A new report from Mimecast has found that the US leads the way in the size of ransom payments following ransomware incidents.

See also: MediaMarkt hit by Hive ransomware
In the “State of Ransomware Readiness” study from Mimecast, researchers spoke with 742 cybersecurity professionals and found that 80% of them had been targeted with ransomware in the past two years.
Of that 80%, 39% paid ransom, with US victims paying an average of $6,312,190. Victims in Canada paid an average of $5,347,508, while those in the UK paid almost $850,000. Victims in South Africa, Australia and Germany paid an average of $250,000.
Over 40% of respondents did not pay the ransom and another 13% were able to negotiate the initial ransom amount.
See also: Ransomware cyberattack on Danaos and Greek shipping companies
Of the 742 experts who spoke to Mimecast, more than half said the primary source of ransomware attacks came from phishing emails with ransomware attachments, and another 47% said it came from “web security.” Phishing emails that led to drive-by downloads were a highly cited source of ransomware infections.
Less than half of respondents said they have backups of files they could use in the event of a ransomware attack, and nearly 50% said they needed larger budgets to update their data security systems.
Despite the lack of backups, 83% of respondents said they could “get all their data back without paying the ransom.” Another 77% of executives said they believed they could get the company back to normal operations within two days of a ransomware incident. This was puzzling to Mimecast researchers, considering that nearly 40% of respondents admitted to paying the ransom.
See also: Clop ransomware: More information revealed
Some respondents called for more education and more information-sharing about threats.
The cost of a ransomware incident extends far beyond the ransom itself. 42% of survey respondents reported disruption to their operations and 36% said they experienced significant downtime. Nearly 30% said they lost revenue and 21% said they lost customers.
Another cost? Nearly 40% of cybersecurity professionals surveyed said they believed they would lose their jobs if a ransomware attack was successful.
Two-thirds of respondents said they would “feel very or extremely responsible if a successful attack occurred.” When asked why, nearly half said it would be because they “underestimated the risk of a ransomware attack.”.
Information source: zdnet.com
