Ransomware in Focus
What CISOs Have to Say
Seeking to cut through the headlines and hype surrounding the topic, we surveyed over 250 Chief Information Security Officers (CISOs) in August 2021 to learn firsthand about their ransomware experience, concerns, and plans for protecting their organizations going forward.
No Relief in Sight
Metric | Overall | Mid-Sized Organizations (1,000–10,000 employees) |
Hit at least once by a ransomware attack in the past 12 months | 53% | 66% |
Expect to be hit at least once by a ransomware attack in the next 12 months | 69% | 80% |
Top 3 industries expecting to be hit by ransomware in the next 12 months:
- Construction & Machinery — 92%
- Retail & Consumer Durables — 83%
- Manufacturing — 79%
Cost of Ransom Is NOT a Major Concern
Ransomware impacts of greatest concern:
- #1 — Exposure of sensitive or proprietary data
- #2 — Costs of recovering/restoring to normal operations
- #3 — Loss of revenue due to operational disruptions
Ransomware impacts of least concern:
- #9 — Loss of employee productivity
- #10 — Costs of paying the ransom
- #11 — Cost of regulatory/compliance fines
Ransomware Roulette
Outcome of Paying the Ransom | Share of Victims |
Led to full recovery of data | 55% |
Led to partial recovery of data | 34% |
Led to no recovery of data | 11% |
1 in 5 ransomware victims had an impact of $5M+. 1 in 20 ransomware victims had an impact of $50M+.
Defenders at the Gate
Technical countermeasures of greatest importance for mitigating against ransomware attacks:
- Data backup & recovery
- Email security (with phishing detection)
- Endpoint protection platform (EPP)
- User awareness and training
Top technical countermeasures being added to ransomware defenses in the next 12 months:
- User and entity behavior analytics (UEBA)
- Network segmentation / Zero Trust access
- Data loss/leak prevention (DLP)
A Silver Lining … of Sorts
It appears that the high-profile, high-impact nature of ransomware is helping elevate cybersecurity as a Board-level issue.
Most significant obstacles to achieving effective ransomware defenses:
- Difficulty implementing tools/technologies
- Lack of skilled personnel to implement solutions
- Other conflicting priorities
Least significant obstacles to achieving effective ransomware defenses:
- Difficulty justifying related budget request
- Lack of support from the Board
Source: Ransomware in Focus, CISOs Connect, 2021. Copyright © 2021 CISOs Connect. All Rights Reserved.