Skip to content
Dekano Logo
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About
Dekano Logo
Call Us
[email protected]
Let’s Connect
Dekano Logo
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About
Call Us
[email protected]
Let’s Connect
  • 18/04/2023

The State of Ransomware 2023

State of Ransomware 2023

A Sophos Whitepaper: 

Findings from an independent, vendor-agnostic survey of 3,000 leaders responsible for IT/cybersecurity across 14 countries, conducted in January-March 2023.

Introduction

Sophos’ annual study of the real-world ransomware experiences of IT/cybersecurity leaders makes clear the realities facing organizations in 2023. It reveals the most common root causes of attacks and shines new light on how experiences with ransomware differ based on organization revenue. The report also reveals the business and operational impact of paying the ransom to recover data rather than using backups.

About the Survey

Sophos commissioned an independent, vendor-agnostic survey of 3,000 IT/ cybersecurity leaders in organizations with between 100 and 5,000 employees across 14 countries in the Americas, EMEA, and Asia Pacific. The survey was conducted between January and March 2023, and respondents were asked to respond based on their experiences over the previous year.

Within the education sector, respondents were split into lower education (catering to students up to 18 years) and higher education (for students over 18 years).

Rate of Ransomware Attacks

The research revealed that the rate of ransomware attacks has remained level, with 66% of respondents reporting that their organization was hit by ransomware in the previous year, the same as in our 2022 survey. With adversaries now able to consistently execute attacks at scale, ransomware is arguably the biggest cyber risk facing organizations today.

Cyber criminals have been developing and refining the ransomware-as-a service model for several years. This operating model lowers the barrier to entry or would-be ransomware actors while also increasing attack sophistication by enabling adversaries to specialize in different stages of an attack. 

Attacks by Country

While the overall reported ransomware rate remains flat compared to 2022, the survey revealed variations at a country level. Singapore reported the highest rate of ransomware attacks in this year’s study, with 84% of organizations being hit in the previous year. Conversely, the UK reported the lowest rate of attack (44%).

Austria reported the biggest drop in rate of attack, down from 84% of organizations hit to 50%. South Africa had the biggest increase in attack rate, with 78% of organizations hit in our 2023 survey compared to 51% in 2022.

Attacks by Industry

The education sector was the most likely to have experienced a ransomware attack in the last year with 80% (lower education) and 79% (higher education) reporting being hit. Education traditionally struggles with lower levels of resourcing and technology than many other industries, and the data shows that adversaries are exploiting these weaknesses. IT, technology, and telecoms reported the lowest level of attack (50%), indicating a higher level of cyber readiness and cyber defenses.

66% hit by ransomware

Singapore highest rate of attack (country)

UK lowest level of attack (country)

Education highest level of attack (industry)

IT, Technology, and Telecoms lowest level of attack (industry)

Attacks by Organization Size: Employees vs. Revenue

The research revealed a clear correlation between annual revenue and propensity to experience a ransomware attack, with the percentage of organizations hit by ransomware increasing progressively with revenue. 56% of organizations with revenue of $10-$50 million experienced a ransomware attack in the last year, rising to 72% of those with revenue of $5 billion plus. Conversely, there was little clear relationship between experiencing ransomware and the number of employees in an organization. Outside the 1,001-3,000 employee segment, the rate of ransomware attack was very consistent:

  • 100-250 employees 62%
  • 251-500 employees 62%
  • 501-1,000 employees 62%
  • 1,001 – 3,000 employees 73%
  • 3,001 – 5,000 employees 63%

The data makes clear that in the context of organization size, annual revenue is a much greater indicator of likelihood of experiencing an attack than number of employees.

Root Causes of Ransomware Attacks

Survey respondents reported that an exploited vulnerability was the most common root cause of ransomware attacks (36%), followed by compromised credentials (29%). These findings align almost exactly with Sophos’ latest retrospective analysis of 152 attacks that our Incident Response and Managed.

Detection and Response (MDR) teams were brought in to remediate, where 37% started with an exploited vulnerability and 30% with compromised credentials.

Emails were the root cause of 30% (with rounding) of attacks: 18% started with a malicious email and 13% with phishing. 3% began with a brute force attack and just 1% with a download.

Root Causes by Industry

The media, leisure, and entertainment sector reported the highest percentage of attacks where the root cause was an exploited vulnerability (55%), indicating widespread security gaps in this area. Central and federal government had the highest percentage of attacks that started with compromised credentials (41%).

This may be due to a higher rate of credential theft in this sector, a lower ability to prevent exploitation of stolen credentials, or a combination of the two.

IT, technology, and telecoms reported the lowest rates for both exploited vulnerabilities (22%) and compromised credentials (22%), which likely reflects strong levels of cyber defenses in this sector. However, it did report the highest rates of email-based attacks, with over half (51%) starting in users’ inboxes.

Root Causes by Revenue

Analyzing the root causes by annual revenue reveals that exploited vulnerabilities and compromised credentials follow opposing propensity curves. The highest percentages of attacks that started with an exploited vulnerability were reported by the lowest (less than $10 million: 50%) and highest ($5 billion plus: 45%) revenue cohorts, dipping down to 30% in the middle cohort ($250 – $500 million).

Conversely, the use of compromised credentials peaks in the middle revenue cohort (33%), while the lowest usage was reported in the lowest (23%) and highest (26%) revenue cohorts.

Rate of Data Encryption

Data encryption has continued to rise, with adversaries succeeding in encrypting data in over three quarters (76%) of ransomware attacks. In fact, encryption levels are now at their highest point in the last four years. This likely reflects the ever-increasing skill level of adversaries who continue to innovate and refine their approaches.

Did the cybercriminals succeed in encrypting your organization’s data in the ransomware attack?

Data Encryption by Industry

Almost all sectors struggle to stop attacks before data can be encrypted: with just one exception, in every sector, over two thirds of attacks resulted in data encryption. The highest frequency of data encryption (92%) was reported by business and professional services.

IT, technology, and telecoms is the sector that bucks the trend, with adversaries succeeding in encrypting data in fewer than half (47%) of attacks. This is another indicator of the high level of cyber defenses and response preparation by this sector.

Data Theft

In 30% of attacks where data was encrypted, data was also stolen. This “double dip” approach by adversaries is becoming increasingly commonplace as they look to increase their ability to monetize attacks. The threat of making stolen data public can be used to extort payments and the data can also be sold. The high frequency of data theft increases the importance of stopping attacks as early as possible before information can be exfiltrated.

30%

Of ransomeware attacks where data was encrypted reported that data was also stolen.

Data Recovery

97% of organizations that had data encrypted got data back. Backups were the most common approach, used in 70% of incidents. 46% paid the ransom and got data back, while 2% used other means. Overall, one in five (21%) used multiple methods to restore their data. 1% of organizations that had data encrypted paid the ransom but didn’t get data back.

Data Recovery by Country

Overall, respondents in EMEA reported higher aggregate levels of backup use (75%) and lower aggregate levels of ransom payments (40%) than those in the Americas (65%/55%) and Asia Pacific (67%/49%). At a country level, France has the highest level of backup use (87%), closely followed by Switzerland (84%).

The importance of backups is demonstrated when we see that the two countries least able to use backups to restore data, Italy (55%) and Singapore (57%), are also the two countries that reported the lowest overall data recovery rates (93% and 90%, respectively). Italy also reported the highest propensity to pay the ransom (56%), closely followed by the U.S. and Brazil (both 55%).

In most cases, organizations that paid the ransom were able to recover data.

However, in France and the UK, around one in ten organizations that paid the ransom did not get any data back.

Ransom Payment and Backup Use by Revenue

Generally speaking, as annual revenue increases, so does the propensity of an organization to recover data by paying the ransom. At the same time, frequency of backup use drops.

Of the organizations with revenue of over $5 billion, 55% got data back by paying the ransom and 63% used backups. At the same time, 36% of organizations with revenue of less than $10 million recovered data by paying the ransom, while 80% used backups – the highest rate of backup use of all revenue cohorts.

Organizations with lower annual revenue have less money to fund ransom payments, forcing them to focus on backups for data recovery. At the same time, larger revenue organizations typically have complex IT infrastructures which may make it harder for them to use backups to recover data in a timely fashion. They are also the businesses most able to buy their way out of such situations.

The Impact of Cyber Insurance on Data Recovery

Organizations with cyber insurance were considerably more likely to recover encrypted data than those without such policies. However, the type of cyber coverage made very little difference: 98% of those with a standalone policy and 97% of those with a wider insurance policy that covers cyber got data back. In comparison, 84% of those without a policy were able to get encrypted data back.

Percentage of ransomware victims that recovered encrypted data:

There are likely several factors behind this variance. First, cyber insurance typically requires organizations to have backups and recovery plans as conditions of coverage.

Insurers are also able to guide ransomware victims through the recovery process in order to optimize outcomes. Furthermore, organizations with cyber insurance are more likely to pay the ransom to recover data than those without a policy.

Impact of insurance on propensity to pay ransom:

Ransom Payments

While overall propensity to pay ransom remains level with last year’s study, the payments themselves have increased considerably over the last year, with the average (mean) ransom payment almost doubling from $812,380 in 2022 to $1,542,333 in 2023. The median ransom payment reported in this year’s study was $400,000.

The study revealed a wide distribution of payments, however the proportion of organizations paying higher ransoms has increased from our 2022 study, with 40% reporting payments of $1 million or more compared to 11% last year. Conversely, just 34% paid less than $100,000, down from 54% last year.

Ransom Payments by Revenue

Perhaps unsurprisingly, the largest revenue organizations were most likely to pay the highest ransoms, reflecting that adversaries will adjust the amount they will accept based on ability to pay. The study did not distinguish between payments funded internally and those funded by insurance providers.

Interestingly, there was very little difference in both the mean and median ransom payments for organizations with $250 million – $500 million revenue and those with $500 million – $1 billion revenue.

