Defeating Ransomware: A 360° Review of the RTF Four Years On
Megan Stifel (Chief Strategy Officer · Institute for Security and Technology), Carole House (Senior Fellow · Georgetown University CyberSMART Center), Allan Liska (Ransomware Sommelier · Recorded Future), Michael Phillips (Cyber Practice Leader, USA · CFC Underwriting Ltd), John Davis (Vice President, Public Sector · Palo Alto Networks)
RSA Conference 2025 · Day 1 · Policy · Policy & Government
Overview
Four years after the Ransomware Task Force published its landmark forty-eight-recommendation report, the panelists who built it — including the Executive Director, two working group co-chairs, the NSC official who turned RTF recommendations into government policy, and the Lloyd's of London cyber insurance underwriter who saw the financial fallout firsthand — gathered to give an honest account of what changed, what didn't, and what the arc of ransomware looks like in 2025. The verdict: roughly fifty percent progress, sustained disruption operations, but the threat is still growing and the policy infrastructure to fight it is now under pressure. ---

Key moments
- 3:43 Pre-2021 ransomware: RaaS groups retaliating by knocking out 10 hospitals
- 7:59 Colonial Pipeline shifts ransomware from law enforcement to national security priority
- 26:32 RTF self-assessment: approximately 50% of 48 recommendations showing progress
- 30:12 FATF crypto standards passed 2019 but most jurisdictions still haven't implemented
- 33:15 50% of 2025 Q1 attacks are data-theft-only — ransomware losing its PR value
- 34:30 40+ law enforcement actions against ransomware in 2024 — biggest disruption year
- 40:03 Nation-state and criminal ransomware actors converging — the 'versus' is erasing
- 42:29 Raccoon Stealer operator caught via girlfriend's Instagram — creative attribution
Defeating Ransomware: A 360° Review of the RTF Four Years On
Talk ID: RSA25-020
Speakers: Megan Stifel (Institute for Security and Technology), Carole House (Georgetown University CyberSMART Center), Allan Liska (Recorded Future), Michael Phillips (CFC Underwriting Ltd), John Davis (Palo Alto Networks)
Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Stage: Policy Stage | Track: Policy & Government
YouTube: Watch on YouTube
Reading Time: ~8 minutes
TL;DR
Four years after the Ransomware Task Force published its landmark forty-eight-recommendation report, the panelists who built it — including the Executive Director, two working group co-chairs, the NSC official who turned RTF recommendations into government policy, and the Lloyd's of London cyber insurance underwriter who saw the financial fallout firsthand — gathered to give an honest account of what changed, what didn't, and what the arc of ransomware looks like in 2025. The verdict: roughly fifty percent progress, sustained disruption operations, but the threat is still growing and the policy infrastructure to fight it is now under pressure.
Introduction
The Ransomware Task Force launched in late 2020 and published its forty-eight-recommendation report on April 29, 2021 — three days before the panel convened at RSA Conference 2025. As Megan Stifel, the RTF's Executive Director and Chief Strategy Officer at the Institute for Security and Technology, noted with dry precision: "Four years ago and three days."
The timing could not have been more pointed. Colonial Pipeline was hit by ransomware nine days after the report's release, JBS Foods followed within weeks, and the recommendations that might otherwise have taken years to be noticed landed in a Washington that was suddenly, urgently paying attention.
The panel reassembled to assess what that four years of attention produced, where the gaps remain, and — with some of the policy infrastructure now being dismantled — what the next chapter requires.
Section 1: Where We Were in 2020 — "Bad"
Allan Liska, intelligence analyst at Recorded Future and ransomware's most prolific public commentator, offered a one-word summary of the pre-RTF landscape: "Bad."
▶ Watch: Liska on the ransomware landscape before the RTF (02:00)
Ransomware-as-a-service was proliferating. New major attacks were appearing weekly. The year before Colonial, a ransomware group had retaliated for a takedown of its infrastructure by knocking out ten hospitals in a weekend. "They were emboldened and felt unstoppable."
