So in Columbia, did they solve the problem my making paying ransom illegal? That's a rhetorical question as that is not how the problem was solved. So what is the point of the comparison? To show you don't need laws to prevent paying ransom to solve the problem? In that case, I agree!
I agree with what needs to be accomplished, I just disagree punishing victims is a valid and reasonable way to get there. Unlike failed states, there are reasonable technical solutions to preventing and recovering from ransomware attacks that can significantly limit their effectiveness. Companies will adapt and ransomware will decline over time. Maybe not today or tomorrow or next year, but in the not too distant future. Remember when some new virus was in the news every day? Especially in the Windows 95/98 days... Operating systems became more secure and anti-virus software got better. The same will happen with ransomware.
I've only skimmed the video so far but I'm not contesting that ransomware is a problem. I'm just contesting your proposed solution. I might contest some of the numbers presented in that video though. 75,000 attacks daily I believe. That the ransom amounts only fall in the range of 200,000 and up I don't believe. In fact, i know otherwise so I'm not sure where those arbitrary numbers came from...maybe it was referring to attacks only on corporations and not on individuals? And the cost of ransomware in 2031 is unknowable but I would be willing to bet that technical solutions, education and improved procedures would keep it well below the amount stated in the video by then. While it can be more complicated that it sounds, all companies and individuals really have to do to mitigate such attacks is to keep frequent backups of important data. Restoring from a recent backup has to be cheaper than paying a ransom and waiting (hopefully) for decryption.
You still haven't explained how government would be able to enforce such laws given both the victim and the attacker would be disinclined to let government know about it. Or, if you want to extend such laws to kidnappings, why on earth you think people would pay attention to such laws when trying to save their loved ones.
Your examples as far as "material support to the enemy" are off base. People aren't paying ransoms to commit treason, they are doing it to save their company, irreplaceable data, loved ones, or whatever it is they are trying to save. If the government considers these people "the enemy" then I suggest they destroy the enemy. Not their victims. Which is very well what such laws might do. By this logic, if a thief had me at gunpoint and I gave him money then I would go to jail and i should have just let him kill me instead. After all, giving him the money is "giving material support to the enemy".
If the law by itself prevents such attacks, then the point is moot. No one would ever have to break the law because they wouldn't be attacked. If they are attacked, then clearly such a law did not help them and in fact potentially causes great harm if obeyed.
Oh, and apparently paying ransom is already illegal according to https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u-s-dept-of-treasury-warns/ and https://home.treasury.gov/system/files/126/ofac_ransomware_advisory_10012020_1.pdf
Has it helped?
RE: Paying Ransomware Should be Illegal