The White House held the third annual Counter Ransomware Initiative (CRI), convening 50 entities – 48 countries, the European Union, and Interpol – to discuss combating ransomware. During this year’s summit, members were focused on:
- Developing capabilities to disrupt attackers and their infrastructure
- Improving cybersecurity through information-sharing and
- Fighting back against ransomware actors.
Out of the summit, there were a few notable deliverables. The first being that nearly all of the governments signed a pledge against paying ransoms to hackers. As the first-ever collective statement of this kind, it signaled a powerful unified front denying cybercriminals the incentives they seek to persist and profit from their attacks.
Albeit inspiring, officials have publicly noted that the pledge is not binding, raising questions on the effectiveness of the commitment. With the way that the agreement is written, it doesn’t lead to a ban, includes carve-outs for emergencies and still gives governments room to decide on a case-by-case basis whether a ransom payment is warranted.
Additionally, the U.S. Department of the Treasury published a "blacklist" containing details on cryptocurrency wallets implicated in previous ransom transfers. The idea behind this is to use artificial intelligence to analyze blockchains, potentially halting transactions originating from flagged wallets.
Finally, the CRI also led to additional information sharing capabilities by Lithuania, Israel and the United Arab Emirates that will enable member countries to quickly exchange news of threat indicators.
There is no doubt that ransomware is a cross-border, transnational threat that demands international collaboration. As the coalition of countries work to expand their influence, potential projects in the future may include formalizing CRI processes by determining governance frameworks, exploring how partnerships with the cyber insurance industry can help in countering ransomware, and how countries should work together with AI and other emerging technologies. To learn more about this year’s summit and its outcomes, click here.
Read Next
European Commission Publishes Final Cyber Resilience Act Implementation Guidance, Addresses Concerns Raised by Cybersecurity Coalition
The Cybersecurity Coalition welcomes final guidance on the Cyber Resilience Act that provides covered entities with clearer guidance on the landmark product security regulation.
Building Texas Cyber Resilience: From Awareness to Action
Texas is building a new model for cyber resilience. A recent convening of state, local, academic, and private sector leaders identified practical steps to strengthen coordination, expand shared capabilities, and improve cybersecurity readiness.
European Commission Announces New Action Plan To Confront Cybersecurity Challenges in the Age of AI
The European Commission released an Action Plan on Cybersecurity and AI, outlining how it intends to manage the growing cybersecurity risks associated with frontier AI models and strengthen Europe’s own AI-enabled cybersecurity capabilities.