Michael Phillips, whose CFC underwriting firm insures roughly ninety thousand small and mid-sized businesses through Lloyd's of London, described the insurance industry's position: "The cyber insurance industry shares the fate of its policyholders." Clients were worried not just about their own defenses but about third-party dependencies they could not control. "The problem had gotten too big for any one organization or even the industry."
John Davis of Palo Alto Networks, a co-chair of the Prepare working group, framed his reason for joining around a conceptual shift: ransomware had finally made the cyber threat real for ordinary people. Previous cyber threats primarily attacked confidentiality — stealing information for profit or intelligence. "That's kind of a hard case to make to a lot of people." Ransomware attacked availability. "Affecting hospitals, schools, police stations, you couldn't get gas — these things were very real."
Section 2: From Report to Policy — The Colonial Moment
Carole House, now a senior fellow at Georgetown's CyberSMART Center, joined the NSC from FinCEN in 2021 — just as Colonial was being hit. She described the government's internal challenge: elevating ransomware from a law enforcement problem to a national security priority.
▶ Watch: House on how Colonial transformed ransomware into a national security issue (08:00)
"Ransomware had always been a law enforcement problem — cybercrime, law enforcement led, primary. It had not been treated as a broader national security apparatus issue." Colonial changed that. It demonstrated the need for a whole-of-government approach that integrated cyber, financial, and infrastructure dimensions simultaneously.
House credited the RTF's timing as directly valuable to the government's policy response. "The benefit of the great work the RTF had done, weeks prior to me showing up at the NSC, was really helpful and informative to what we were doing."
The government's response had to address ransomware's distinctively transnational character: distributed ransomware-as-a-service economies, money laundering networks crossing jurisdictions, both state and non-state actors as perpetrators, and victims spanning municipalities and private enterprises.
Section 3: What Has Actually Changed — The Scorecard
▶ Watch: RTF 50% progress assessment and remaining gaps (16:01)
The panel's honest assessment: roughly half of the forty-eight recommendations have seen meaningful progress. Some wins are significant. Law enforcement coordination has improved dramatically — at least forty ransomware or ransomware-adjacent enforcement actions took place in 2024, a substantial increase from prior years. CISA's Vulnerability Warning Pilot has shown practical utility. International coordination through the Counter Ransomware Initiative has created intelligence-sharing channels that did not previously exist.
The financial tracking infrastructure has matured substantially. House noted a critical asymmetry that favors law enforcement: "Cash and Fedwire and SWIFT do not publish to public ledgers. Cryptocurrency does. I don't know why all these criminals are publishing their transactions on public ledgers, but it's very useful for traceability."
Liska offered the most striking data point for 2024: ransomware attack volumes continued rising, but total payments actually declined. For the first time, the amounts paid are trending down even as the number of incidents goes up. "That's a good sign." He attributed this to a combination of law enforcement disruption, improved backup and recovery capabilities reducing victim dependence on decryption keys, and a partial shift to data-theft-only attacks without encryption.
▶ Watch: Ransomware payments down despite rising attack volumes (32:02)
The shift to data-theft-only attacks creates its own dynamics: ransomware actors are complaining publicly that they can't get press attention anymore. "One of the reasons ransomware's been so successful is it's one of the few cybercrimes with essentially its own PR arm." When pure data exfiltration doesn't generate headlines, the extortion model weakens.
Section 4: The Convergence Problem — Nation-State and Criminal Actors
Davis articulated what the panel treated as the most concerning structural trend: the erosion of the distinction between nation-state and criminal ransomware actors.
▶ Watch: Davis on the convergence of nation-state and criminal ransomware actors (40:03)
"Nation-states either turn a blind eye, in some cases inspire it, and in other cases covertly support this when the interests are aligned and it's to the benefit of the nation-state." The implication for policy is significant: ransomware is not just a crime problem. It is a national security issue, an economic issue, a public health and safety issue, and a national security issue simultaneously. The risk of treating it as only the former — primarily a law enforcement concern — is exactly the mistake the RTF was designed to correct.
