Case Studies

Ransom response survey

by Mark Rowe

Authorities – in the United States, the Director of the FBI, the US Attorney General and the White House – warn against paying cyber-related ransoms. However, a majority, 60 percent of organisations have admitted they would shell out funds in the event of an attack, according to new research from the Neustar International Security Council (NISC). When asked how much money they would consider handing over, one in five respondents said they would consider paying 20 percent or more of their company’s annual revenue.

The study, which was commissioned by Neustar and run by Harris Interactive, comes just days after US meat-processing company JBS confirmed that it had paid $11 million to the REvil ransomware criminals, which locked its systems at the end of May. Meanwhile, Japanese multinational conglomerate, Fujifilm said it had refused to pay a ransom demand to the cyber criminals that attacked its network in Japan, instead relying on back-ups to restore operations.

Given high-profile attacks, 80 percent of cyber security people surveyed reported placing more emphasis on protecting against ransomware threats. When questioned about the technologies available to help them do so, the majority (74pc) of respondents found current solutions to be either ‘very’ or ‘somewhat’ sufficient in detecting, preventing, and mitigating attacks. A quarter (26pc), however, perceived the technologies available to be ‘somewhat’ or ‘very’ insufficient.

Rodney Joffe, NISC Chairman, SVP and Fellow at Neustar saidd: “Companies must unite in not paying ransoms. Attackers will continue to increase their demands for ever larger ransom amounts especially if they see that companies are willing to pay. This spiral upwards must be stopped. The better alternative is to invest proactively in mitigation strategies before the attacks, including the use of qualified providers of “always-on” monitoring and filtering of traffic as part of a layered security approach.”

During March and April, most, 69pc of respondents perceived ransomware as an increasing threat to their organisation, marking their top concern across more than a dozen threat vectors and representing a 16pc spike in the average survey response over a two-year period.

This escalated concern followed a warning from the UK official National Cyber Security Centre (NCSC) in March in response to ransomware attacks being carried out on the UK education sector.

Joffe added: “With less than three in ten (28pc) cybersecurity professionals feeling very confident that all members of their organisation know the appropriate measures to take in the event of a ransomware attack, it’s no surprise that the level of concern is rising. Given that more than a third (35pc) also perceive guidance from government/official bodies to be insufficient it’s essential that organisations take matters into their own hands and educate all their employees on best practice cybersecurity processes.”

Related News

  • Case Studies

    Crime maps hailed

    by Mark Rowe

    The police.uk website has been revamped with new functions, offering access to information about crime. Functions new include: Email alerts informing people…

  • Case Studies

    Screening for One Love

    by Mark Rowe

    The ThruVis thermal screening cameras from Digital Barriers plc were deployed by contractor G4S for the Manchester “One Love” Concert at the…

  • Case Studies

    Data breach report

    by Mark Rowe

    Massive data breaches are degrading the personal privacy of people, say researchers from the Central European University, in Budapest. The study was…

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing