A recent survey of decision makers from IT, risk, fraud and compliance departments at various UK companies have found that almost 70% of successful ransomware attacks last year were the result of hackers gaining access via phishing emails or social media phishing campaigns.
Public awareness of the threat of ransomware has certainly increased following several high profile ransomware attacks, such as WannaCry and NotPetya, but this latest research from security software company SentinelOne demonstrates that many people are still failing to identify malicious phishing emails. The advice to any victims remains that ransom demands should not be paid, but the research also found that victims actually paid an average of £34,845 to recover their files after an attack. Perhaps more concerning is that 58% of the respondents admitted that even though their organisation had paid the ransom, the perpetrators then tried to extort a second payment and 42% said their files were not decrypted even though they had met the ransom demands.
Although technical detection measures against ransomware are improving, this research shows that people remain the weakest line of defence. To help mitigate against the threat, prevention through education and awareness is one of the simplest and most cost-effective measures. Companies should also maintain regular back-ups of important data (and keep those back-ups on a separate network/offline), and ensure security updates are installed on devices and networks at the earliest opportunity.
PGI offer a Phishing Vulnerability Assessment. We will send a series of mock malicious e-mails to your staff to gauge their vulnerability to compromised links, followed by training for your staff.
Protection Group International believes that cyber security doesn’t need to be overly complicated, incomprehensible or vastly expensive. We specialise in delivering strategic vulnerability assessment services and offer a range of senior cyber awareness education to enable you to tackle cyber threats in-house. For more information click here.
Our partner company, Protection Vessels International, is focussed on the efficient delivery of high quality, cost-effective security solutions for the maritime community. We invest in our well-maintained logistic infrastructure to enhance customers’ business continuity through the protection of their assets and people. For more information click here.
Your free global geopolitical
PGI’s Risk Portal tool provides daily intelligence feeds, country threat assessments and analytical insights, enabling clients to track, understand and navigate geopolitical threats.
The Risk Portal gives users up-to-date information and analysis on global affairs.
The Risk Portal allows users to visualise information in a unique and instantly understandable way. Mapping filters enable the visualisation of incidents by threat category, time period, perpetrator and target type.
Risk Portal users can upgrade their accounts to include the Report Builder and Country Profile Generator features. The Report Builder allows users to select information, data and images from the Risk Portal and create bespoke reports and emails.
Subscribers to PGI’s Bespoke services receive tailored analysis on specific sectors and geographies of interest, delivered at a frequency they determine.
Subscribe to our Cyber Bytes Newsletter
Keep yourself in the loop with PGI by signing up to our Monthly Cyber Bytes email. You will receive updates, tips and narrative around what has been happening in the world of information security.