Pharos Report No. 4 | Assessing the Impact of Ransomware Interventions and Countermeasures: A Framework

Ransomware has become a central national security concern, prompting governments to expand their response toolkit beyond traditional law enforcement measures. Arrests, infrastructure takedowns, sanctions, indictments and public exposure are now routinely deployed against ransomware actors. Yet these interventions are often applied opportunistically and assessed in isolation, making it difficult to determine whether they produce lasting strategic effects or merely short-term disruption. Visibility is frequently mistaken for effectiveness.

The fourth report of the Pharos Series, a joint project of Virtual Routes and Royal United Services Institute (RUSI), is authored by Max Smeets, Jamie MacColl, Sophie Williams-Dunning and Bob Herczeg. The report introduces a practical framework for evaluating ransomware interventions across four dimensions: severity, scope, longevity and reversibility, and signalling value. This structured approach enables graded assessments, distinguishes between actor-level and ecosystem-level effects, and makes trade-offs across different types of interventions explicit.

The framework is illustrated through four cases — REvil, Emotet, Hive, and LockBit — demonstrating how different intervention designs generate distinct impact profiles. Overall, the report provides policymakers and operational teams with a consistent method to compare interventions, avoid equating publicity with impact, and strengthen long-term counter-ransomware strategy.

This project was made possible by the support of the German Federal Foreign Office. The views expressed in this paper do not necessarily represent the views or policies of the ministry or the government.

Read the full report below.

This report is a part of the Pharos Series, a series shedding light on cybersecurity and emerging technology challenges. The series aims to offer clear expert insights helping policymakers, researchers, and practitioners navigate evolving threats.

Authors

Max Smeets

Co-Director, Community Trustee

Jamie MacColl

Senior Research Fellow
Royal United Services Institute

Sophie Williams-Dunning

Research Analyst, Cyber and Tech team
Royal United Services Institute

Bob Herczeg

Executive Support and Research Officer

Similar posts

Research & Analysis

Three insights from the latest countermeasures tracker update

We have updated the Virtual Routes Ransomware Countermeasures Tracker with over 50 new cases from the period between May and November 2025.
Research & Analysis

Apolline Rolland presents REMIT research at the 2025 Conference on International Cyber Security

At the 2025 Conference on International Cyber Security, we joined a vibrant discussion on how states, technologies, and private actors are reshaping the boundaries of espionage and governance in the digital realm, representing EU-funded REMIT project.
Research & Analysis

OSCE publishes a new Handbook on National Cyber Incident Classification, written by Virtual Routes Co-Director James Shires

The handbook is divided into six steps, from setting the goals and engaging stakeholders to implementing, testing and refining the system.

Thank you for signing up to our newsletter!

Thank you! RSVP received for Pharos Report No. 4 | Assessing the Impact of Ransomware Interventions and Countermeasures: A Framework

Pharos Report No. 4 | Assessing the Impact of Ransomware Interventions and Countermeasures: A Framework

Loading...

Loading…