More and more large companies have been falling victim to ransomware attacks lately.

Garmin is still recovering from a ransomware outage. Australia, has seen a spike in ransomware attacks on major companies like Toll and Lion. Toll has recently recovered from an attack .
All of these incidents have alarmed JLLMark Smink, who said the ransomware pandemic has evolved a lot compared to four or five years ago.
“I am particularly concerned that Fortune 500 companies are being actively targeted and experiencing as much damage as possible,” he said.
“It is worrying how close these incidents are happening to us.”
One way to cope with this situation, according to Smink, is a coordinated approach between technology, people and processes.
Taking it a step further, Cisco Australia cybersecurity director Steve Moros said the industry itself will need to evolve, as a low-profile approach to defending against ransomware is no longer effective.

“I don’t think [ransomware] can stop in terms of people developing the sophistication and the techniques and the persistence of these types of attacks, so I think it’s here to stay. If we take into account the history so far, it’s going to continue to evolve,” he said.
“The security industry needs to evolve and when it comes to security solutions, we need to work as a team and that means communicating in real time and learning from each other and then having a coordinated response to these attacks.”
Last week, a report by the industry advisory panel, which will feed into the federal government's upcoming Cyber Security 2020 , recommended that large businesses receive incentives to support smaller businesses in their supply chain and customer base.
For Moros, this is about sharing information.
“From an economic perspective, a smaller organization working with a larger one is the weakest link, because it is a trusted connection that can be compromised to carry out an attack on a larger organization,” he said.
For this reason, he said that smaller businesses should receive help from larger ones regarding best practices for security, so that the entire system is secured and there are no gaps that can be exploited by cybercriminals.
