Legal Reclassification of Global Ransomware as Corporate Risk
DOI:
https://doi.org/10.59022/iijcl.3Keywords:
Ransomware, Corporate Governance, Legal Reclassification, Fiduciary Duty, Cybersecurity Disclosure, Shareholder Protection, Director AccountabilityAbstract
Ransomware attacks cause severe financial and reputational damage to global corporations annually. Legal systems classify ransomware primarily as criminal conduct, ignoring broader corporate governance failures. This research examines how legal reclassification could clarify director accountability and disclosure obligations. Current corporate law lacks clear standards addressing cybersecurity preparedness and fiduciary duty. Shareholders face limited remedies challenging inadequate board oversight following major ransomware incidents. Insurance markets struggle pricing risk without consistent legal liability standards across jurisdictions. This study analyzes existing legal frameworks, identifying significant gaps between criminal and corporate law. Findings reveal fragmented disclosure requirements, weak fiduciary recognition, and inconsistent regulatory enforcement globally. This research proposes reclassifying ransomware as formal corporate risk within governance frameworks. Such reclassification would strengthen director accountability, shareholder protection, and insurance market stability. The study offers practical recommendations for policymakers, courts, and corporate boards. This framework connects fragmented legal domains, addressing modern digital security challenges comprehensively and effectively.
References
Andre Yosua, M., &Hardianto, S. (2024). The role of criminal law in combating corporate crime that harms the public interest. Global International Journal of Innovative Research, 2(11), 2616–2625. https://doi.org/10.59613/global.v2i11.364
Ashraf, M., & Sunder, J. (2023). Can shareholders benefit from consumer protection disclosure mandates? Evidence from data breach disclosure laws. The Accounting Review, 98(4). https://doi.org/10.2308/TAR-2020-0787
Bello, A.-W., Wonuola, I., Izundu, A. C., &Izundu, J. C. (2025). Cybersecurity threats in the financial sector: Analyzing attack types, vulnerabilities, and response mechanisms across geopolitical contexts (2015–2024). International Journal of Science and Research Archive, 16(1), 134–150. https://doi.org/10.30574/ijsra.2025.16.1.2007
Cremer, F., Sheehan, B., Fortmann, M., Kia, A. N., Mullins, M., Murphy, F., & Materne, S. (2022). Cyber risk and cybersecurity: A systematic review of data availability. The Geneva Papers on Risk and Insurance – Issues and Practice, 47(3), 698–736. https://doi.org/10.1057/s41288-022-00266-6
Elsayed, D. H., Ismail, T. H., & Ahmed, E. A. (2024). The impact of cybersecurity disclosure on banks’ performance: The moderating role of corporate governance in the MENA region. Future Business Journal, 10(1), 115. https://doi.org/10.1186/s43093-024-00402-9
Gale, M., Bongiovanni, I., & Slapničar, S. (2022). Governing cybersecurity from the boardroom: Challenges, drivers, and ways ahead. Computers & Security, 121. https://doi.org/10.1016/j.cose.2022.102840
Hayes, C. (2026). Evolving threats, evolving duties: Ransomware, artificial intelligence, and cybersecurity law. Case Western Reserve Journal of Law, Technology & the Internet, 17(1), A5. https://scholarlycommons.law.case.edu/jolti/vol17/iss1/5
Hayes, C. (2026). Evolving threats, evolving duties: Ransomware, artificial intelligence, and cybersecurity law. Case Western Reserve Journal of Law, Technology & the Internet, 17, A5. https://scholarlycommons.law.case.edu/jolti/vol17/iss1/5
He, Q., Faure, M., & Chen, C. Y. (2025). Insuring the “uninsurable” cyberwarfare: Rethinking war exclusions in cyber policies and the role of insurance in global cybersecurity governance. The Geneva Papers on Risk and Insurance – Issues and Practice, 50, 470–501. https://doi.org/10.1057/s41288-025-00346-3
Irvita, M., & Asriani, A. (2025). Transparency and accountability in the justice system: Building public trust and justice: The role of public trust in fair law enforcement. Priviet Social Sciences Journal, 5(4), 26–40. https://doi.org/10.55942/pssj.v5i4.367
Jaffe, J., &Floridi, L. (2024). Ransomware: Why it’s growing and how to curb its growth. Applied Cybersecurity & Internet Governance. https://doi.org/10.60097/ACIG/192959
Khan, M. N. I., & Rabbi, M. S. (2024). Cybercrime, legal accountability, and contractual risk: A systematic review of jurisprudence and protective frameworks. American Journal of Advanced Technology and Engineering Solutions, 4(1), 71–100. https://doi.org/10.63125/228bwz17
Liu, C., & Babar, M. A. (2026). Corporate cybersecurity risk and data breaches: A systematic review of empirical research. Australian Journal of Management, 51(1), 62–92.https://doi.org/10.1177/03128962241293658
Phipps, A., & Nurse, J. R. C. (2025). Inside ransomware groups: An analysis of their origins, structures, and dynamics. Computers & Security. Advance online publication. https://doi.org/10.1016/j.cose.2025.104705
Qureshy, A. (2023). Director duties and shareholder protection within the modern enlightened paradigm. SSRN Electronic Journal. https://doi.org/10.2139/ssrn.4630607
Rakha, N. A. (2022). Significance of regulation for enhancing online activity. Web of Scientist: International Scientific Research Journal, 3(5), 1854–1859.https://api.ziyonet.uz/uploads/books/10001253/cbgt9bl0j0Inb1j.pdf
Rakha, N. A. (2023). Artificial intelligence strategy of Uzbekistan: Policy framework, preferences, and challenges. International Journal of Law and Policy, 1(2). https://doi.org/10.59022/ijlp.27
Simanjuntak, S. Y., & Waluyo, B. (2025). Criminal liability for hacking personal data through ransomware attacks on digital service providers in Indonesia. Jurnal Daulat Hukum, 8(4), 851. https://doi.org/10.30659/jdh.v8i4.48885
Song, Y., Sheedy, E. A., & Yu, F. (2026, June 10). Voices from Australian industries: Understanding cybersecurity disclosure (SSRN Working Paper No. 6909958). SSRN. https://doi.org/10.2139/ssrn.6909958
Tariq, A. (2025). Mandatory sustainability reporting and the disclosure-performance gap: Insights from the EU directive. Meditari Accountancy Research. Advance online publication. https://doi.org/10.1108/MEDAR-02-2025-2838
Teichmann, F. (2026). International legal responses to ransomware: Toward a ban on payments? International Cybersecurity Law Review, 7, 41–68. https://doi.org/10.1365/s43439-025-00167-z
Teichmann, F., & Wittmann, C. (2022). When is a law firm liable for a data breach? An exploration into the legal liability of ransomware and cybersecurity. Journal of Financial Crime, 30(6), 1491–1498. https://doi.org/10.1108/JFC-04-2022-0093
Tsohou, A., Diamantopoulou, V., Gritzalis, S., &Lambrinoudakis, C. (2023). Cyber insurance: State of the art, trends and future directions. International Journal of Information Security, 22(3), 737–748. https://doi.org/10.1007/s10207-023-00660-8
Umeanozie, C. P., & Akana, C. (2025). Cybersecurity and critical infrastructure: Legal obligations under the Cyber Incident Reporting for Critical Infrastructure Act, 2022.
Vidović, N., Cvetković, V. M., Beriša, H., &Milašinović, S. (2025). Understanding ransomware through the lens of disaster risk: Implications for cybersecurity and economic stability (Preprint). https://doi.org/10.20944/preprints202504.1950.v1
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Malgozata Stvol (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.


