Skip to content

Ransomware

What is Ransomware?

Malicious software that encrypts a victim's files or systems and demands payment (ransom) for the decryption key. Ransomware has become one of the most financially damaging forms of cyber attack affecting organisations worldwide.

Information Security

Each of these is named in at least one of the same controls as ransomware. The number is how many controls name both.

What the standards actually require on ransomware

Requirements naming ransomware across 6 standards, quoted from the control text.

HKMA C-RAF 2024-2025 pipeline + emerging risks + sectoral cybersecurity evolution. KEY 2024-2025 INITIATIVES: (1) AI + MACHINE LEARNING + GENERATIVE AI CYBER GOVERNANCE - AIs deploying AI/ML for fraud detection + AML + customer service + lending + risk managem...

HKMA-CRAF-2024-2025-AI-Quantum-Cloud-Ransomware-DORA · HKMA C-RAF 2024-2025 Pipeline - AI, Quantum-Resistant Cryptography, Cloud Security, Ransomware, EU DORA Coordination

Lloyds Cyber Insurance Requirements - Claims Handling Standards for Cyber Events and Sanctions/Ransomware Compliance. Claims Handling Standards for Cyber Events: (a) Specialised cyber claims handling capability + Lloyds claims handler training in cyber-specifi...

LLOYDS-CI-Claims-Handling-Standards-Cyber-Events-Sanctions-Ransomware-Payment-Compliance-OFAC-HMT · Lloyds Cyber Insurance Claims + Sanctions + Ransomware Payment + OFAC

The ransomware payment report must contain the prescribed information, including details of the incident, the demand, the payment made and the entity to which it was made.

AUCSA-RAN-CONTENT · Content of a ransomware payment report
HITECH Act5 controls

HITECH 4-tier CIVIL MONETARY PENALTIES (CMP) + enforcement (Section 17939; 45 CFR 160.404; inflation-adjusted annually). HHS OCR ENFORCEMENT AUTHORITY: HHS Office for Civil Rights (OCR) primary federal enforcer;

HITECH-Enforcement-CMP-Tiers-StateAGs-OCR · HITECH 4-Tier Civil Monetary Penalty Structure, State AGs Enforcement and HHS OCR Settlements

A covered entity that makes a ransom payment as the result of a ransomware attack must report the payment to CISA not later than 24 hours after the payment is made, even if the attack is not a covered cyber incident.

CIRCIA-2242a2 · 24-Hour Ransom Payment Report

Questions people ask about ransomware

What is Ransomware?
Malicious software that encrypts a victim's files or systems and demands payment (ransom) for the decryption key. Ransomware has become one of the most financially damaging forms of cyber attack affecting organisations worldwide.
Why is Ransomware important for compliance?
Ransomware is a key concept in Information Security. Understanding ransomware helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Ransomware?
Ransomware appears in the requirement text of Japan FSA Cybersecurity Guidelines for Financial Institutions, HKMA Cyber Resilience Assessment Framework (C-RAF), Lloyd's of London Cyber Insurance Requirements and Underwriting Standards, Cyber Security Act 2024 (Australia), HITECH Act. Across these standards we have identified 27 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Ransomware?
Explore our compliance framework pages to see how ransomware applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Ransomware applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.