The Ransomware Task Force, when it released its April report, said world leaders needed to shift their approach to ransomware and prioritize it as a matter of national security. “This needs to be, even at the head of state level, something that’s brought up in every conversation between presidents and prime ministers as a problem that can no longer be treated as status quo,” said Philip Reiner, CEO of the Institute for Security and Technology (IST).

IST founded the Ransomware Task Force in late December, and four months later the group’s report offered 48 recommendations to combat future attacks. The task force’s 60-plus members include Microsoft, Palo Alto Networks, Cisco, the FBI, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

Last week, IST received a $450,000 donation from Craig Newmark Philanthropies to continue the anti-ransomware work.

In its report, the task force called on the White House to coordinate an anti-ransomware interagency working group. It also recommended a government-run cyber response and recovery fund, and it urged the government to mandate that organizations report ransom payments. Among other actions, it called for a crackdown on cryptocurrency exchanges, crypto kiosks, and over-the-counter trading desks to ensure that they adhere to the same regulatory standards as banks.

Since then, the task force has been “pleasantly surprised” at the shift, particularly in the United States and the United Kingdom, to move away from the traditional law-enforcement approach and instead treat ransomware as a national-security threat.

Ransomware Prioritization Changing

“Even to the best of our expectations when we released the report in April, I don’t think anybody would have expected ransomware, for instance, to be a top-three item in a summit between the president United States and that of Russia,” Reiner said. “By no means do we attribute it to the Ransomware Task Force. But one of the big things that we pushed for was to see that level of prioritization changed on the international stage, and I would argue that the level of discussion has shifted from this being a cybercrime-only type challenge to be much more of a national security threat.”

But even more importantly, “you see meaningful activity that points to that reprioritization,” he added, noting the Justice Department’s own ransomware task force, the Department of Homeland Security’s first 60-day “sprint” to fight ransomware, and the FBI seizing about $2.3 million in bitcoin paid to the Colonial Pipeline ransomware gang.

Last week members of IST’s Ransomware Task met with Anne Neuberger, deputy national security advisor for cyber and emerging technology at the White House, and her cyber team on the National Security Council to discuss ransomware “and they are very much prioritizing this,” Reiner said.

White House Uses Both Carrots and Sticks

These moves show that the White House will use “both carrots and sticks to encourage better behavior in order to protect systems and take the steps that are necessary in order to prevent ransomware attacks from even happening in the first place,” he added.

Additionally, some lawmakers want to make ransom payment disclosures mandatory for corporations, which is something else the Ransomware Task Force called for in its report. “And you’ve seen NIST, at a much more granular level and very unsexy, talking about a profile for ransomware risk management based off of the cybersecurity framework that they’ve put a draft out on already — that’s remarkably fast,” Reiner said.

“On the insurance side of things: the report recommended a consortium be stood up for the better sharing of information so that the cyber insurance industry can do better underwriting of these policies and increase the expected standard level of cybersecurity behavior in order to get insured,” he continued.

Last month, a group of major insurers formed a consortium to coordinate cyber-risk analysis and mitigation efforts.

“So again, I can’t say that folks necessarily are doing this because the report recommended it, but we see that happening and it’s encouraging,” Reiner said. “By no means does that mean that the ransomware threat has abated. There’s still a lot more that needs to be, but I think the right things are being set in place.”

What’s Next for Ransomware Task Force?

Meanwhile, on the Ransomware Task Force side of things, IST still has its work cut out for its team.

“Our whole intent was not to write a report, but to actually work with all of our partners to devise actual activities that we can engage in,” Reiner said. “There’s an immense amount of work where we can be helpful that was in our report, and that’s what we’re going to be doing: How do you get the ransomware incident response network set up? How do you help shape the public-private collaboration piece? How do you potentially contribute to the conversation around cryptocurrencies?”

Reiner won’t say which of these projects the Ransomware Task Force will tackle first or allocate the most resources toward. “It’s a bit TBD,” he said. “But the intent here is to help carry the report forward, because those recommendations need to be implemented.”