Skip to main content

Clifford Chance

Clifford Chance

Cyber

Talking Tech

Ransomware Playbook

January 2022

Data Privacy Cyber Security 20 January 2022

Ransomware attacks have dramatically increased in volume and become more sophisticated in the wake of the COVID-19 pandemic with no sign of slowing down. In 2021, governments and private entities both have reported surges in attacks. As one example, in just the first half of 2021, the United States Financial Crimes Enforcement Network received USD 590 million in ransomware-related suspicious activity reports, over a 40% increase compared to such reports received in all of 2020. And while companies have become more resilient to such attacks, attackers continue to succeed in wreaking havoc on valuable IT systems and critical data. In a survey conducted in early 2021 of 5,400 IT decision makers employed by a range of organizations across 30 countries, over one-third reported being the target of a ransomware attack—and over half reported that the attackers were successfully able to infect their systems.

In addition to costing companies millions of dollars, ransomware attacks have also become a significant source of regulatory and reputational risk. As privacy and data security increasingly penetrate the global zeitgeist, reports of ransomware attacks have become regular fixtures in international news publications across the globe.

The Ransomware Playbook 2022 (download link at bottom of page ) aims to help companies understand and address the risk of a ransomware attack. It provides guidance on how to prevent and prepare for ransomware attacks and what to do if and when a company is the victim of such an attack. It also discusses important legal considerations from different key jurisdictions, and describes how Clifford Chance can help.

Table of Contents 

Anatomy of an attack

  • Infect
  • Attack
  • Extort
  • Spread

Prevention & Preparation

  • Strong Cybersecurity Measures
  • Training
  • Backup & Disaster Recovery
  • Incident Response Plans

Responding to an attack

  • Immediate response
  • Payment
  • Recovery & Restoration
  • Investigation & Remediation

Legal Considerations in Key Jurisdictions

  • US
  • UK
  • France
  • Germany
  • Luxembourg
  • China
  • Hong Kong (SAR)
  • Singapore
  • Australia

How Clifford Chance can help

  • Deep engagement with the changing regulatory landscape
  • A pragmatic, solution-focused approach
  • A highly experienced team