Share this article
Earlier this month the world’s largest meat supplier, JBS, paid a ransom equivalent to nearly £8 million. This follows the payment of over £3 million by Colonial Pipeline in May. Both payments were in response to ransomware attacks. Not only do these high-profile cases highlight the exponential growth in the scale and value of this particular form of cybercrime, but they also beg the question: should you consider paying a ransom to restore your stolen or encrypted data?
The first recorded ransomware attack was carried out by posting a floppy disk to attendees to a World Health Organisation international AIDS conference back in 1989. More than thirty years on, organised ransomware groups have updated and refined their process and, in the wake of the disruption caused by the Covid pandemic, attack volumes are up an astonishing 900% year on year.
The cryptocurrency Bitcoin has had a role in this because it is fast and easy to use and, above all, hard to trace. Global ransomware payments made in Bitcoin went up 311% in 2020.
According to the CEO of JBS: “We felt this decision had to be made to prevent any potential risk for our customers.” This reflects the thought process behind so many ransomware payments and, given the fact that attackers are identifying targets with minimal tolerance for downtime, it is completely understandable. In fact, even the FBI has softened its approach, conceding that organisations need to consider all their options.
Some may be persuaded by the cautionary tale of Travelex, which shows how quickly a major global business can be derailed. In January 2020 Travelex was hit with a ransomware attack with the company initially refusing to pay $6 million for the release of its sensitive business and customer data. In retaliation, the criminals released a cache of its data online, including customer payment details and company financials. The major disruption caused by this damage together with a month of being locked out of its systems was compounded by the Covid crisis, and although Travelex eventually agreed to pay $2.3 million, it was too little too late. In August 2020 the largest foreign exchange company in the world went into administration.
When considering the question of paying a ransom, however, it is important to emphasise that it is not a simple black and white issue: to pay or not to pay. Because there is no guarantee that, even if you do submit to a hacker’s demands, you will get your data back. That is because, although it may sound blindingly obvious, you just can’t trust criminals. The reality is that in today’s world of cyber criminality there is little evidence of honour among thieves. The fact is that a 2021 survey found of the 57% of ransomware victims who paid up, 28% failed to recover their data.
Also, if you do pay, there is evidence that you may then be asked again, repeatedly, for additional payments. Moreover, paying up can attract the attention of other hackers who will see you as a source of recurring revenue. Veritas found that once companies had been involved in a ransomware incident, they went on to suffer an average of 4.46 additional attacks.
As if things were not difficult enough, penalties for falling victim to ransomware are also rising. On top of the downtime and lost revenue caused by the attack itself, there are also punitive regulatory and legislative fines for data loss resulting from ransomware attacks.
It is also worth noting that global research has revealed that only 23% of customers believe businesses should ever negotiate with criminals. Yet, the damage to reputation caused by the release of customer data can have huge financial consequences.
The key is anticipation and preparation. Although we can all hope that robust cyber defences will act as a deterrent, the ransomware attacks on global giants indicate that a specific ransomware strategy is also advisable. Within your business continuity planning efforts, taking the time to understand how you would respond in the event of this type of breach is, sadly, necessary.
Ransomware can spread through a network rapidly so multiple backups need to be kept in a protected environment, away from the main network. It is recommended that files are copied three times, with copies held on two devices and one copy stored offsite. That way you can restore the stolen or encrypted data from other secure sources. Although this can take up huge amounts of storage space, carefully managing retention periods can ease the pressure. A master catalogue of files held will facilitate data access so individual files can be found easily.
It is essential to isolate backups. Off-site backups can be stored in the Cloud which provides a low-cost and scalable option. Copies held on devices need to be immutable, in an unchangeable format.
Remote working has seen an increase in vulnerability with employees working outside the safety of the office environment. For example, the Colonial Pipeline ransomware attack has now been attributed to the breach of a virtual private network, commonly used by remote employees to connect to a company system. So, it is prudent to conduct a thorough review of your remote working protocols and seek professional advice if you are in any doubt as to the security of your current practices.
Some ransomware attacks are successfully launched long before the ransom is demanded, giving criminals plenty of time to gather and encrypt data. Automated tools which focus on endpoint security, IDS and firewalls are helpful in preventing the initial infection but security teams also need to have the time and resource to use strategies and tools which can identify suspicious activity during this dormant period. Automating key defensive actions such as blocking suspicious IP address can make all the difference in providing some breathing space.
When working on defensive and recovery strategies, organisations benefit from the expertise of a trusted Major Incident Manager (MIM). Finding a competent team member or new appointee to fill this role can be problematic and costly but a MIM service can be engaged to provide this support at considerably lower cost.
The MIM service provides support and resource to the in-house team to develop a remediation action plan and co-ordinate the organisation’s response. The MIM can also manage regular rehearsals and rigorous testing to uncover any issues early on providing an invaluable advantage in the battle against cyber criminals.
Explore our website today to find out more about our Major Incident Manager service and our suite of Incident Response solutions.