Annapolis, MD – The information technology field is incredibly vast and varied, involving hundreds of different types of jobs and job sectors. One of the most challenging and most important sectors of IT is security. In an ever-evolving digital landscape, it’s imperative for both small businesses and large corporations to have cyber security that goes above and beyond standard regulations. And while laws aren’t always in sync with what’s new in cyber crime, Maryland lawmakers are now introducing a bill that would carry harsh penalties for those who orchestrate ransomware attacks.

Ransomware is aptly named: it’s a type of malicious software that takes control of an individual or business’s hardware or personal data until a specific code is given to unlock it. In order for victims to obtain this code, they’re extorted for ransom by the cyber perpetrators — many times, for hundreds to tens of thousands of dollars. However, even when victims pay the ransom, some criminals will delete data or completely wipe out an entire system, leaving victims with nothing.

Under current Maryland law, these types of attacks are covered by extortion statutes. If a victim loses property, labor, or services with a value of less than $1,000, these crimes are classified as misdemeanors. And because many of these criminals are located outside the country, both victims and law enforcement agencies are often left helpless.

But in a new bill being introduced to the Maryland General Assembly, these crimes would carry much stricter penalties. The bill would define all ransomware attacks as felonies, which would carry a fine of up to $10,000 and up to 10 years in jail. In contrast, current penalties can range anywhere from a $1,000 to $25,000 fine and 18 months to 25 years in prison, depending on the scope of the crime itself.

This new bill would also allow the victims to file a damage suit in civil court. This would allow victims a viable alternative to waiting on state prosecutors and still get the recompense they deserve.

The bill would be a very important development for businesses, libraries, and hospitals, as ransomware attacks can be devastating for these organizations. Just last year, a network of Maryland hospitals was impacted by such a breach. Hospitals in the MedStar Health Network had to take their email and EHR systems offline to prevent the spread of the virus. Staff members couldn’t book appointments, access computer files, or even turn on their devices.

While this was an extreme case, it’s by no means a rare one. Since security incidents like these cause an average ย downtime of more than eight hoursย for 31% of impacted organizations, harsh penalties for cyber criminals can allow businesses to recover at least a portion of their losses.

Still, ransomware can be particularly tricky to track, and the law can’t cover every possible scenario. Some ransomware requires its victims to view web pages; these views boost ad and site revenue, but that value is difficult to calculate and factor into the scope of a crime. And because one ransomware attack is never exactly the same as another, judges and prosecutors would be chiefly responsible for how this law is interpreted.

There will always be new challenges in the realm of cyber crime, but at least Maryland legislators are doing their part to catch up and fight back against these malicious attacks.