Menu

Call us on 03450 21 21 51

Less than secure: ransomware continues to thrive in the UK
The SRM Blog

Less than secure: ransomware continues to thrive in the UK

Claire Greathead

Written by Claire Greathead

27th November 2023

Share this article

ransomware

The latest British Library breach shows there is still much to be done when it comes to securing UK business data

The British Library has confirmed that its personal HR data has been posted online, for sale to the highest bidder. The attack, which took place in October, has been claimed by known ransomware group Rhysida. They’ve set the “exclusive, unique, and impressive” data for sale with a starting bid of 20 bitcoins (around £596,000) and a deadline of 27th November.

This incident serves as a stark reminder that, as one of the most common forms of cybercrime, ransomware poses a significant threat to businesses across the UK, regardless of size and industry. Despite advances in tech and a nationwide push to school organisations on the importance of effective cybersecurity, the threat of ransomware is more prevalent than ever.

We’re going to take a closer look at the figures surrounding ransomware, exploring what risks businesses face and what you can do to ensure that your data remains protected.

Ransomware: here to stay?

A new assessment from the National Cyber Security Centre (NCSC) reveals the ransomware industry has evolved into a sophisticated supply chain that continues to defy western governments and put unprotected businesses at risk. Ten years after the first widespread ransomware attack – Cryptolocker – the crime continues to take advantage of business’ weak online security.

The main perpetrators existing in Russia, Belarus, and several other former Soviet Union countries, but operators have also been detected in India, West Africa, and South-East Asia.

A recent operation – Qakbot – infected millions of computers with its malware, leaving countless businesses on the back foot. Chester Wisniewski, field chief technology officer at Sophos, says ransomware has proven itself “a tried and true method of extorting money from victims”, describing it as “an everyday part of the criminal threats we face.”

In recent months, hacker group CLoP made headlines by hitting dozens of western company that rely on the MOVEit software, including the BBC, British Airways, Boots and more.

What is ransomware?

Ransomware is one of the most common kinds of cybercrime. It is a type of malware that prevents you from accessing your own device and data, usually due to external file encryption. In most cases, a criminal group will encrypt your data and demand a ransom in exchange for decryption, hence the crime’s name.

Often, hackers will threaten to delete or leak the data they’ve stolen. This can be particularly damaging if the data in question includes sensitive customer information, as businesses can face hefty fines for failing to keep customer data protected and confidential.

Should you pay your ransom?

Following on from the British Library’s data theft, the institution said, “We have taken targeted protective measures to ensure the integrity of our systems, and we continue to undertake an investigation with the support of the National Cyber Security Centre (NCSC), the Metropolitan Police, and cybersecurity specialists.”

The NCSC adds: “We are working with the British Library to fully understand the impact of an incident. Ransomware is the key cyber threat facing the UK, and all organisations should take immediate steps to limit risk.”

These steps, however, rarely include paying hackers the money they demand. Ransomware has three key stages: access, activation, and ransom demand, and payment is usually demanded via an anonymous web page and usually in cryptocurrency.

Law enforcements do not encourage victims to pay a ransom because:

  • You are effectively funding criminal activity
  • There is no guarantee you’ll get your data back
  • Your computer will still be infected
  • You’re more likely to get targeted in future

How to protect your business data

Like most cybercrimes, it is much easier, cheaper, and less damaging to prevent ransomware rather than dealing with the fallout. As such, it’s important to take key steps to ensure your business data is safe and secure.

Some of the key actions to protect against ransomware include:

  • Backing up your data regularly and testing to ensure your data is recoverable
  • Reducing the likelihood of malware reaching your data by blocking malicious websites
  • Inspecting content carefully
  • Filtering the kind of files you’re willing to receive

Certain programs like App Locker can be used to limit which applications can be accessed, meaning malware can’t access all data even if it reaches your device. Investing in effective data protection software can also deter criminals.

Creating a Disaster Recovery plan

Even with all the necessary defences in place, you should still prepare for the worst. Create a plan of action should you fall victim to ransomware.

This should include:

  • A communication strategy: how will your team be informed?
  • A public response: how will your clients be told?
  • Identifying the roles of each member of the team
  • Emergency response procedures
  • Backup data operations
  • Recover actions to make sure your business downtime is limited

Your DR plan should be regularly tested and updated, to make sure it still applies to the way your business runs and stores data. That way, should disaster strike, your team can act decisively and speedily.

If you’re looking for effective data protection for your business, or have any questions about the threat of ransomware on your organisation, don’t hesitate to get in touch. Click here to reach out to the SRM team and we’ll be happy to help.