Ransomware attack on laptop in front of a hacker and the flag of the united kingdom

The Growing Ransomware Crisis

Over Half of Breached UK Firms Pay Ransom: The Growing Ransomware Crisis

Ransomware attacks are becoming increasingly common in the UK, with a rising number of organisations falling victim to these cybercrimes. According to a recent study by Cohesity, a leading security vendor, the growing trend of paying ransoms is encouraging cybercriminals to target more businesses. The findings in Cohesity’s Global Cyber Resilience Report 2024 highlight concerning statistics that show just how deep the problem has become in the UK.

Ransomware Hits More UK Firms Than Ever Before

The survey, which polled over 3,100 IT and security decision-makers across eight countries, revealed alarming figures for the UK. In the past year, 53% of UK respondents reported experiencing a ransomware attack, a significant increase from 38% in the previous year. This surge in ransomware incidents can largely be attributed to the fact that more organisations are paying the ransom, which in turn motivates cybercriminals to continue their attacks.

The report also highlighted that 59% of UK firms that were targeted by ransomware attacks chose to pay the ransom. Shockingly, 74% of UK respondents stated they would be inclined to pay if they were targeted in the future. While 66% of businesses claim to have policies in place not to pay ransoms, only 7% completely rule out paying in the event of an attack.

The High Cost of Paying Ransoms

The financial impact of ransomware attacks on UK organisations is substantial. UK respondents who paid a ransom spent an average of £870,000, with two companies admitting to paying between £10 million and £20 million. On a global scale, 5% of ransomware victims reported paying over £10 million.

However, paying the ransom does not guarantee a successful recovery. Only 4% of respondents managed to recover all their data after paying the ransom, and less than 2% were able to fully restore their business processes within 24 hours. While 23% of respondents could recover within 1 to 3 days, a significant portion of victims reported a much slower recovery process. Some organisations took between three weeks and two months to recover.

The Need for Cyber Resilience

Despite the growing trend of paying ransoms, law enforcement and government authorities consistently advise against it. Paying extortionists not only funds cybercriminal operations but also offers no certainty that data will be restored. Additionally, paying ransomware actors linked to sanctioned cybercrime groups is illegal.

James Blake, global head of cyber-resilience strategy at Cohesity, emphasises the importance of developing a strong cyber-resilience strategy. Given the determination of cybercriminals and the expansive nature of corporate attack surfaces, relying solely on preventative measures is unrealistic. Blake stresses that cyberattacks can severely disrupt an organisation’s operations, impacting revenue, reputation, and customer trust.

To address these challenges, Blake encourages business leaders to make cyber-resilience a priority, not just IT and security leaders. He also advocates for viewing regulations as the minimum standard and going beyond them to adopt robust data security and recovery capabilities.

What Steps Can Your Company Take?

To protect your organisation from the rising threat of ransomware, implementing a proactive approach is critical. Here are some preventive measures that can help reduce the risk of falling victim to a ransomware attack:

  1. Employee Training and Awareness
    Ensure that all employees are trained to recognise phishing emails, suspicious links, and other tactics commonly used by cybercriminals. Awareness is key in preventing attacks from infiltrating your systems.
  2. Regular Data Backups
    Maintain regular, secure backups of critical data. Ensure that backups are kept offline or in a separate network, making it difficult for attackers to access and encrypt backup data during a ransomware attack.
  3. Network Segmentation
    Segment your network to limit the spread of ransomware if it does penetrate your system. This makes it harder for the attack to move across your entire infrastructure, allowing you to contain the damage.
  4. Advanced Endpoint Protection
    Implement advanced endpoint protection solutions that can detect and block malware, including ransomware, before it infiltrates your systems. Keep software up to date with the latest security patches to address vulnerabilities.
  5. Implement Multi-Factor Authentication (MFA)
    Use multi-factor authentication to add an extra layer of security to your accounts and systems. Even if an attacker gains access to user credentials, MFA can stop them from accessing critical systems.
  6. Maintain Incident Response and Recovery Plans
    Develop a comprehensive incident response plan to quickly detect, contain, and recover from ransomware attacks. Ensure your recovery procedures are tested regularly and that all staff members know their roles in the event of an attack.
  7. Restrict Privilege Access
    Limit administrative access and ensure that employees only have access to the data and systems necessary for their role. This helps minimise the risk of attackers exploiting privileged accounts.
  8. Use Ransomware Detection Tools
    Invest in tools that are specifically designed to detect ransomware behaviour, such as unusual file encryption patterns, and alert your IT team to take action before the attack spreads.

Changing Focus:

The rise in ransomware attacks in the UK highlights a growing cybersecurity crisis that businesses cannot afford to ignore. As cybercriminals continue to target organisations, the temptation to pay ransoms is strong, but it comes at a high cost. Companies must prioritise cyber-resilience and adopt comprehensive security measures to minimise the risks of ransomware attacks. Instead of focusing on paying extortionists, organisations should focus on building resilient systems and recovery processes that can withstand and recover from these devastating attacks.

________________________________________________________________________________

If you need help strengthening your cybersecurity strategy or improving your organisation’s resilience to ransomware attacks, contact us today for expert guidance!