HomeSecurityEfforts to stop ransomware are starting to bear fruit

Efforts to stop ransomware are starting to bear fruit

Government and industry efforts to curb ransomware are slowly starting to bear fruit.

ransomware

It may seem counterintuitive, given the frequency of ransomware attacks today, but these debilitating cyberattacks decreased for the first time in 2022, thanks to actions and policy changes implemented by businesses and governments in countries around the world.

This good news comes from the Ransomware Task Force (RTF), an industry group founded by the Institute for Security and Technology (IST) during the height of the ransomware surge triggered by COVID-19. In its May 2023 progress report, the RTF announced that of its 48 recommendations for how society could resist the scourge of ransomware, a full 92% have already been addressed in one way or another.

The results of this progress are already visible in the data and are being felt in practice.

Still, ransomware attacks continue. Every week, new threat actors emerge, getting better at what they do and evolving their tactics and technologies to bypass our best defenses. Major, multi-million dollar attacks—which would have seemed extreme just a few years ago—continue to hit both businesses and government targets. Just last week, for example, the sheriff’s department in San Bernardino, California, admitted to paying a $1.1 million ransom.

The RTF was founded in December 2020, bringing together dozens of leaders from organizations including Microsoft, Bank of America, Mandiant, the U.S. Department of Justice, and Europol. In April 2021, the group published its inaugural report, focusing on “a comprehensive framework of actions (48 in total) that government and industry leaders can take to significantly disrupt the ransomware business model and mitigate the immediate and long-term impacts of these attacks .”

It would be easy to lose track of all this action or ignore it altogether. Instead, “two years later, we have seen impressive moves by industry, the U.S., and partner governments toward implementing these recommendations,” the authors of the latest report wrote.

So far, 44 of the RTF's 48 recommendations "have seen some action" on 24 of them, "significant progress has been made" since April 2021, while "preliminary actions" have been taken to address another 20. "Only 4 recommendations have had no publicly known action taken," the new report states.

“Among the countless ways in which governments, businesses and individuals took action,” Franklin says, “each one had a significant impact.”.

Even the way governments talk about ransomware has been important. RTF co-chair Megan Stifel points to the Colonial Pipeline attack as a turning point in ransomware policy.

Meanwhile, private industry has played its part. “Organizations have gotten better at their own hygiene,” Stifel estimates. “Organizations have changed their responses to ransomware incidents,” including paying their attackers much less often — just 37% of the time in Q4 2022, compared to 85% of the time in Q1 2019, according to Coveware.

ransomware

All of these developments have already paid off. In its May report, RTF noted 2022 data from CrowdStrike – showing that ransomware had declined by 20% in data theft and extortion – and Chainalysis – that the average lifespan of a ransomware strain had plummeted to 70 days, down from 153 in 2021 and 265 in 2020.

As much effort as it took to stop ransomware the first time, it will take even greater effort to contain it and deal with the next threat that emerges in its place.

Source of information: darkreading.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS