If you have turned on the news recently, then “ransomware” may be top of mind when considering the impact it could have on your organization’s ability to deliver its services.
The term certainly has been in the headlines lately. Colonial Pipeline has been the highest-profile ransomware attack so far in 2021, but there have been several others that made national news, including JBS Foods and Quanta.
With more of our clients continuing to ask about ransomware attacks and what they can do to limit their risk and exposure to potential attackers, Baker Tilly recently hosted a comprehensive webinar, Managing your risk against a ransomware attack.
Risk advisory team member, Brian Nichols, discussed key components of ransomware attacks, as well as recent ransomware trends and some leading prevention techniques.
Let’s highlight some of the key topics discussed.
Ransomware is malicious software that infects a computer system, propagates to network-connected devices and encrypts critical data, rendering it unusable until a ransom is paid to decrypt the files.
Typically, the data is held hostage – locked, in essence – until the victim pays the attackers a ransom to provide the decryption key. Additionally, the attackers may exfiltrate the data before encrypting it and threaten that if the ransom is not paid, the data will be released on the dark web.
In either case, it’s not a fun situation for any organization to find itself in.
There are a variety of delivery channels for ransomware, but email remains the primary method. Nearly 80% of ransomware attacks originate through phishing emails.
Increasing the concern is the release of ransomware as a service (RaaS) capabilities that allow attackers with minimal sophistication to successfully execute a ransomware attack. This has contributed to the rise in attacks over the last year or so.
As far as ransomware is concerned, the recent trends feature some eye-catching figures.
It is critical for organizations to implement proactive controls to prevent ransomware attacks and minimize their chances of being the next victim on the news. Leading prevention practices include:
For more information on these prevention techniques and how to implement a proactive ransomware prevention program, contact our team.
[1] Cyware Social, Breaking Down the Ransomware Trends in 2021. May 18, 2021.
[2] Cybersecurity and Infrastructure Security Agency
[3] RedTeam Security, The Top 6 Industries At Risk For Cyber Attacks
[4] Coveware, Ransomware Payments Fall as Fewer Companies Pay Data Exfiltration Extortion Demands. Feb. 1, 2021.
[5] Cyware Social, Breaking Down the Ransomware Trends in 2021. May 18, 2021.
[6] Cybereason, Ransomware: The True Cost to Business. 2021.