ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

SpyCloud Report: Organizations Unprepared for Ransomware Attacks Despite Confidence in Cyber Defenses

81% of companies are confident their organization’s cybersecurity is above average, yet many fail to implement basic cybersecurity recommendations

SpyCloud, the leader in Account Takeover (ATO) Prevention, today released its 2021 Ransomware Defense Report, an analysis of IT security leaders’ perceived threat of ransomware attacks and the maturity of their cybersecurity defenses.

The report found that while 81% of those surveyed consider their security to be above average or exceptional, many lack basic cyber hygiene – 41% lack a password complexity requirement, one of the cheapest, easiest forms of protection, and only 55.6% have implemented multi-factor authentication (MFA).

“The loss of data and resources due to ransomware attacks can be debilitating. Though organizations are taking this threat seriously, too many are failing to take basic preventative steps. This report indicates a disturbing misplaced confidence that defenses never fail or that paying a ransom after an attack will always work – they do, and it won’t,” said Ted Ross, CEO and co-founder of SpyCloud. “Ransomware is a real problem, and it’s growing, but there are concrete steps organizations can take to prepare. Proactively implementing preventative solutions is the key to disrupting ransomware early in the lifecycle and successfully mitigating the damage.”

Key highlights from the State of Ransomware Report include:

  • Organizations are not optimistic about the ransomware problem. 62% of respondents believe a ransomware incident is likely to occur in the next 12 months.
  • 72% of surveyed organizations were affected by ransomware from August 2020 - August 2021, with 13% affected 6-10 times.
  • 79% agree that reports of high-profile attacks (including SolarWinds and Colonial Pipeline) have “significantly elevated” their organization’s concerns about weak or stolen credentials used by employees and customers.
  • Despite ranking compromised credentials as a high-risk entry point for ransomware attacks, most organizations lack even the simplest practices for shoring up passwords and authentication.
    • 41% don’t have a password complexity requirement and only 55.6% have implemented multi-factor authentication (MFA).

Mitigating Fallible Defenses with Proactive Prevention

Organizations reported the average cost of ransomware recovery at $1.85 million in 2021, more than double the 2020 price tag of $760,000. Despite the explosion of ransomware attacks, individuals are still organizations’ greatest vulnerability – and their best asset in the fight against cybercriminals.

Respondents ranked phishing emails with infected attachments or links as the riskiest vector for ransomware attacks, followed by weak or exposed credentials. Surprisingly, cybersecurity budgets ranked as the least challenging hurdle for organizations.

However, rather than investing in strategies to address common root causes of ransomware attacks, organizations have focused efforts and resources on containing the damage after it occurs. For example, 50.4% have purchased ransomware-specific insurance riders, 36.4% have retained a third-party payment broker and 30% have opened a bitcoin account, even though experts question the effectiveness of each of these measures.

To get ahead of cybercriminals, organizations must focus on mitigating the most common entry vectors. Addressing stolen credentials –– a major cause of ransomware attacks – is critical to disrupting the lifecycle of an attack early. This can be achieved by increasing employee awareness of phishing emails and the risks of using weak and recycled passwords, as well as through implementing MFA.

While better employee awareness, robust authentication and device security are critical, organizations must recognize that even the strongest defenses fail. Solutions that monitor the criminal underground for stolen credentials help protect employees and empower companies with a proactive approach to containing a highly sophisticated threat.

Detecting stolen credentials and resetting them before criminals can use them to infiltrate corporate networks is the most direct path to fighting ransomware before criminals can gain a foothold. To learn more about how SpyCloud helps organizations defend against ransomware attacks, visit https://spycloud.com/solutions/ransomware/.

The full Ransomware Defense Report is available for download at https://spycloud.com/resource/ransomware-defense-report-2021/.

About SpyCloud

SpyCloud protects consumers, employees, suppliers, and citizens globally from the dangers of compromised identity. Its solutions make breached information actionable to prevent fraud, enabling a proactive, automated response that negates the value of stolen data before it can be used to cause harm. Its data also powers many popular dark web monitoring and identity theft protection offerings. SpyCloud customers include four of the ten largest global enterprises, mid-size companies, and government agencies around the world. Headquartered in Austin, TX, SpyCloud is home to over 100 cybersecurity experts who aim to make the internet a safer place.

To learn more and see an overview of your organization’s exposed data, visit spycloud.com.

New @SpyCloudCo Report: 81% of companies are confident their organization’s #cybersecurity is above average, yet many fail to implement basic cybersecurity recommendations to prevent #ransomware attacks.

Contacts

Recent Quotes

View More
Symbol Price Change (%)
AMZN  222.54
+0.00 (0.00%)
AAPL  274.11
+0.00 (0.00%)
AMD  207.58
+0.00 (0.00%)
BAC  55.33
+0.00 (0.00%)
GOOG  309.32
+0.00 (0.00%)
META  647.51
+0.00 (0.00%)
MSFT  474.82
+0.00 (0.00%)
NVDA  176.29
+0.00 (0.00%)
ORCL  184.92
+0.00 (0.00%)
TSLA  475.31
+0.00 (0.00%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.