Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Ransom payments are tip of the iceberg for the true cost of ransomware
Articles

Ransom payments are tip of the iceberg for the true cost of ransomware

Neil StobartBy Neil StobartFebruary 15, 2022Updated:January 4, 20233 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ransomware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Calculating the true cost of a ransomware attack is a notoriously difficult task for businesses. There is the immediate cost of getting business operations up-and-running again but there is the reputational damage and break down in investor confidence to consider as well.

According to a Ransomware Victims Report carried out in 2021, over half (55%) of US-based IT decision-makers whose organisation had experienced a ransomware attack in the last two years chose to pay a ransom. The average payment was $223,000, with 14% paying $500,000 or more. In addition, these organisations spent an average of $183,000 on other costs directly related to the attack, with 37% of respondents paying at least $100,000 more.

For many businesses, this daunting figure of almost half a million dollars is just the beginning. 52% of the IT decision-makers said their organisation suffered substantial reputational damage following a ransomware attack. For publicly listed companies, this can seriously affect their share price. Just look at the high-profile Equifax hack of 2017. Following this, the company’s share price dropped by 31% and took two years to recover.

Smart attackers understand how important a company’s share price is to its board, which is one of the reasons ransom demands continue to increase.

The difficulty of keeping ransomware out

Ransomware is insidious, and once it enters an organisation it can spread like wildfire. Research found that in over half of successful attacks (56%), attackers gained control of their victims’ data and demanded a ransom within just 12 hours. In the case of phishing-led attacks, this figure rose to 76%.

Of the victims surveyed, 49% had perimeter defences such as anti-malware in place before the attack, 54% had invested in anti-phishing training for employees and 43% had implemented internal access controls. As these figures demonstrate, even organisations with robust cyber-attack prevention mechanisms can fall victim to ransomware attacks.

Unfortunately, paying a ransom does not guarantee that your data will be returned. As you can imagine, cyber criminals can’t always be relied upon to keep up their end of the bargain. In fact, only 57% of survey respondents who paid a ransom had all their data restored. Plus, cyber insurance is not the panacea that many think it to be. 79% of respondents had cyber insurance, which covered an average of just 60% of their ransomware payment and other costs. What’s more, 88% of cyber insurance holders saw a significant increase in their premiums post-attack.

A change in strategy

So, what can organisations do to protect themselves? The harsh reality is that businesses need to accept that it’s not a case of if they’ll fall victim to a ransomware attack, but when. As such, it makes sense for IT decision-makers to adopt a cybersecurity strategy that focuses on recovery as much as prevention. More specifically, organisations should have an immutable, or unchangeable, backup copy of their data. Put simply, an immutable backup uses WORM (write once, ready many) storage to prevent hackers from encrypting or deleting data for a specified period. Then, when an attack happens, organisations can quickly restore the uninfected backup copy without having to pay ransom.

Data immutability can now be easily implemented and run automatically as part of a standard backup process. This not only enables ransomware victims to minimise disruption and recovery costs but also helps break the cycle of ransomware payments funding further, more sophisticated, attacks.

Neil Stobart
  • Neil Stobart
    Why Safeguarding Endpoint Data In Distributed IT Environments Requires A Different Approach To Storage

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}