HomeSecurityGovernment agencies: Why are they vulnerable to ransomware attacks?

Government agencies: Why are they vulnerable to ransomware attacks?

Ransomware is one of the most significant cyber threats and despite the enormous damage it can cause, government agencies are still not adequately protected.

According to Emisoft , at least 948 government agencies, educational institutions, and healthcare providers were targeted by ransomware in 2019. On the other hand, Recorded Future ’s analysis showed that there were 81 successful ransomware attacks on US government agencies , affecting many small towns in the wider region.

Florida , Louisiana , New Orleans , and Texas are just a few of the local governments that have been hit by such an attack. If ransomware infiltrates a government network , it can cause a number of problems, including: system outages for the agency or even the entire city, loss of access to central government systems , financial losses, etc.

According to IBM, many US local and state governments feel very confident about their security against malware, but Deloitte says that in reality governments are not doing enough to protect themselves.

On Wednesday, Deloitte published a reportthat examines how ransomware attacks and what government officials can do to address this challenge and protect themselves.

According to researchers, local and state governments are now providing their services online. This, combined with the increased emergence of Ransomware-as-a-Service (RaaS), offers hackers more opportunities to attack.

“A few decades ago, there were only a few computers in the headquarters of local schools or police departments, but today there are computers,” the report says. “Each of these computers is a potential access point for malware.” According to the researchers, this means that government agencies now have many more systems to protect, but without a corresponding investment in cybersecurity.

But there is another key reason why governments are vulnerable to ransomware and other hacking attacks. That reason is the use of old, outdated, and outdated systems and software. All of these systems can have vulnerabilities that hackers.

Government agencies: Why are they vulnerable to ransomware attacks?

“Even current, up-to-date networks require ongoing effort to maintain security patches and settings, a task that even the most well-staffed and trained personnel find difficult,” says Deloitte.

However, the research highlights that the most important factor in the success of ransomware attacks is people , not systems. Without skilled personnel and overall awareness of cybersecurity, hackers can carry out successful attacks. Phishing and social engineering are two techniques that are often used, and their success depends on how users.

A survey conducted by NASCIO and Deloitte found that in government agencies, only 2% of the total IT budget is used for cybersecurity.

So the appropriate infrastructure is not in place, and governments are forced to pay the ransom if they fall victim to a ransomware attack. Many times there are no backups either.

In the meantime, not paying the ransom could prove significantly more costly.

An example is the city of Baltimore, which refused to pay the ransom ($76,000), but lost over $18 million due to lost revenue and investments in systems recovery.

Ransomware is not going away anytime soon, so ways to combat it need to be found.

So what can state and local governments do to address the problem?

Modernization of systems: Modernization of IT systems is important. The systems used by services must be modern and up-to-date to prevent the significant problems that ransomware can cause them.

Staff training: education and training is crucial, since as we said, the human factor plays a role in the success of ransomware attacks.

Patches and updates: Services must constantly update their systems. They also need to segment their data and networks.

Cyberinsurance: While cyberinsurance services can cover the costs of ransomware attacks, their use should be considered with caution. These services usually encourage customers (victims of the attack) to pay the ransom. Hackers know this, so they step up and demand even more money.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS