PART ONE

Future-proofing your cybersecurity strategy

Defending Against RANSOMWARE


Ransomware Is Everywhere

Ransomware is running amok. The term refers to a type of malware that encrypts the victim’s data, preventing the organization or individual user from accessing their files and records. In exchange for decrypting it, the perpetrator demands a ransom — hence the name.

According to recent reports:

  • A ransomware attack occurs every 11 seconds, and a staggering 84% of U.S. organizations have reported phishing or ransomware attacks in the past 12 months.
  • Among businesses that operate globally, more than a third (37%) have been victimized by ransomware.

Those executives have good reason to worry. Analysts predict that the frequency of ransomware attacks will rise to one every two seconds, as perpetrators refine their malware and attack methods. The cost of these attacks is expected to soar as well, reaching $265 billion by 2031.

  • A study by Mimecast found that one out of every three executives believes their jobs are threatened by a successful ransomware attack.
  • For the first seven months of 2021, the FBI’s Internet Crime Complaint Center reported 2,084 ransomware incidents — a year-over-year increase of 62%.

More than 1 out of 3

global businesses have been victimized by ransomware.


Who Are the Victims?

Some of the world’s most prominent businesses were the targets of ransomware last year. These ran the gamut from energy conglomerates to food processors to the National Basketball Association.

  • Colonial Pipeline, for example, which supplies gasoline and jet fuel to the southeastern U.S., was forced to close down its entire pipeline network for five days owing to a ransomware attack. It was the first time in its 57-year history that the company had to cease operations; and it was only able to resume them after paying a $4.4 million ransom.
  • Acer, the Taiwanese electronics and computer manufacturer, was hit by multiple ransomware attacks last year. Among them was a March 2021 attack demanding $50 million in ransom.
  • Accenture, the global IT consultancy, had six terabytes of data stolen during a ransomware attack, for which the perpetrator demanded a $50 million ransom. The company acknowledged this in its 2021 annual report, in which it stated that “During the fourth quarter of fiscal 2021, we identified irregular activity in one of our environments, which included the extraction of proprietary information by a third party, some of which was made available to the public.”

Such incidents are no longer the exception — they’ve become the rule. Mimecast’s State of Email Security 2022 report, based on an in-depth survey of 1,400 information technology and cybersecurity professionals from 12 countries, found that ransomware afflicted three-out-of-four (76%) companies worldwide in 2021, up from 61% in 2020.

A ransomware attack occurs every 11 seconds.
Soon, one will take place every 2 seconds.


What Are the Consequences?

Measured in terms of downtime, the Mimecast study found that a quarter of the companies (25%) that suffered ransomware incidents experienced outages of two-to-three days, although nearly as many (22%) were down for a week, while another 15% were dead in the water for up to two weeks.

The largest known ransomware payout to date was made by an insurance company for $40 million. A survey of 1,263 companies found that although 46% recovered their files after paying the ransom, most of the data was corrupted. Meanwhile, 80% of the victims that paid a ransom experienced another ransomware attack soon after.

How Are Businesses Responding?

The sad reality is that when companies are confronted with a ransomware attack, nearly two-thirds (64%) feel compelled to pay off the attackers. Yet among companies that agree to pay a ransom, nearly four-out-of-10 (39%) fail to get back their data, according to Mimecast’s State of Email Security survey. This begs the question: How should they respond? While it’s easy to advise a company that it is self-defeating to pay off cybercriminals, the reality is not so simple. Companies must have access to their data to protect their customers and remain in business. Realistically, no company is in a position to defy its attackers — unless it is thoroughly prepared to respond to a ransomware attack.

companies that pay a ransom fail to get their data back.


Defeating Ransomware: A Three-Part Approach

The battle against ransomware needs to be waged on three fronts:

Protecting Communications

As reliance on electronic communications like email and collaboration tools continues to grow, attackers have zeroed in on them. This has been particularly true since the start of the COVID-19 pandemic, when email use soared and companies turned to new collaboration platforms like Microsoft Teams and Slack to replace in-person meetings. This swell of digital activity presented bad actors with numerous openings for social engineering attacks, many of which were devised to infect companies with ransomware. To protect an organization’s communications, it’s critical to harden its business processes and infrastructure. This involves asking and answering many questions: Are your procedures stable and secure, or can they be ignored or manipulated? Do you frequently use software that can be easily exploited? Do you work with third parties whose security procedures and systems are less robust than your own? Once you begin to systematically explore these issues, you are likely to uncover numerous vulnerabilities that an interloper could use to gain access to your network.

Protecting People

Most successful cyberattacks succeed due to human error. Ergo, a top priority in the fight against ransomware should be to raise employees’ awareness and train them to recognize and respond to an attack. This is especially important since phishing is one of the most common methods used by cybercriminals to embed ransomware.

Protecting Data

Defending against ransomware amounts to an arms race. Perpetrators are quick to adopt the latest technologies in their efforts to encrypt and gain control of your data. One example is the malware kits that have become readily available on the dark web. These can be used even by those with minimal technical skills to quickly devise and disseminate new forms of ransomware. This means that you, the defender, can’t rely on yesterday’s tech. Traditional ransomware detection tools can’t keep pace with today’s ransomware programs, and datanappers have found ways around conventional antivirus software. To protect your data and defend against incursions, you need specialized software that dynamically adapts to new threats. It’s also critical to be able to recover your data and restore your email in the event that an attacker manages to infiltrate your systems. To safeguard against this, backup and continuity services that keep your business up and running in the face of an attack also need to be part of your arsenal.


Mimecast: Your Best Ally for Ransomware Readiness

Mimecast offers AI-powered email threat protection, along with an array of robust tools and proven services, that can support your fight against ransomware on all three fronts. These let you:

  • Secure your email – the top attack vector. E-mail is the door through which most ransomware perpetrators commence their attacks. By applying the right detections at the right time and utilizing state-of-the-art AI and machine learning, Mimecast’s Email Security solutions block all email-based threats, including those that can open the door to ransomware.
  • Prevent employee mistakes – a factor in 94% of successful breaches. Mimecast security awareness training was developed by leaders from the military, law enforcement, and intelligence communities and will prepare your employees to detect and evade a ransomware threat.
  • Maintain Business continuity and data protection. In the face of a ransomware attack, the ability to keep email flowing and prevent the loss of email and collaboration tool data can mean the difference between being shut down completely and keeping the lights on.
  • Strengthen your endpoints, where most ransomware attacks take place. While malicious email paves the way for an attack, most ransomware attempts take place at your network’s endpoints. Mimecast, which monitors 1.3 billion emails daily, has extremely robust threat intelligence that can be distributed to your network’s endpoints via APIs.

Conclusion:

Seizing the High Ground

Ransomware is sure to be a protracted struggle, but the defensive measures described in this paper will allow you to seize the high ground from which to throw back the enemy’s incursions.

By deploying these defenses, together with a well-conceived battle plan, you can reduce your risk and lay the foundation for an accelerated recovery if – and likely when – faced with a ransomware attack.