The median cost per ransomware incident more than doubled over the past two years to $26,000, with 95% of events that resulted in a loss costing upwards of $2.25 million, according to Verizon Business in its newly-released 2023 Data Breach Investigations Report.
Ransomware Exploding
The 16th edition of the highly referenced volume analyzed 16,312 security incidents and 5,199 breaches. Verizon Business found that the number of ransomware attacks in the past couple of years amounted to more than the previous five years combined. In fact, ransomware accounted for nearly one in four (24%) cyberattack methods, the report said.
Human error continued to be a weak link in the ransomware chain, with some involvement in nearly three in four (74%) of events, despite an emphasis on employee training. Phishing and business email compromise are two examples of social engineering that require an employee mistake to propagate.
Chris Novak, Verizon Business managing director of cybersecurity consulting, explained how upper-level management is a “growing cybersecurity threat” for many organizations:
“Not only do they possess an organization’s most sensitive information, they are often among the least protected, as many organizations make security protocol exceptions for them. With the growth and increasing sophistication of social engineering, organizations must enhance the protection of their senior leadership now to avoid expensive system intrusions.”
Emails Attacks Double
Here are the key takeaways from the report:
Stolen Credentials Most Prevalent Attack Method
Other findings in the 2023 DBIR include: