Ransomware attacks on has moved to the centre of the policy debate. Ultimately, the question is not whether the system will be tested again, but how prepared it will be when that happens. On current evidence, the answer is: better than before, but not yet good enough.
At the international level, the picture is mixed. While multilateral forums have produced statements of shared concern, concrete commitments — on funding, on verification, on enforcement — remain thin.
Regional implications
History offers some guidance, though not much comfort. Previous episodes of this kind were resolved only after a combination of sustained external pressure and a shift in domestic incentives — conditions that do not yet appear to be in place.
Not everyone shares this assessment. Some analysts contend that the risks have been overstated and that markets have already priced in most of the downside. The evidence for this more optimistic view is real, but it rests on assumptions about stability that recent events have repeatedly challenged.
We are moving from an era of managing crises to an era of living with permanent disruption. Institutions need to be designed for that reality.
Technology is both part of the problem and part of the solution. The same digital tools that enable faster coordination also create new vulnerabilities, from data leaks to targeted disinformation campaigns that exploit existing social divisions. This is where questions of ransomware attacks on become most acute.
Lessons from history
The legal framework has struggled to keep pace. Existing rules were designed for a different era and leave significant grey areas, particularly where state and non-state actors operate in the same space or where activity crosses multiple jurisdictions.
- Short term: contain immediate risks and protect the most exposed groups.
- Medium term: strengthen coordination and information-sharing between agencies.
- Long term: invest in resilience, diversification and institutional capacity.
The private sector has emerged as an unexpectedly important actor. Companies with global footprints increasingly find themselves making decisions with geopolitical consequences, often without clear guidance from governments.
For policymakers, the challenge is one of sequencing. Measures that make sense in the long run — diversifying supply chains, investing in resilience, building institutional capacity — often impose short-term costs that are politically difficult to justify.
What comes next
Looking ahead, three indicators will be worth watching closely: the trajectory of public spending commitments, the cohesion of the regional coalition, and whether external actors choose to escalate or de-escalate their involvement.
The economic stakes are considerable. Conservative estimates suggest that disruption on this scale could shave between 0.3 and 0.7 percentage points off regional growth next year, with the heaviest burden falling on import-dependent economies and low-income households.
Why it matters now
Critics argue that the current approach treats symptoms rather than causes. In interviews with more than two dozen practitioners, a recurring theme emerged: coordination between agencies remains weak, and information is still shared on a case-by-case basis rather than systematically.
Interviews with security officials suggest a growing recognition that deterrence must be paired with resilience. Hardening critical infrastructure, rehearsing crisis responses and communicating clearly with the public are no longer optional extras. For more context, see our research library.
Discussion (2)
Sign in or create a free account to join the discussion.
Helga Erdman
This matches what we are seeing on the ground. Coordination remains the weakest link.
James Mwangi 1 month ago
Thanks for the thoughtful comment — a fair point, and one we will explore in a follow-up.