Resource Library
ReportsIncident ResponseSegmentationFebruary 15, 2024

Ransomware Research Report Infographic

Report

Ransomware in Focus

What CISOs Have to Say

Seeking to cut through the headlines and hype surrounding the topic, we surveyed over 250 Chief Information Security Officers (CISOs) in August 2021 to learn firsthand about their ransomware experience, concerns, and plans for protecting their organizations going forward.

No Relief in Sight

Metric

Overall

Mid-Sized Organizations (1,000–10,000 employees)

Hit at least once by a ransomware attack in the past 12 months

53%

66%

Expect to be hit at least once by a ransomware attack in the next 12 months

69%

80%

Top 3 industries expecting to be hit by ransomware in the next 12 months:

  • Construction & Machinery — 92%
  • Retail & Consumer Durables — 83%
  • Manufacturing — 79%

Cost of Ransom Is NOT a Major Concern

Ransomware impacts of greatest concern:

  • #1 — Exposure of sensitive or proprietary data
  • #2 — Costs of recovering/restoring to normal operations
  • #3 — Loss of revenue due to operational disruptions

Ransomware impacts of least concern:

  • #9 — Loss of employee productivity
  • #10 — Costs of paying the ransom
  • #11 — Cost of regulatory/compliance fines

Ransomware Roulette

Outcome of Paying the Ransom

Share of Victims

Led to full recovery of data

55%

Led to partial recovery of data

34%

Led to no recovery of data

11%

1 in 5 ransomware victims had an impact of $5M+. 1 in 20 ransomware victims had an impact of $50M+.

Defenders at the Gate

Technical countermeasures of greatest importance for mitigating against ransomware attacks:

  • Data backup & recovery
  • Email security (with phishing detection)
  • Endpoint protection platform (EPP)
  • User awareness and training

Top technical countermeasures being added to ransomware defenses in the next 12 months:

  • User and entity behavior analytics (UEBA)
  • Network segmentation / Zero Trust access
  • Data loss/leak prevention (DLP)

A Silver Lining … of Sorts

It appears that the high-profile, high-impact nature of ransomware is helping elevate cybersecurity as a Board-level issue.

Most significant obstacles to achieving effective ransomware defenses:

  • Difficulty implementing tools/technologies
  • Lack of skilled personnel to implement solutions
  • Other conflicting priorities

Least significant obstacles to achieving effective ransomware defenses:

  • Difficulty justifying related budget request
  • Lack of support from the Board

Source: Ransomware in Focus, CISOs Connect, 2021. Copyright © 2021 CISOs Connect. All Rights Reserved.

Frequently asked questions
What ransomware defense priorities do security leaders recommend?
ORDR's research of 250+ security leaders identifies the most critical defense priorities across government, healthcare, manufacturing, education, and financial sectors. The report reveals which defense strategies security professionals prioritize most based on their industry vertical and attack exposure.
How do my organization's ransomware recovery outcomes compare to peers?
This report provides benchmarking data that allows you to compare your organization's ransomware recovery strategies and outcomes against surveyed peer organizations in your sector. Understanding peer responses helps identify gaps in your incident response and recovery capabilities.
What emerging ransomware attack trends should shape my strategy?
ORDR's research reveals emerging attack trends that are reshaping ransomware defense strategies across critical infrastructure sectors. By understanding these trends, organizations can proactively adjust their incident response and segmentation strategies before threats escalate.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →