HomeinetRansomware Survey: 94% of Companies Would Pay

Ransomware Survey: 94% of Companies Would Pay

Ransomware Survey: 94% of Companies Would Pay

What emerges from a new study by Cohesity, a specialist in artificial intelligence-powered data security management, is that While a “don’t pay” policy for ransomware may sound good in theory, responding negatively to cybercriminals’ demands for payment to recover data is easier said than done.

See also: HeadCrab Malware: Targets Redis for Crypto Mining

Ransomware itself surveys more than 900 IT and security decision-makers “who view cyberattacks on their organization as a matter of when rather than if.”.

The survey showed that 94% of respondents said their company would pay the ransom to recover data and restore business processes, while 5% said “maybe, depending on the ransom amount.”

Most of those surveyed paid at least once in the past two years, and most said they expect the risk of cyberattacks to increase significantly in 2024. And, alarmingly, 79% of respondents said their company was a victim of ransomware between June and December 2023. That means 96% of respondents said the risk of cyberattacks in their industry will increase this year, with 71% predicting it will increase by more than 50%.

See also: CISA: Warns of vulnerability exploitation in Apple products

Ransomware research

9 out of 10 companies paid the ransom

67 % of respondents said their company would be willing to pay more than $3 million to recover data and restore business processes, and 35% said they were willing to pay $5 million for ransom. The Ransomware survey also highlighted the importance of being able to react and recover, as 9 in 10 said their organization had paid ransom in the past two years, despite 84% saying their company had a “do not pay” policy.

“Organizations cannot control the increasing volume, frequency, or sophistication of cyberattacks like ransomware,” said Brian Spanswick, Chief Information Security Officer and CIO at Cohesity. “What they can control is their cyber resilience, which is the ability to react and recover quickly from cyberattacks or IT failures by adopting modern data security capabilities.”.

Spanswick said it was “not surprising” that the majority of companies surveyed had fallen victim to ransomware.

“What is worrying is that 90% have paid ransom at least once, violating ‘don’t pay’ policies, and most are willing to pay over $3 million because they cannot recover their data and quickly restore their business processes,” he added.

See also: Europcar: Denies data breach allegations

Clarifications on Ransom Payments

So what happens if an MSSP or MSP customer or end user falls victim to ransomware? Is it advisable to pay? That depends on a variety of circumstances, as well as the implementation of an organization’s incident response plan, according to experts who spoke to MSSP Alert for a recent article.

A major piece is whether any data is exposed that contains personally identifiable information (PII) or sensitive data. Losing old, outdated, or non-sensitive data isn’t necessarily something that should cause a victim to panic and immediately pay money to recover the data, according to Quentin Simmons, lead analyst for digital investigation and incident response for eSentire, a management detection and response (MDR) specialist.

There are also legal issues to consider, as paying a ransom could violate US OFAC ( Office of Foreign Assets Control ) regulations

Cohesity found that despite efforts by governments and public bodies to encourage stronger cybersecurity and data management, only 46% of respondents said that government initiatives, legislation and regulations are actually driving their companies’ data security, data management or data recovery initiatives.

Source: msspalert

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS