Report: Ransomware affected 72% of organizations in past year

Enterprise

SpyCloud researchers recently reported that an overwhelming majority of cybersecurity leaders surveyed (81%)  believe their organization’s security is above average or exceptional. At the same time, 72% reported that their organization was affected by ransomware at least once within the past twelve months, with 18% reporting they were impacted more than six times in the past year. With regard to the frequency of attacks, SpyCloud’s report states that “Organizations of all sizes were affected nearly to the same extent, with the exception of those with more than 25,000 employees.”

In addition, only 18% of survey respondents believe a ransomware incident is not likely to happen at their organization within the next year, while 13% believe it’s very likely to happen at least once, and 22% believe it’s very likely to happen multiple times. Businesses’ confidence in their preparedness for ransomware is demonstrably misplaced.

Above: SpyCloud’s 2021 Ransomware Defense Report survey respondents identified phishing emails with infected attachments and links as the riskiest ransomware attack vector, followed by weak or exposed credentials. Nevertheless, they reported a comparative lack of investment in tools aimed at closing these risky entry points.

Image Credit: SpyCloud

This gap between organizations’ perception of their “cyber maturity” and the reality of their vulnerability to ransomware attacks stems from a failure to invest in prevention. While respondents identified phishing emails and weak or stolen credentials as the riskiest ransomware attack vectors, many lacked basic password hygiene and prevention measures. For example, 41% lack a password complexity requirement, and only 55.6% have implemented multifactor authentication (MFA).

Business leaders are acutely aware of the dangers they face. Despite the rising costs of cybersecurity, organizations are prioritizing their investments in cybersecurity defenses more than ever before. The biggest hindrance is the lack of skilled security personnel, followed closely by low-security awareness among employees.

To combat the threat of ransomware, prevention and vigilance are key. While people may be organizations’ greatest source of vulnerability, they are also critical to closing the riskiest entry points for cybercriminals. Increasing security awareness, implementing protocols to improve password hygiene, and monitoring to detect exposed credentials and change them before criminals can use them to infiltrate corporate networks are basic preventative steps that all companies should take.

SpyCloud’s 2021 Ransomware Defense Report analyzes a survey of IT security professionals and executives from a cross-section of small, mid-market, and large enterprises regarding how they view the threat of ransomware attacks and the maturity of their cybersecurity defenses between August 2020 and August 2021.

Read the full report by SpyCloud.

VentureBeat

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative technology and transact.

Our site delivers essential information on data technologies and strategies to guide you as you lead your organizations. We invite you to become a member of our community, to access:

  • up-to-date information on the subjects of interest to you
  • our newsletters
  • gated thought-leader content and discounted access to our prized events, such as Transform 2021: Learn More
  • networking features, and more

Become a member

Products You May Like

Articles You May Like

Xiaomi 12, Xiaomi 12X Tipped to Launch in December; Specifications Leaked
Interpol Arrests Over 1,000 Cyber Criminals From 20 Countries; Seizes $27 Million
PlayStation End of Year Deals Sale: Big Discounts on Marvel’s Spider-Man, F1 2021, Assassin’s Creed Valhalla
CronRAT: A New Linux Malware That’s Scheduled to Run on February 31st
New Hub for Lean IT Security Teams

Leave a Reply

Your email address will not be published. Required fields are marked *