83% of organizations paid up in ransomware attacks 


Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More


Today, cloud network detection and response provider ExtraHop released the 2023 Global Cyber Confidence Index, which found that not only did the average number of ransomware attacks increase from four to five from 2021 to 2022, but also that 83% of victim organizations paid a ransom at least once. 

The report found that while entities like the FBI and CISA argue against paying ransoms, many organizations decide to eat the upfront cost of paying a ransom, costing an average of $925,162, rather than enduring the further operational disruption and data loss. 

Organizations “are paying ransoms because they believe it’s the quickest and easiest route to get their business back up and running,” said Jamie Moles, senior technical manager at ExtraHop.

At the same time, the popular double extortion modus operandi of many cyber gangs “incorporates stealing data before encrypting it and threatening to publish it on the internet if you don’t pay the ransom,” said Moles, thus placing extra pressure on organizations to pay up. 

Event

Transform 2023

Join us in San Francisco on July 11-12, where top executives will share how they have integrated and optimized AI investments for success and avoided common pitfalls.

 


Register Now

The cost of cybersecurity debt 

The research comes just after KFC, Taco Bell and Pizza Hut parent company Yum! Brands announced it had experienced a ransomware breach. 

One of the underlying themes of ExtraHop’s report released today is that organizations are giving ransomware attackers leverage over their data by failing to address vulnerabilities created by unpatched software, unmanaged devices and shadow IT. 

For instance, 77% of IT decision makers argue that outdated cybersecurity practices have contributed to at least half of security incidents. 

Over time, these unaddressed vulnerabilities multiply, giving threat actors more potential entry points to exploit and greater leverage to force companies into paying up. 

“The probability of a ransomware attack is inversely proportional to the amount of unmitigated surface attack area, which is one example of cybersecurity debt,” said Mark Bowling, chief risk, security and information security officer at ExtraHop. “The liabilities, and, ultimately, financial damages that result from this de-prioritization compounds cybersecurity debt and opens organizations up to even more risk.”

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.



Source link: https://venturebeat.com/security/83-of-organizations-paid-up-in-ransomware-attacks/

Sponsors

spot_img

Latest

Shibacals Contest Wraps Up: SHIB Fans Scoop Champion Hoodies

The Shibacals NFT hoodie contest is counting its last hours. NFT enthusiasts can submit their designs...

What We’re Watching on TikTok

Charming animal interactions FTW. By the wonderful Grace Farris. P.S. What we’re doing this Friday and 7 Instagram reels that will make you laugh.…...

We drank 72 bottles of wine at the Ryder Cup

Paul McGinley: We drank 72 bottles of wine at the Ryder Cup © Al Messerschmidt / Getty Images Sport Paul McGinley is a man...

Spring Pieces I’m Already Wearing a Million Times

What are you wearing these days? I find myself reaching for the same few things every morning… How cute is this denim jacket? The...

Learn Python: 76% off Python course bundle

TL;DR: The 2023 Complete Python Certification Bootcamp Bundle is on sale for £15.93, saving you 76% on list price.Anyone looking to get into...