Recovery Costs

Ransom payments are just one element of recovery costs when dealing with ransomware events. Excluding any ransoms paid, organizations reported an estimated mean cost to recover from ransomware attacks of $1.82 million, an increase from the 2022 figure of $1.4 million and in line with the $1.85 million reported in 2021.

Note: the 2021 and 2022 study question wording included ransom payments in the estimated costs, but they were removed from the 2023 survey wording. As a result, the year-on-year comparison should be considered indicative only.

Mean Recovery Cost:

Mean reported recovery costs started at $165,520 for organizations with annual revenue of less than $10 million, rising to $4,496,086 in the $5 billion plus cohort. 

Recovery Cost by Revenue

Recovery cost by data recovery method

Whichever way you look at the data, it is considerably cheaper to use backups to recover from a ransomware attack than to pay the ransom. The median recovery cost for those that used backups ($375,000) is half the cost incurred by those that paid the ransom ($750,000). Similarly, the mean recovery cost is almost $1 million lower for those that used backups. If further evidence were needed of the financial benefit of investing in a strong backup strategy, this is it.

Business Impact

84% of private sector organizations hit by ransomware reported that the attack caused them to lose business/revenue. Annual revenue had a relatively small impact on loss of business, with the lowest rate (79%) reported by the $250 million – $500 million cohort and the highest rate (88%) by those with less than $10 million and those with more than $5 billion revenue.

Industry type played a much greater role in propensity to lose business/revenue. Overall, lower education (94%) and construction and property (93%) were most likely to report some loss of business/revenue due to attacks and the manufacturing and production sector was least likely (77%).

Diving deeper, we see considerable variation in the sectors that reported losing “a lot” of business/revenue, with business and professional services (64%) more than five times more likely than IT, technology, and telecoms (12%) to have experienced this level of impact.

Recovery Time

While the time to recover from a ransomware attack is broadly in line with the 2022 report, the percentage that were able to recover in less than a day has dropped from 14% to 8%.

Recovery time by data recovery method

The research revealed that organizations that use backups to recover their data recover from the attack more quickly than those that pay the ransom. 45% of those that used backups recovered within a week, compared with 39% of those that paid the ransom. Almost one third (32%) of those that paid the ransom took more than a month to recover, while the figure for those that used backups is 23% (with rounding). While these two response options were not mutually exclusive and some respondents will have both paid the ransom and used backups, the recovery advantages of backups are clear.

Conclusion

Independent of revenue, geography, or industry, ransomware continues to be major threat to organizations. As adversaries continue to hone their attack tactics, techniques, and procedures (TTPs), defenders are struggling to keep pace, resulting in increased encryption rates.

The drop in the use of backups to recover encrypted data is considerable cause for concern. If further evidence was needed regarding the financial and operational benefits of investing in a strong backup strategy, this report provides it.

With the growth of the ransomware-as-a-service business model, we do not anticipate a drop in attacks in the coming year. Organizations should focus on:

  • Further strengthening their defensive shields with: ÂŹ
    • Security tools that defend against the most common attack vectors, including endpoint protection with strong anti-exploit capabilities to prevent exploitation of vulnerabilities, and zero trust network access (ZTNA) to thwart the abuse of compromised credentials ÂŹ
    • Adaptive technologies that respond automatically to attacks, disrupting adversaries and buying defenders time to respond ÂŹ
    • 24/7 threat detection, investigation, and response, whether delivered in-house or in partnership with a specialist Managed Detection and Response (MDR) service provider
  • Optimizing attack preparation, including making regular backups, practicing recovering data from backups, and maintaining an up-to-date incident response plan ĂŚ
  • Maintaining good security hygiene, including timely patching and regularly reviewing security tool configurations
Share Follow Tweet
Share Tweet

Related Articles

Loading...
Sophos Network Detection and Response (NDR)

Enhancing Security Operations with Sophos...

A Sophos Whitepaper: In today’s ever-changing threat landscape, organizations must adopt...
Read More
18/04/2023
Cyber Defenses in Cyber Insurance Adoption

The Critical Role of Frontline...

A Sophos Whitepaper:  Findings from a research study into the relationship...
Read More
18/04/2023

Let’s Connect

We provide more than just services.
We forge partnerships

"*" indicates required fields

By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. Reply Help for more information. You can reply STOP to opt-out of further messaging*
This field is for validation purposes and should be left unchanged.
Dekano Logo

© Dekano Strategic Partners
16 Industrial Pkwy S, Suite 105 Aurora, Ontario, L4G 0R4 Canada
All Rights Reserved | Privacy policy

Linkedin Instagram Twitter social-icon-svg tiktok_fill
Linkedin Twitter social-icon-svg tiktok_fill

Subscribe to Industry Insights

Subscribe to Industry Insights

"*" indicates required fields

By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. Reply Help for more information. You can reply STOP to opt-out of further messaging*
This field is for validation purposes and should be left unchanged.
  • Home
  • Services
    • Custom Web Applications
    • Cybersecurity Consulting
    • Developer Optimization
  • Blogs
  • About