House added that the current transition toward data-extortion-only attacks, without encryption disruption, raises a different concern for prioritization: "If you take disruption out of it, how much does it stay at the top line of priorities?" The original driver of political urgency was availability attacks on critical infrastructure — the ability to take down a pipeline, a hospital, a food processing plant. If the threat model shifts toward quieter data theft, sustaining that priority may become harder precisely when it remains essential.
Section 5: What Still Needs Doing — and What Is Being Undone
▶ Watch: Counter Ransomware Initiative — continuing momentum under pressure (44:03)
House called out the disbanding of the National Crypto Enforcement Team as a concrete setback. "Policy that's not enforced is useless and feckless, and we need more enforcement here." Several working enforcement mechanisms are now in question.
Phillips offered the insurance industry's perspective on what government should do: destigmatize the victim experience. There remains political ambiguity about "whose fault" a ransomware incident is and what victims are expected to absorb versus externalize. "When you look at small and mid-sized businesses, they are not generating the kinds of margins where they're able to invest in all of the latest and greatest." Targeted investment and clearer frameworks for shared responsibility are required.
Liska closed with characteristically deadpan recommendations: more cryptocurrency mixer takedowns, continued law enforcement action, and — if not drone strikes on ransomware actors — at least tracking the Instagram accounts of their associates. He offered a genuine example: the operator of Raccoon Stealer was identified and arrested after fleeing Russia to Poland, where law enforcement tracked his girlfriend's Instagram account documenting their exodus. "If we're not going to drone strike, maybe if we could get more of the ransomware actors' Instagram model girlfriends and just track their activity, so when they leave Russia we can pick them up, that would be wonderful."
Notable Quotes
"Ransomware has finally made the cyber threat real for people. Confidentiality attacks are a hard case to make to a lot of people. But ransomware — affecting hospitals, schools, police stations — these things were very real." — John Davis
"I don't know why all these criminals are publishing their transactions on public ledgers. I hope they do it forever." — Carole House
"For the first time, we saw the amount paid going down, even though the number of attacks is up. That's a good sign." — Allan Liska
"Nation-states either turn a blind eye, inspire it, or covertly support ransomware when it aligns with their interests. This is a national security issue." — John Davis
"Policy that's not enforced is useless and feckless." — Carole House
Key Takeaways
- Approximately 50% of RTF recommendations have seen meaningful progress — law enforcement coordination, CISA's Vulnerability Warning Pilot, and international information sharing through the Counter Ransomware Initiative are genuine achievements.
- Ransomware payments are declining even as attack volumes rise — a meaningful inflection that reflects improved defenses, law enforcement disruption, and changing threat actor tactics, not necessarily reduced threat.
- The shift to data-theft-only attacks challenges prioritization — the availability attacks that created political urgency for action may be declining, but the threat to critical data and operations is not diminishing.
- Nation-state and criminal ransomware actors are converging — the policy response must treat this as a national security and whole-of-government problem, not solely a law enforcement matter.
- Key enforcement infrastructure is under pressure — the disbanding of the National Crypto Enforcement Team and questions about other mechanisms represent concrete steps backward in the financial disruption toolkit that took years to build.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
The definitive retrospective on the Ransomware Task Force four years on, featuring the people who actually built it and turned it into policy. Unusually honest about partial progress and genuine failures. The convergence of nation-state and criminal actors, the shifting economics of ransomware toward data-theft-only, and the enforcement infrastructure now being dismantled are the substantive contributions. Dense with firsthand insight that doesn't appear in public reporting.
Heather Calloway (CISO) — MUST SEE
Ransomware Task Force four-year retrospective: 48 recommendations made, 36% fully implemented, 61% partially or fully addressed. The gap between ransomware-as-crime and ransomware-as-national-security-threat has not been closed. Payment disruption and international cooperation remain the two levers with the highest returns.