Technology & Platforms · Policy Lab
Cybercrime and Ransomware
A public research route covering institutions, existing frameworks, possible interventions, and open policy questions.
How to interpret these labels
Urgency is a qualitative editorial assessment of time sensitivity and potential severity in the underlying working research. Addressability is a qualitative assessment of whether identifiable institutions and public interventions may materially affect the issue. The labels are research triage categories; they are not measured forecasts, comparative rankings, or recommendations. Recheck both classifications against current primary sources before use.
Possible public intervention
Mandatory breach notification. Cyber insurance reform (ban ransom reimbursement). Critical infrastructure hardening mandates. International attribution cooperation.
Institutions to examine
- FBI (IC3)
- CISA
- DOJ (Computer Crime Section)
- Europol (EC3)
- INTERPOL
Institution abbreviations
- DOJ
- U.S. Department of Justice
- EU
- European Union
Existing frameworks and precedents
- CFAA (1986)
- Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) (2022)
- EU NIS2 Directive (2022)
- Budapest Convention on Cybercrime (2001)
Open policy gap
Cyber insurance moral hazard increases ransom payments 3.4×.
Legislative and policy forums
- Homeland Security
- Judiciary
- Intelligence
- ITRE
- LIBE
Continue the research
Use Reform Pathfinder to locate jurisdiction-specific institutions and possible action paths. Use the public glossary for terminology and the selected publications for public evidence and methods.
Research-use notice. This material is for research and educational use. Information may be incomplete or out of date. Verify primary sources, current law, institutional authority, source dates, and local applicability before acting. This site does not provide legal, financial, investment, regulatory, or implementation advice.