Understanding Ransomware Through the Lens of Disaster Risk: Implications for Cybersecurity and Economic Stability

Abstract

Ransomware has emerged as a modern digital crisis, mirroring the widespread disruptions typically associated with natural or artificial disasters. As global economies grow increasingly interconnected through digital systems, the fallout from ransomware attacks stretches far beyond mere technical breaches. These incidents result in severe financial damage, disrupt operations, erode reputations, and contribute to broader socioeconomic instability. This study adopts a disaster risk perspective to examine the broader economic and social impact of ransomware, particularly its effects on critical infrastructure and public trust in institutions. Through a multi-case analysis of sixteen significant ransomware attacks between 2015 and 2025, the research highlights a recurring pattern: direct and indirect costs often compound, with impacts varying from ransom demands and halted services to reputational loss and sector-wide vulnerabilities. The rise of Ransomware-as-a-Service (RaaS) has also made these attacks more accessible and complex, deepening the threat landscape. The findings underscore the need to integrate cybersecurity into comprehensive disaster risk management strategies. Policymakers, institutions, and businesses must adopt a forward-looking approach—emphasising continuous risk evaluation, resilient digital infrastructure, and collaboration across sectors. To protect economies from escalating cyber threats, adaptive regulations and anticipatory defences are no longer optional—they’re essential.

Conclusions

This paper has shown that ransomware should no longer be viewed solely as a cybersecurity challenge, but as a complex and evolving disaster risk with far-reaching consequences for economic stability, institutional resilience, and public trust. Drawing on sixteen high-impact case studies, the research presents a typology of financial losses and systemic disruptions, highlighting the disproportionate impact on critical infrastructure and the compounding nature of indirect costs. By framing ransomware as a form of digital disaster, the study contributes to a more integrated approach to cyber risk within the broader context of disaster risk governance and resilience planning.
The findings point to several practical implications, calling for coordinated but context-specific action from key stakeholders: a) governments should incorporate ransomware preparedness into national risk strategies, encourage transparent incident reporting, and provide fiscal incentives for cybersecurity investments; b) private-sector entities need to implement zero-trust architectures, develop insurance solutions tailored to cyber threats, and enhance organisational resilience that extends beyond technical safeguards; c) at the international level, institutions must advance cross-border collaboration—particularly in regulating virtual assets, supporting joint law enforcement efforts, and setting global standards for cyber disaster response.
The financial impact of cybercrime has reached staggering proportions, with projections indicating an alarming upward trend. An unfortunate aspect of today’s online society affects businesses of all sizes. The global scale of financial flows associated with ransomware attacks has grown dramatically in recent years. New techniques have increased the profitability of attacks and the likelihood of success. These include targeting large, high-value entities and ransomware-as-a-service (RaaS), where ransomware criminals sell customised software kits to affiliates. The consequences of a ransomware attack can be dire, posing significant national security threats that include damage and disruption to critical infrastructure and services. A ransomware attack is a form of extortion, and FATF standards require it to be criminalised as a predicate offence for money laundering (The Financial Action Task Force, 2023). Ransomware criminals exploit the international nature of virtual assets to facilitate large, near-instantaneous cross-border transactions, sometimes without the involvement of traditional financial institutions that have programs in place to prevent money laundering and terrorist financing.
Ransomware attacks are on the rise globally, and any business or organisation can be a target of these attacks, which require additional attention and preparation in terms of business cybersecurity and the complete protection of the digital economy. As Krivokapić et al. (2023) point out, it is crucial that all relevant institutions, including financial institutions, are informed about the ransomware attack and the ransom payment. This is important because it provides sufficient evidence for possible legal proceedings or cancellation of ransom payments. Additionally, business entities should invest in insurance policies that include cybersecurity coverage, as standard commercial policies often do not provide sufficient protection against cyberattacks. These insurance policies help cover the costs arising from attacks, such as ransomware (Cobos et al., 2024). Since states cannot always effectively protect themselves from cyber attacks, it is recommended that they encourage investment in cybersecurity. This can be supported by introducing tax breaks and double deductions for costs related to cybersecurity.
The first recommendation is to continue investing in workforce education and training, enabling individuals to identify threats and respond effectively (World Economic Forum, 2025). Then, it is necessary to adopt a zero-trust approach, which minimizes the risk of attacks by treating all requests as potentially malicious. It is also crucial to enhance incident response plans to respond promptly to cyberattacks and mitigate their impact. Advanced technologies, such as artificial intelligence and automation, should be used to improve threat detection and predictive analytics, but with caution against attacks launched by artificial intelligence (Thakur, 2024). Collaboration and information sharing among members of the cybersecurity community are also key to strengthening defences. Data protection and privacy should be a top priority, alongside regulatory compliance and transparent communication. Finally, it is essential to regularly assess and update security to identify new vulnerabilities and adapt defences to emerging threats, as cybersecurity is an ongoing process that requires a proactive approach, collaboration, and the integration of modern technologies to successfully confront evolving threats.
This study has limitations. The analysis relies on publicly available data, which may exclude undisclosed or underreported incidents. Future research should focus on analysing longitudinal data, identifying sector-specific vulnerabilities, and modelling recovery trajectories following major ransomware events. In closing, confronting the ransomware threat demands more than just technological fixes. It requires a fundamental shift in how digital risk is conceptualised, governed, and financed. Without integrated, adaptive, and inclusive strategies, ransomware may become one of this century’s defining disaster threats.

How to cite

Vidović, N., Cvetković, V. M., Beriša, H., & Milašinović, S. (2025). Understanding Ransomware Through the Lens of Disaster Risk: Implications for Cybersecurity and Economic Stability. International Journal of Disaster Risk Management, 7(1), 247–264.

DOWNLOAD PDF

Leave a Reply

Your email address will not be published. Required fields are marked *