Site icon Nairametrics

Data encryptions from ransomware attacks on businesses hit 4-year high—Report

ransomware

Article summary


The latest report by cybersecurity company, Sophos, has revealed that the rate of successful data encryption from ransomware attacks on organizations has hit the highest level in 2023.  

Sophos in its “State of Ransomware 2023” report, said it found that in 76% of ransomware attacks against surveyed organizations, adversaries succeeded in encrypting data. It said this came as the highest rate of data encryption from ransomware since Sophos started issuing the report in 2020. 

According to the company, the survey also shows that when organizations paid a ransom to get their data decrypted, they ended up additionally doubling their recovery costs ($750,000 in recovery costs versus $375,000 for organizations that used backups to get data back).  

It added that paying the ransom usually meant longer recovery times, with 45% of those organizations that used backups recovering within a week, compared to 39% of those that paid the ransom. Sophos further disclosed that overall, 66% of the organizations surveyed were attacked by ransomware—the same percentage as the previous year.  This, it said, suggests that the rate of ransomware attacks has remained steady, despite any perceived reduction in attacks. 

Rising encryption rate 

Commenting on the report, field CTO at Sophos, Chester Wisniewski, said: 

Root cause of attacks 

The company added that while analyzing the root cause of ransomware attacks, it found that the most common was an exploited vulnerability (involved in 36% of cases), followed by compromised credentials (involved in 29% of cases). It said this is in line with recent, in-the-field incident response findings from Sophos’ 2023 Active Adversary Report for Business Leaders. 

Additional key findings from the report include: 

Recommended best practices 

In its recommendations, Sophos advised businesses to strengthen their defensive shields with security tools that defend against the most common attack vectors, including endpoint protection with strong anti-exploit capabilities to prevent exploitation of vulnerabilities, and Zero Trust Network Access (ZTNA) to thwart the abuse of compromised credentials. 

It also advised businesses to adopt adaptive technologies that respond automatically to attacks, disrupting adversaries and buying defenders time to respond. 

Data for the State of Ransomware 2023 report comes from a vendor-agnostic survey of 3,000 cybersecurity/IT leaders conducted between January and March 2023.

Respondents were based in 14 countries across the Americas, EMEA and Asia Pacific. Organizations surveyed had between 100 and 5,000 employees, and revenue ranged from less than $10 million to more than $5 billion. 

Exit mobile version