We have just released the first long-time study focusing on IT Pros experience with ransomware. In June 2016 we surveyed 1,138 companies in a variety of industries and compared your levels of concern about ransomware in 2014 to 2016. It's not a pretty picture.
Huge Jump in ransomware infections from 20% to 38%
The study showed there is growing apprehension over ransomware, rising to 79% from 73% of those who are very or extremely concerned about it. There was a huge jump in companies hit directly by ransomware at 38% in 2016 compared to 20% in 2014. Midsize companies 250 -1000 were the hardest hit at 54%. Two out of three knew someone who was hit at 65% compared to 43% in 2014. IT professionals surveyed are even more worried ransomware will continue to grow scoring 93% over 88% in 2014.
We thought it would be interesting to see the level of impact that ransomware has had in two years time. The threat of ransomware is very real and IT professionals are increasingly realizing traditional solutions are failing. IT pros agree that end-user Security Awareness Training is one of the most effective security practices to combat these ransomware threats.
Nearly half say they would be forced to pay the ransom
Surprisingly, only 40% would fully rely on backup to solve the situation. However, faced with the potential scenario of several weeks of failed backups, nearly half say they would be forced to pay the ransom. This can have a grave impact on organizations as backups fail 50-66% of the time, according to the method used (tape vs cloud).
According to a report by Symantec, 47% of enterprises lost data in the cloud and had to restore their information from backups, 37% of SMBs have lost data in the cloud and had to restore their information from backups and 66% of those organizations saw recovery operations fail.
- 93% expect ransomware to increase the rest of 2016 over 88% in 2014.
- 61% feel email attachments pose the largest threat compared to 47% in 2014.
- A shocking 38% have been hit by ransomware compared with 20% in 2014. Companies with 250-1000 employees were the biggest targets at 54% compared with 1000+ employees at 41% and below 250 at 35%.
- In 2016, 65% know someone who has been hit compared to 43% in 2014. 71% of Tech companies know someone who has been hit, higher than education and banking who hover at or slightly above 50%.
- Manufacturing has been hit the hardest at 54% compared with 44% in Healthcare, Education at 35%, Tech at 29% and Banking at 28%.
- 89% consider Security Awareness Training the most effective protection from ransomware, immediately followed by backup 83%, almost identical to 2014.
- Only 19% feel their current solutions are very effective, while 70% feel they are somewhat effective.
- Confidence in email and spam filtering effectiveness is 72%.
- If faced with 4 hours of lost work from ransomware encryption, only 40% would rely on backup compared with 81% in 2014. 51% would just reformat and start from scratch (nuke).
- The study asked when confronted with a scenario where backups have failed and weeks of work might be lost, 42% would begin with paying the $500 ransom and hope for the best vs 57% in 2014.
Our study shows corporate awareness of phishing attack vectors has increased but users need more help as techniques evolve and criminal exploits become more sophisticated. Just take a look at how many new ransomware strains have been developed since the beginning of the year! The overwhelming majority of IT pros think the criminals behind ransomware should be prosecuted and sent to jail for a long time. KnowBe4 agrees, but US law enforcement has no jurisdiction in Eastern Europe where these criminals are largely free to commit their crimes, and we have to rely on our own ingenuity to protect against this growing threat.
61% feel email attachments pose the largest threat compared to 47% in 2014.
This ties back immediately to the vulnerabiity of your users to malware that makes it through your filters into their inbox. Many of the email addresses of your users are exposed on the Internet and easy to find for cybercriminals. With these addresses they can launch social engineering, spear- phishing and ransomware attacks on your organization.
The more email addresses that are exposed, the bigger your attack footprint is, and the higher the risk. It’s often a surprise how many of your addresses are actually out there.
Find out which of your users emails are exposed before the bad guys do.
The Email Exposure Check is a one-time free service. We will email you back a report containing the list of exposed addresses and where we found them within 2 business days, or sooner!
Don't like to click on redirected buttons? Cut & Paste this link in your browser instead: