In three out of four cyberattacks, the hijackers succeeded in encrypting victims’ data, cybersecurity provider Sophos said in its newly released State of Ransomware 2023 report.
Data Encryption Tops Ransomware Exploits
The rate of data encryption amounted to the highest from ransomware since Sophos first issued the report in 2020, the company said. Overall, roughly two-thirds of the 3,000 cybersecurity/IT leaders’ organizations were infected by a ransomware attack in the first quarter of 2023, or the same percentage as last year.
Much advice has been doled out by cybersecurity providers and law enforcement urging cyber-kidnapped organizations to not pay a ransom. According to Sophos’ survey, the data shows that when organizations paid a ransom to decrypt their data, they ended up doubling their recovery costs. On average, those organizations paying ransoms for decryption forked out $750,000 in recovery costs versus $375,000 for organizations that used backups to recover their data.
Moreover, paying the ransom usually meant longer recovery times, with 45% of those organizations that used backups recovering within a week, compared to 39% of those that paid the ransom.
Chester Wisniewski, Sophos field chief technology officer, explained that rates of encryption returning to very high levels after a temporary dip during the pandemic is “concerning":
“Incident costs rise significantly when ransoms are paid. Most victims will not be able to recover all their files by simply buying the encryption keys; they must rebuild and recover from backups as well. Paying ransoms not only enriches criminals, but it also slows incident response and adds cost to an already devastatingly expensive situation.”
Education Sector Most Attacked
Additional key findings from the report include:
Human-led threat hunting is very effective at stopping cyber criminals in their tracks, said Wisniewski:
“Experienced analysts can recognize the patterns of an active intrusion in minutes and spring into action. This is likely the difference between the third who stay safe and the two thirds who do not. Organizations must be on alert 24x7 to mount an effective defense these days."
Steps to Defense Against Ransomware
Sophos recommends the following best practices to help defend against ransomware and other cyberattacks: