Two-fifths of UK have suffered at least one ransomware attack in the last year, although they are less likely to give in and pay the ransom. However, those that have paid have given some of the highest amounts, according to CrowdStrike.

As part of the “Global Security Attitude Survey 2020”, the security spoke to 2200 decision-makers and security professionals from around the world (200 from the UK).
According to researchers, the increase in ransomware attacks over the past year could be a result of the pandemic, which created security gaps. Many organizations focused on digital transformation to meet new work demands. In addition, there was a massive shift to remote work, which cybercriminals exploited.
In fact, 63% of respondents in the UK agreed that there is a greater risk of ransomware or other attacks due to the pandemic crisis. The average time it takes UK organisations to detect a security incident has increased by 56% since 2019, giving attackers an advantage.
On the positive side, just 13% of UK companies have paid the ransoms demanded by ransomware gangs. This is the lowest rate in the world and around half the global average (27%).

CrowdStrike's EMEA CTO, Zeki Turedi, claimed that this figure may indicate that UK companies have improved their security incident response capabilities.
“In the UK, we have a very mature approach to handling cyber incidents,” he told Infosecurity.
“ Companies are more likely to contact their insurance carrier or legal team who will work with an approved company to help them investigate and address the threat.”
However, the average amount given by British companies is £940,000, much higher than France (£560,000), Germany (£800,000) and Italy (£300,000).
This large amount may indicate the “value” of these victim or the new trend of ransomware gangs to steal data before encrypting systems and threaten to leak it online if the ransom is not paid.
“The approach to ransomware needs to change. We must not only be able to recover from an attack, we must make sure it doesn’t happen in the first place,” the report states.
You can find CrowdStrike's full report here.
Source: Infosecurity Magazine
