November 23, 2016 By Mark Samuels 2 min read

Nearly half of organizations across the globe have fallen victim to a ransomware campaign in the past 12 months. Cybersecurity executives must respond to the challenge with an effective mix of strategy and technology.

That is the main conclusion drawn from a recent SentinelOne survey conducted by market research firm Vanson Bourne. The study also found that 80 percent of businesses suffered three or more attacks in 2016. Additionally, organizations hit by the ransomware epidemic suffer an average of six attacks a year.

Ransomware creates a significant problem for cybersecurity executives. The vast majority of respondents, to the tune of 94 percent, indicated that an attack has an impact on their organization. The challenge now is for IT and security professionals to turn the threat posed by the ransomware epidemic into an opportunity to establish better business practices.

Boosting Business Awareness

The good news for security executives is that attacks often create renewed business awareness of the cybersecurity challenge at hand. More than two-thirds of survey respondents said they plan to increase spending on IT security, and more than half will change their IT security strategy to focus on mitigation.

Eighty-five percent reported that their organizations were able to identify attackers. Almost all respondents — 95 percent — said they had gained insight into the motivations of cybercriminals as a result of a ransomware attack. The most common motives are financial gain (54 percent), simple disruption to a successful business (47 percent) and cyber espionage (42 percent). Employee information, financial data and customer information, meanwhile, are the types of knowledge most likely to be affected by an attack.

Building a Stronger Operation

The continued threat of ransomware, however, does leave some executives feeling perplexed. Evidence suggests business are willing to spend to help mitigate the security risk, yet the scale of the potential challenge can lead some business managers to question the success of their investments.

The Vanson Bourne research revealed that 54 percent of executives believe their organizations have lost faith in traditional cybersecurity techniques such as antivirus, Help Net Security reported. Seventy-one percent of respondents indicated that their business needs a new solution to meet the challenges associated with ransomware.

Jeremiah Grossman, chief of security strategy at SentinelOne, recognizes the scale of the technological challenge. “It’s clear that there’s an immediate need for a new generation of security technologies that can discover, stop and adapt to the new breed of threats and hacker strategies,” Grossman said.

The Ransomware Epidemic Is Spreading

The Proofpoint Threat Report released earlier this year also highlighted the ever-increasing risk posed by ransomware. The research suggested attackers’ exploits are more likely to be successful if security teams are unprepared.

The key message for cybersecurity executives is to use increased business awareness of the risk posed by ransomware to support a new, targeted approach that draws on the expert resources of trusted technology partners.

For the ransomware report, Vanson Bourne surveyed 500 cybersecurity decision-makers at organizations around the world with more than 1,000 employees. Interviews were conducted with 200 executives in the U.S., 100 in the U.K., 100 in France and 100 in Germany.

More from

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

A spotlight on Akira ransomware from X-Force Incident Response and Threat Intelligence

7 min read - This article was made possible thanks to contributions from Aaron Gdanski.IBM X-Force Incident Response and Threat Intelligence teams have investigated several Akira ransomware attacks since this threat actor group emerged in March 2023. This blog will share X-Force’s unique perspective on Akira gained while observing the threat actors behind this ransomware, including commands used to deploy the ransomware, active exploitation of CVE-2023-20269 and analysis of the ransomware binary.The Akira ransomware group has gained notoriety in the current cybersecurity landscape, underscored…

New proposed federal data privacy law suggests big changes

3 min read - After years of work and unsuccessful attempts at legislation, a draft of a federal data privacy law was recently released. The United States House Committee on Energy and Commerce released the American Privacy Rights Act on April 7, 2024. Several issues stood in the way of passing legislation in the past, such as whether states could issue tougher rules and if individuals could sue companies for privacy violations. With the American Privacy Rights Act of 2024, the U.S. government established…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today