement bodies. Typically, such government procurement mandates permeate more broadly throughout the private sector as they become best practices.
Meanwhile, the Department of Homeland Security also issued a new requirement for pipeline owners and operators to report confirmed and potential cybersecurity incidents. And lawmakers are preparing legislation on reporting requirements.
“We have no actual system in place to make [any company] mandatorily report information to the government in real time so that we could have a full-fledged response,” said Senate Intelligence Committee Chair Mark Warner on a television broadcast. Warner suggested limited liability protections and confidentiality for companies that do submit reports.
Details to come will determine the impact on companies large and small. “Arguably, sharing may help to improve prevention, detection and responses to breaches, but smaller vendors with fewer resources to address compliance may feel the largest impact,” The Wall Street Journal reported.
And as one cybersecurity expert noted, “The coming directives over the next few months and years may be gradual, or they may be more sudden, depending on how events and incidents unfold … so start planning for it now.”
Ransomware Task Force Recommends Reporting Mandate
A new Ransomware Task Force, including 60 U.S. and international companies and advocacy groups, has issued an anti-ransomware strategy listing 48 action items that range from coordinated international diplomatic and law enforcement efforts to greater cryptocurrency regulation.
The reporting of ransom payments — prior to paying any ransom — should be mandated, the group says. But it stops short of advocating a prohibition on such payments, as some are suggesting. A standard format for reporting ransomware should be developed, and protections against revealing the victim’s identity, such as anonymous notifications, should be built into the reporting process.
Anti-Ransomware Calls Echo from Europe to Asia-Pacific
Australia’s Defense Ministry recently released a statement encouraging companies to report ransomware attacks. But Australia’s Labor Party is calling for a stronger, mandatory ransomware notification scheme as part of a national strategy. While the country has a reporting requirement covering breaches that compromise personal data, Labor leaders said a parallel regime is needed for ransomware.
Initiatives in Europe, meanwhile, include one addressing the energy sector and other infrastructure providers. Essential digital service providers and electric utilities are required to notify national authorities of serious incidents, for example. Legislation is expected to take effect soon to reinforce and streamline this information sharing across the European Union.
In a related matter in the Netherlands, the problem of international and interagency sharing of cybersecurity incident reports has prompted calls to break down barriers that keep critical information from reaching the affected businesses.
The Bottom Line
Consensus is growing that companies need to be more transparent about ransomware attacks so that government and industry can get a better handle on this ongoing crime wave. Initiatives are calling for mandatory reporting and streamlined information sharing.
 “Cybercrime Victims in the Netherlands Not Reporting Offenses,” ComputerWeekly
 “Executive Order on Improving the Nation’s Cybersecurity,” White House
 “DHS Announces New Cybersecurity Requirements for Critical Pipeline Owners and Operators,” Department of Homeland Security
 “After Colonial Pipeline Hack, U.S. to Require Operators to Report Cyberattacks,” Wall Street Journal
 “European Energy Sector Prepares for New Cybersecurity Rules,” Wall Street Journal
 “CSR Recommendation Letter on the Accelerated Sharing of Incident Information,” Cyber Security Council
Subscribe to Cyber Resilience Insights for more articles like these
Get all the latest news and cybersecurity industry analysis delivered right to your inbox
Sign up successful
Thank you for signing up to receive updates from our blog
We will be in touch!