Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Average cost for rescuing information from a ransomware attack: $84,000

Costo por ataque ransomware

International. According to Oswaldo Palacios, senior account executive in Mexico and NOLA at Guardicore, a company that is part of Akamai, the demands of cybercriminals are growing proportionally with the increase in ransomware attacks, with an average cost for the ransom of the information of 84 thousand dollars.

The most painful thing about these charges, in addition to the obvious fiscal detriment and that imply liquidity for those who commit crimes, is that they go hand in hand with an excessive increase in attacks of this type. According to the World Economic Forum's most recent report, WEF The Global Risk Report 2022, ransomware increased by 435% in 2020. In addition, the value of crypto-assets received as payments to rescue information was quadrupled, taking into account crypto payment addresses that have already been identified as being used for these purposes.

As can be detailed below, in Figure 3.1 of the aforementioned report, the total in millions of dollars of cryptocurrency value received in 2020, in addresses identified for ransomware payment, reached 406.34, which translates into an increase of 437.21% compared to 2019.millones de dólares de valor de criptomonedas recibidas en 2020 en direcciones identificadas para pago de ransomware

Apart from this data, the document notes that 85% of the World Economic Forum's Leading Cybersecurity Community maintains that ransomware is becoming a threat "that grows dangerously and represents a major concern for public safety." It also considers that the sophisticated cyber tools we currently have "also allow cyber threat actors to attack their selected targets more efficiently" so that they should not settle for opportunity-based targets, a matter that demonstrates the high potential for targeted attacks, which can lead to greater financial damage, but also social and reputational in the future.

- Publicidad -

What should you consider in a ransomware attack?

In that sense, Palacios states that there are several parameters to measure the impact of ransomware, but the most relevant corresponds to the question of how much money would I lose per minute, hour or day if my computer systems stop working? Considering that transactional and billing portals, among others, can be considered critical applications.

Another parameter to consider is the time it would take your company to restore the operation of its systems, or the cost of implementing a disaster recovery system, which may include alternate sites, staff training programs, and backup systems.

The case of the American provider CompuCom stands out, which confirmed (in March 2021) that it expected to lose up to 8 million dollars in revenue due to the temporary suspension of certain services after the DarkSide ransomware attack, in which the colonial pipeline company was attacked. To this figure he added a total anticipated expenditure of 20 million dollars to restore his services and address other problems remaining from the attack.

For Palacios, despite the fact that experts recommend not paying a ransom demanded by cybercrime, some companies pay the ransom fees in full, but do not receive the means to reverse the encryption of their data, so, in those specific cases, organizations spend a lot of time and money to rebuild what was lost.

Possible measures to avoid paying for ransomware
Palacios believes that since the average ransomware incident lasts 16.2 days, creating a defense strategy that prevents lateral movement at the beginning of an attack can help prevent widespread data loss, high costs, and downtime if the worst were to occur. He adds that, some attackers may exfiltrate sensitive materials to sell or exploit.

Once a ransomware attack is discovered in an IT environment, Palacios recommends that security leaders should ensure that there are no more infected assets, which can be achieved with a visibility tool at the level of the communication process within a server, in this way the activation of the malware will be neutralized and it will be known exactly where it is. "Another important point is that it cannot be propagated in the network, something fundamental so that this does not happen is to have a microsegmentation tool that allows isolating the critical assets of the company."

- Publicidad -

Cobros por ataques ransomware

The expert believes that a strategy to prevent new ransomware attacks is to have visibility and segmentation at the process level in servers or assets, inside and outside the data center. "We can't protect what we can't see." Thus, it states that the answer is to create a whitelist of communications processes, to know when an infected asset tries to communicate with the controller server and block said request. "This will be proactively mitigating the threat."

Finally, Palacios indicates that planning a ransomware mitigation and defense strategy must begin long before an organization is affected. This is possible by using network segmentation policies, which allow organizations to block common ransomware propagation techniques. Oswaldo concludes that using zero-trust microperimeters around critical applications, backups, file servers and databases, coupled with creating segmentation policies that restrict traffic between users, applications and devices, will drastically reduce the attack surface.

Iris Montoya Ricaurte
Author: Iris Montoya Ricaurte
Editora
Periodista con amplia experiencia en corrección de estilo y generación de contenidos de valor para el sector especializado - [email protected]

No thoughts on “Average cost for rescuing information from a ransomware attack: $84,000”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Suscribase Gratis
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS

Webinar: NxWitness el VMS rápido fácil y ultra ligero

Webinar: Por qué elegir productos con certificaciones de calidad

Por: Eduardo Cortés Coronado, Representante Comercial - SECO-LARM USA INC La importancia de utilizar productos certificados por varias normas internacionales como UL , Ul294, CE , Rosh , Noms, hacen a tus instalciones mas seguras y confiables además de ser un herramienta más de venta que garantice nuestro trabajo, conociendo qué es lo que certifica cada norma para así dormir tranquilos sabiendo que van a durar muchos años con muy bajo mantenimiento. https://www.ventasdeseguridad.com/2...

Webinar: Anviz ONE - Solución integral para pymes

Por: Rogelio Stelzer, Gerente comercial LATAM - Anviz Presentación de la nueva plataforma Anviz ONE, en donde se integran todas nuestras soluciones de control de acceso y asistencia, video seguridad, cerraduras inteligentes y otros sensores. En Anviz ONE el usuario podrá personalizar las opciones según su necesidad, de forma sencilla y desde cualquier sitio que tenga internet. https://www.ventasdeseguridad.com/2...

Webinar: Aplicaciones del IoT y digitalización en la industria logística

Se presentarán los siguientes temas: • Aplicaciones del IoT y digitalización en la industria logística. • Claves para decidir el socio en telecomunicaciones. • La última milla. • Nuevas estrategias de logística y seguimiento de activos sostenibles https://www.ventasdeseguridad.com/2...

Sesión 5: Milestone, Plataforma Abierta que Potencializa sus Instalaciones Manteniéndolas Protegidas

Genaro Sanchez, Channel Business Manager - MILESTONE https://www.ventasdeseguridad.com/2...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter