A task force of 60+ experts from industry, government, nonprofits, and academia calls on the US and allies to take steps to fight a surge in ransomware attacks
the Secret Weapon to Combatting Ransomware Danny Palmer / ZDNet : Ransomware is now a national security risk. This group thinks it knows how to defeat it Duncan Riley / SiliconANGLE : Expert task force shares framework on how to disrupt ransomware Lily Hay Newman / Wired : An Ambitious Plan to Tackle Ransomware Faces Long Odds Andy Meek / BGR : Russian hackers are getting even more brazen in the US Tweets: Neeraj K. Agrawal / @neerajka : Some articles about the Ransomware Task Force are suggesting their report calls for new regulations of cryptocurrencies. It doesn't. It calls for better enforcement of existing policies and has a sensible note about not punishing victims for paying. https://securityandtechnology.org/ ... Katie Nickels / @likethecoins : I am proud that I was part of the #RansomwareTaskForce that released a report on combating ransomware today. My thoughts are here: https://medium.com/.... And the report is here: https://securityandtechnology.org/ ... https://twitter.com/... @rapid7 : Read the #RansomwareTaskForce report by @IST_org, with 48 actions to mitigate #ransomware. We are proud to have played a part in this groundbreaking coalition! Check out the report here: http://securityandtechnology.org/ ... Katie Moussouris / @k8em0 : “Ransomware is not a problem cybersecurity professionals can solve alone. Nor can policymakers. Nor can law enforcement. Nor can cyber insurance companies. Nor can creators of operating systems. It's going to take all of us.” #RansomwareTaskforce https://twitter.com/... Cristin Goodwin / @cristingoodwin : The #RansomwareTaskForce report is out! #Ransomware is a #nationalsecurity issue, and requires a coordinated response. Looking forward to reading this closely. https://securityandtechnology.org/ ... @fireeye : Read the #RansomwareTaskForce report by @ist_org, with 48 actions to mitigate ransomware. We're proud to have played a part in this groundbreaking coalition. This is not a threat anyone can address alone. ▶️ http://securityandtechnology.org/ ... https://twitter.com/... @talossecurity : #Ransomware is not just financial extortion. It is crime that transcends business, academic and geographic boundaries. Talos was proud to assist with this #RansomwareTaskForce report that provides a path forward to mitigate this criminal enterprise https://cs.co/... https://twitter.com/... Tonya Riley / @tonyajoriley : Mayorkas said at #RansomwareTaskForce event that DHS will work to implement recommendations and White House is also working on tackling the ransomware problem. Event here: https://securityandtechnology.org/ events/ You can read more about the report in today's Cyber 202: https://www.washingtonpost.com/ ...
Context & Ripple Effects
The Ransomware Task Force grew out of a security-industry coalition formed in late 2020, while the DOJ had already created its own ransomware-focused enforcement task force. The new report joins those tracks by giving DHS and allied governments a shared set of 48 actions rather than treating ransomware as solely an individual company’s security problem.
The related coverage also shows why the scope matters: ransomware’s effects were becoming visible beyond security teams in everyday public disruption, and attackers were operating at a scale that made patching-only advice inadequate.
First-order effects
- DHS gains an implementation agenda from the task force’s 48 recommendations, with Secretary Mayorkas committing the department to work on them.
- Rapid7 and the other contributors move from identifying the problem to supplying a common policy framework for U.S. and allied government action; the report emphasizes enforcing existing cryptocurrency policies rather than creating new ones.
Second-order effects
- The DOJ’s enforcement effort can be paired with DHS-led implementation, increasing pressure on ransomware operations across the ecosystem rather than concentrating only on victim organizations.
- Companies facing incidents remain exposed to negotiations such as those handled by ransomware negotiators, but government coordination shifts more attention toward disrupting the actors and infrastructure behind those incidents.
Third-order effects
- If governments act on the shared framework, ransomware defense will increasingly be organized as cross-border ecosystem enforcement and resilience policy, not just enterprise cyber hygiene.
- The task force model gives security vendors, government agencies, and civil-society participants a recurring role in setting operational priorities as ransomware becomes a national-security issue.
The trend: Ransomware response is shifting from company-by-company incident management toward coordinated government and industry disruption of the broader criminal ecosystem.