NotPetya, WannaCry and BadRabbit
You have understood well that the above are ransomware names that have so far caused damages of billions of dollars in accounts, which spread from hundreds of organizations, public and private, in more than 60 countries.
The hospitals must remove patients from emergency areas, bank customers who cannot access their funds, and large shipping ports that cannot load or unload cargo – these are only a few of the results that were achieved by keeping the data required for businesses in “omphria”. For accuracy, first by encrypting this data and then selling the decryption keys back to the infected central computer, the above examples were carried out.

Arizona Beverages, the company behind Arizona's Iced Tea, had become the target of such an attack in March 2019. The attack caused sales problems according to rumors. “We lost millions of dollars a day in sales” the company said.
There is a possibility that the ransomware, which reached over 200 servers and networked computers, was delivered via a malicious email attachment.
Explosive growth
The recent development of ransomware personnel and attacks is not a coincidence. The following factors have contributed to this:
- The online hacker group, known as TheShadowBrokers, amassed a treasure of tools and exploits developed by the NSA, the so‑called dumping, and sold them in 2016 and 2017.
- The invention of “digital scarcity”, in the form of cryptocurrencies, as a way to transfer value over the internet (anonymously and pseudonymously) and to generate revenue from security vulnerabilities.
Measuring the cost
The biggest cost of a ransomware attack for a victim is rarely the ransom itself (if paid), but the damage caused to an organization’s operations and the cost to get it running properly again. These actions include necessary security upgrades, lost revenue, reputation damage and staff retraining. FedEx, Maersk (shipping) and Merck (pharmaceutical), just three of the many victims of the NotPetya attack, are expected to ultimately lose a combined $1.5 billion.
The most concerning part of all this is that ransomware is not always targeted. It can spread organically and indiscriminately through the digital installations that connect your company with one of the suppliers, customers, or your employees. Additionally, it is worth noting that the cost of pushing ransomware to an additional organization is close to zero. The cost also does not differ for an intruder whether your company is worth thousands of dollars or billions of dollars (although the expected ransom amount will vary greatly).
Stay a small company
We are in an era where size no longer provides the same strategic advantage it once did. It is important to know the industries, geographic regions and business models where increasing size can be correlated with increased exposure to virtual attacks. Small businesses have lower rates of ransomware. A hacker seeking ransom can only demand what an organization can endure without conceding, otherwise both will be left empty‑handed.
Hiding at a simple glance
“Information technology is portable, meaning it can operate independently of location and increase the mobility of ideas, people and capital” says Davidson & Rees-Mogg.
As more and more organizations evolve to become technology companies at their core, with global reach, they use methods that match these new demands. Dispersed offices without a central building, remote workforce of freelancers, external suppliers and distributors, leased equipment and infrastructure, contracted service providers and subscriptions – the form in which an organization can become opaque. These measures, when combined, reduce the digital visibility of your operations.
Keep a low profile
A brand-centric organization carries value in the form of goodwill. Goodwill is something that needs to be constantly protected, and an attacker knows this. It has been revealed that Marriott Hotels, through its Starwood subsidiary, has now potentially exposed 327 million passport numbers between 2014 and 2016 in a massive data breach. Rumor has it that this wasn’t caused by ransomware, but the blow to the company is the same, and the company will be trying to rebuild trust for decades to come. Now imagine if the same thing were to happen to INTL FCStone. Have you ever heard of them? I haven’t. Probably because they don’t need me to know who they are to be successful. But they made $29 billion in 2017, are based in New York, and all this with less than 15K followers on Twitter.
