{"id":21975,"date":"2023-05-11T09:46:47","date_gmt":"2023-05-11T17:46:47","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/05\/11\/news-15706\/"},"modified":"2023-05-11T09:46:47","modified_gmt":"2023-05-11T17:46:47","slug":"news-15706","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/05\/11\/news-15706\/","title":{"rendered":"The State of Ransomware 2023"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/05\/SoR-2023-blog-image.png\"\/><\/p>\n<p><strong>Credit to Author: Sally Adam| Date: Wed, 10 May 2023 10:00:19 +0000<\/strong><\/p>\n<div class=\"entry-content lg:prose-lg mx-auto prose max-w-4xl\">\n<p>Sophos has released its annual <a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/c949g7693gsnjh9rb9gr8\/sophos-state-of-ransomware-2023-wp.pdf\"><span data-ccp-charstyle=\"Hyperlink\">State of Ransomware 2023<\/span><\/a><span data-contrast=\"auto\"> report, revealing deep insights into the ransomware challenges facing businesses today based on a survey of 3,000 IT\/cybersecurity professionals across 14 countries.<\/span><\/p>\n<h2>Attack rates remain level, but data encryption has increased<\/h2>\n<p>66% of organizations surveyed said they were hit by ransomware in the last year. This is the same attack rate as reported in our 2022 study, suggesting that the rate of ransomware attacks has remained steady despite any perceived reduction in attacks. <span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">The education sector reported the highest level of ransomware attacks, with 79% of higher education organizations surveyed<\/span> and 80% of lower education organizations surveyed saying that they were victims of ransomware. <span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p>Data encryption from ransomware is at the highest level in four years with adversaries succeeding in encrypting data in 76% of attacks. Furthermore, in 30% of cases where data was encrypted, data was also stolen, suggesting this \u201cdouble dip\u201d method (data encryption and data exfiltration) is becoming commonplace<span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">. <\/span><\/p>\n<p>The most common reported root cause of attack was an exploited vulnerability<span data-ccp-parastyle=\"heading 1\"> (involved in 36% of cases), followed by compromised credentials (involved in 29% of cases). This is in line with <\/span><span data-ccp-parastyle=\"heading 1\">recent, in-the-field <\/span>incident response <span data-ccp-parastyle=\"heading 1\">findings<\/span><span data-ccp-parastyle=\"heading 1\"> from <\/span><span data-ccp-parastyle=\"heading 1\">Sophos\u2019 <\/span><a href=\"https:\/\/news.sophos.com\/en-us\/2023\/04\/25\/2023-active-adversary-report-for-business-leaders\/\"><span data-ccp-charstyle=\"Hyperlink\">2023 Active Adversary Report for Business Leaders<\/span><\/a><span data-contrast=\"none\"> report.<\/span><\/p>\n<h2>Paying the ransom doubles recovery costs<\/h2>\n<p><span data-contrast=\"none\">Overall, 46% of organizations surveyed that had their data encrypted paid the ransom and got data back. Larger organizations were far more likely to pay with more than half of businesses with revenue of $500 million or more admitting that they paid the ransom. <\/span><\/p>\n<p><span data-contrast=\"none\">However, the survey also shows that when organizations paid a ransom to get their data decrypted, they ended up doubling their non-ransom recovery costs ($750,000 in recovery costs versus $375,000 for organizations that used backups to get data back). <\/span><\/p>\n<p>Moreover, paying the ransom usually meant longer recovery times, with 45% of those organizations that used backups recovering within a week, compared to 39% of those that paid the ransom.<span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">\u00a0<\/span><em>\u201cIncident costs rise significantly when ransoms are paid. Most victims will not be able to recover all their files by simply buying the encryption keys; they must rebuild and recover from backups as well. Paying ransoms not only enriches criminals, but it also slows incident response and adds cost to an already devastatingly expensive situation.\u201d<\/em><\/p>\n<p><em>Chester Wisniewski, field CTO, Sophos<\/em><span data-contrast=\"none\">\u00a0<\/span><\/p>\n<h2>Mitigating the ransomware risk<\/h2>\n<p>Megan Stifel, executive director of the Ransomware Task Force and chief strategy officer, Institute for Security and Technology comments:<\/p>\n<p><em>\u201cSophos\u2019 latest report is a clarion reminder that ransomware remains a major threat, both in scope and scale. This is particularly true for \u2018target-rich, resource-poor\u2019 organizations that don\u2019t necessarily have their own in-house resources for ransomware prevention, response and recovery.<\/em><\/p>\n<p><em>One way to boost security, which is aligned with Sophos\u2019 findings in the report, is to implement the <a href=\"https:\/\/securityandtechnology.org\/ransomwaretaskforce\/blueprint-for-ransomware-defense\/\">Ransomware Task Force\u2019s Blueprint for Ransomware Defense<\/a>, a framework of 48 safeguards\u00a0based on the CIS IG1 Controls. It\u2019s past time for the private and public sector to band together and collectively fight ransomware, which is why we are excited to work with cybersecurity providers like Sophos.\u201d\u00a0<\/em><\/p>\n<p><span data-contrast=\"none\">\u00a0Additionally, <\/span><span data-contrast=\"none\">Sophos recommends the following best practices to help defend against ransomware and other cyberattacks:<\/span><\/p>\n<ol>\n<li><span style=\"font-size: 1em\">Strengthen defensive shields, including:\u00a0<\/span>\n<ul>\n<li><span data-contrast=\"none\"> Security tools that defend against the most common attack vectors, including <\/span><a href=\"https:\/\/www.sophos.com\/en-us\/products\/endpoint\"><span data-ccp-charstyle=\"Hyperlink\">endpoint protection<\/span><\/a><span data-contrast=\"none\"> with strong anti-exploit capabilities to prevent exploitation of vulnerabilities, and <\/span><a href=\"https:\/\/www.sophos.com\/en-us\/products\/zero-trust-network-access\"><span data-ccp-charstyle=\"Hyperlink\">Zero Trust Network Access<\/span><\/a><span data-contrast=\"none\"> (ZTNA) to thwart the abuse of compromised credentials\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\"> Adaptive technologies that respond automatically to attacks, disrupting adversaries and buying defenders time to respond\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\"> 24\/7 threat detection, investigation and response, whether delivered in-house or by a specialist <\/span><a href=\"https:\/\/www.sophos.com\/en-us\/products\/managed-detection-and-response\"><span data-ccp-charstyle=\"Hyperlink\">Managed Detection and Response<\/span><\/a><span data-contrast=\"none\"> (MDR) provider <\/span><\/li>\n<\/ul>\n<\/li>\n<li>Optimize attack preparation, including making regular backups, practicing recovering data from backups and maintaining an up-to-date <span style=\"font-size: 1em\" data-contrast=\"auto\">incident response plan\u00a0<\/span><\/li>\n<li><span data-contrast=\"none\"> Maintain good security hygiene, including timely patching and regularly reviewing security tool configurations<\/span><\/li>\n<\/ol>\n<h2><strong>About the survey<\/strong><\/h2>\n<p>Data for the State of Ransomware 2023 report comes from a vendor-agnostic survey of 3,000 cybersecurity\/IT leaders conducted between January and March 2023. Respondents were based in 14 countries across the Americas, EMEA and Asia Pacific. Organizations surveyed had between 100 and 5,000 employees, and revenue ranged from less than $10 million to more than $5 billion.<span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"none\">Read the <\/span><a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/c949g7693gsnjh9rb9gr8\/sophos-state-of-ransomware-2023-wp.pdf\"><span data-ccp-charstyle=\"Hyperlink\">State of Ransomware 2023<\/span><\/a><span data-contrast=\"none\"> report for global findings and data by sector.\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}\">\u00a0<\/span><\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.sophos.com\/en-us\/2023\/05\/10\/the-state-of-ransomware-2023\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2023\/05\/SoR-2023-blog-image.png\"\/><\/p>\n<p><strong>Credit to Author: Sally Adam| Date: Wed, 10 May 2023 10:00:19 +0000<\/strong><\/p>\n<p>The latest edition of Sophos\u2019 annual ransomware study reveals the reality facing organizations in 2023, including the frequency, cost and root cause of attacks.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[19253,29352,129,24562,3765,1931,10752],"class_list":["post-21975","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-credentials","tag-encryption-featured","tag-featured","tag-products-services","tag-ransomware","tag-research","tag-vulnerabilities"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21975","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21975"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21975\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21975"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21975"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}