---
title: The New Ransomware Law That Could Change How Businesses Handle Cyberattacks
description: Learn how the proposed Ransomware and Financial Stability Act could change the way major financial institutions handle ransomware attacks.
image: https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Abstract%20cybersecurity%20concept.jpeg
---

- [Home](https://shardsecure.com/)
- [Blog](https://shardsecure.com/blog)

# The New Ransomware Law That Could Change How Businesses Handle Cyberattacks

![Picture of Bob Lam](https://shardsecure.com/hs-fs/hubfs/Staff%20headshots/Bob-Lam--2022--Resized%20(1).jpg?width=60&name=Bob-Lam--2022--Resized%20(1).jpg "Picture of Bob Lam")

[Bob Lam](https://www.shardsecure.com/team/bob-lam) CEO and Co-Founder, ShardSecure 

 April 22 2024 

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Abstract%20cybersecurity%20concept.jpeg)

The New Ransomware Law That Could Change How Businesses Handle Cyberattacks

From major operational disruptions to exorbitant ransom payments, the effects of ransomware attacks can be incapacitating. Take Lincoln College, which [permanently closed in 2022](https://www.cbsnews.com/news/lincoln-college-closes-ransomware-hackers-illinois/) due in large part to a ransomware attack — or the Arkansas-based telemarketing firm that shut down and [laid off all its employees](https://www.zdnet.com/article/company-shuts-down-because-of-ransomware-leaves-300-without-jobs-just-before-holidays/) in 2020 for the same reason.

It’s no surprise. The [average ransom payment](https://www.varonis.com/blog/ransomware-statistics) was up to $1.54 million in 2023, almost double what it was in 2022.

Up until now, though, many large enterprises have been able to just pay the ransom and hope that the problem will go away. The hit to their bottom line from continued downtime can be much larger than the payment being demanded, so it can make sense for major organizations to pay up and move on.

Or at least, it used to. The way that large financial institutions handle ransomware is poised to change with the introduction of a new ransomware bill in the US House of Representatives.

## The proposed bill

The [Ransomware and Financial Stability Act](https://bankingjournal.aba.com/2024/04/proposed-bill-would-block-large-ransomware-payments-by-financial-institutions/), spearheaded by House Financial Services Committee Chairman Patrick McHenry and Rep. Brittany Pettersen, proposes a shift in how large companies can respond to ransom demands. It would target the finance industry specifically, including financial utilities, large securities exchanges, and critical technology service providers of core processing services at banks.

At the center of the proposed bill are stringent regulations surrounding ransom payments by financial institutions. Under the legislation, these institutions would be mandated to notify the Treasury Department before paying any ransom demands. If the payment exceeds $100,000, the company would need to seek prior approval from law enforcement (specifically, the Financial Crimes Enforcement Network) or obtain a presidential waiver. 

The [goal of the bill](https://financialservices.house.gov/news/documentsingle.aspx?DocumentID=409217), according to the House Financial Services Committee, is to bolster the resilience of our critical financial infrastructure, safeguard our daily economic activity, and deter hackers. It’s also intended to set “commonsense guide rails” for financial institutions and disrupt the economic incentives driving ransomware attacks.

It’s worth noting that the bill includes provisions for exceptional circumstances (i.e. if a ransom payment is in the national interest). It would also allow financial institutions to avoid public disclosure of most of the information surrounding ransomware incidents, underscoring the ever-important balance between transparency and privacy.

## Key takeaways

If the Ransomware and Financial Stability Act passes, responding to ransomware will get a lot more complicated for financial organizations. For starters, large companies may be incentivized to implement even stronger data security measures than they already had. From threat detection software to disaster recovery protocols, ironclad cybersecurity defenses will be non-negotiable.

Organizations should also begin employing advanced ransomware mitigation tools like microsharding to prevent operational downtime and to avoid data exfiltration and double extortion. With the rise in sophisticated ransomware tactics, basic mitigation software won’t cut it anymore. Instead, companies need to be planning ahead to maintain their business continuity and data privacy. 

Enter the ShardSecure platform. Our solution offers data integrity checks, high availability, and self-healing features to [mitigate the impact of ransomware attacks](https://shardsecure.com/resources/white-papers/ransomware) and safeguard sensitive information. By reconstructing affected data and automatically migrating it to a safe alternative location, the platform maintains the accuracy and availability of data. ShardSecure offers a way for organizations to meet the rising number of ransomware threats with robust data resilience and confidence.

## Moving ahead

We won’t know the fate of the Ransomware and Financial Stability Act until it’s put to a vote, but we do know that ransomware will continue to be a problem for companies large and small. As we navigate the evolving threat of cyberattacks, we’re going to need more proactive collaboration among lawmakers, businesses, and cybersecurity experts than ever before.

That’s one reason why we’re excited to be at RSAC 2024 in a few weeks: It’s a great chance to talk with our colleagues across the industry and make plans for a more resilient and secure cyber landscape.

Planning to be at the conference? Come visit our team — and our key technology partners, including [KPMG](https://shardsecure.com/news/kpmg-alliance), [BackBlaze](https://shardsecure.com/resources/briefs/solution-brief-backblaze), [Entrust](https://shardsecure.com/resources/briefs/entrust-hsm), [Wasabi](https://shardsecure.com/resources/briefs/wasabi), and more — at booth #5263 Moscone North. We look forward to sharing more information about our platform and talking about the future of cybersecurity together.

[Ransomware](https://shardsecure.com/blog/tag/ransomware)

## Read on

![](https://shardsecure.com/hubfs/Picture2.jpg)

June 15 2026

### [ShardSecure MCP Secure Gateway](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

[Read more](https://shardsecure.com/blog/shardsecure-mcp-secure-gateway-identity-aware-data-redaction-and-least-privilege-context-enrichment-for-ai-inference)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

February 18 2026  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Unstructured Data Left Exposed: A Cloud Breach That Should Worry Every Enterprise](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

[Read more](https://shardsecure.com/blog/unstructured-data-left-exposed-a-cloud-breach-that-should-worry-every-enterprise)

![](https://shardsecure.com/hubfs/Keyboard%20with%20high%20tech%20user%20map%20icons%20and%20symbols-1.jpeg)

November 12 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Can You Really Trust Hyperscalers with Your Data at Rest?](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

[Read more](https://shardsecure.com/blog/can-you-really-trust-hyperscalers-with-your-data-at-rest)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Acronis%20and%20ShardSecure%20unveil%20a%20groundbreaking%20technology%20partnership%20set%20against%20a%20backdrop%20of%20a%20sleek%20modern%20office%20filled%20with%20digital%20screens%20displaying%20dynamic%20data%20flows%20The%20atmosphere%20buzzes%20with%20excitement%20and%20anticipation%20illuminated%20by%20sof-1.png)

October 16 2025  | [Cloud](https://shardsecure.com/blog/tag/cloud)

### [Acronis + ShardSecure: Stronger data protection for modern threats](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

[Read more](https://shardsecure.com/blog/acronis-shardsecure-stronger-data-protection-for-modern-threats)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20portrays%20a%20hightech%20digital%20landscape%20filled%20with%20abstract%20representations%20of%20data%20security%20concepts%20At%20the%20forefront%20a%20glowing%20vault%20symbolizing%20advanced%20filelevel%20encryption%20stands%20tall%20surrounded%20by%20intricate%20patterns%20of%20fragmented%20data.png)

October 1 2025  | [Data Sensitivity](https://shardsecure.com/blog/tag/data-sensitivity)

### [Revolutionizing Data Security: How Agentless File Level Encryption Makes Stolen Data Useless](https://shardsecure.com/blog/sensitive_data)

[Read more](https://shardsecure.com/blog/sensitive_data)

![unstructured data](https://shardsecure.com/hubfs/Digital%20image%20of%20globe%20with%20conceptual%20icons.%20Globalization%20concept.jpeg)

September 15 2025  | [Cybersecurity News](https://shardsecure.com/blog/tag/cybersecurity-news)

### [Elevating unstructured data security: ShardSecure® and Entrust® Join Forces!](https://shardsecure.com/blog/entrust_partnership)

[Read more](https://shardsecure.com/blog/entrust_partnership)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/scales%20%20ransomware%20attack%20to%20pay%20the%20money%20or%20risk%20the%20attack.jpeg)

July 29 2025  | [Ransomware](https://shardsecure.com/blog/tag/ransomware)

### [CISOs on Strategic Considerations in Ransomware Response](https://shardsecure.com/blog/ransomware-fine)

[Read more](https://shardsecure.com/blog/ransomware-fine)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Image%20for%20AI%20data%20types-1.jpeg)

July 29 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [The Growth of AI is driving the Imperative of Securing Unstructured Data](https://shardsecure.com/blog/ai-unstructured-data)

[Read more](https://shardsecure.com/blog/ai-unstructured-data)

![](https://shardsecure.com/hubfs/AI-Generated%20Media/Images/The%20image%20depicts%20a%20hightech%20digital%20landscape%20showcasing%20a%20sleek%20modern%20office%20environment%20illuminated%20by%20soft%20blue%20and%20white%20lighting%20In%20the%20foreground%20a%20large%20computer%20screen%20displays%20intricate%20graphs%20and%20charts%20related%20to%20data%20security%20while%20a%20gr.jpeg)

July 22 2025  | [Data security](https://shardsecure.com/blog/tag/data-security)

### [How to make your SharePoint data of zero value in a zero day attack!](https://shardsecure.com/blog/sharepoint_breach)

[Read more](https://shardsecure.com/blog/sharepoint_breach)

[![ShardSecure®](https://shardsecure.com/hubfs/ShardSecure%20brand%20assets/Logo%20(2022)/ShardSecure-Logo__Horizontal--White.svg "ShardSecure®")](https://shardsecure.com/)

101 Avenue of the Americas, 9th Floor, New York, NY 10013, United States of America

[![linkedin](https://shardsecure.com/hubfs/_2023/li.svg) ](https://www.linkedin.com/company/shardsecure) [![tweeter](https://shardsecure.com/hubfs/_2023/tweeter.svg) ](https://www.twitter.com/ShardSecure) [![facebook](https://shardsecure.com/hubfs/_2023/facebook.svg) ](https://www.facebook.com/ShardSecure/) [![facebook](https://shardsecure.com/hubfs/_2023/youtube.svg) ](https://www.youtube.com/@shardsecure877)

© 2026 ShardSecure®. All rights reserved.   
[Privacy Policy](https://shardsecure.com/privacy-policy)

![websights](https://ws.zoominfo.com/pixel/62e7bb6d62a6b2008e071c83) ![](https://px.ads.linkedin.com/collect/?pid=5456580&fmt=gif)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Bob Lam",
    "url" : "https://shardsecure.com/blog/author/bob-lam"
  },
  "dateModified" : "2024-04-22T16:00:00.570Z",
  "datePublished" : "2024-04-22T16:00:00.000Z",
  "headline" : "The New Ransomware Law That Could Change How Businesses Handle Cyberattacks",
  "image" : [ "https://shardsecure.com/hubfs/AI-Generated%20Media/Images/Abstract%20cybersecurity%20concept.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://shardsecure.com/blog/new-ransomware-law",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://shardsecure.com/hubfs/ShardSecure-Logo__Horizontal--Purple-Inverted.svg"
    },
    "name" : "ShardSecure"
  }
}
```