November 23, 2016 By Mark Samuels 2 min read

Nearly half of organizations across the globe have fallen victim to a ransomware campaign in the past 12 months. Cybersecurity executives must respond to the challenge with an effective mix of strategy and technology.

That is the main conclusion drawn from a recent SentinelOne survey conducted by market research firm Vanson Bourne. The study also found that 80 percent of businesses suffered three or more attacks in 2016. Additionally, organizations hit by the ransomware epidemic suffer an average of six attacks a year.

Ransomware creates a significant problem for cybersecurity executives. The vast majority of respondents, to the tune of 94 percent, indicated that an attack has an impact on their organization. The challenge now is for IT and security professionals to turn the threat posed by the ransomware epidemic into an opportunity to establish better business practices.

Boosting Business Awareness

The good news for security executives is that attacks often create renewed business awareness of the cybersecurity challenge at hand. More than two-thirds of survey respondents said they plan to increase spending on IT security, and more than half will change their IT security strategy to focus on mitigation.

Eighty-five percent reported that their organizations were able to identify attackers. Almost all respondents — 95 percent — said they had gained insight into the motivations of cybercriminals as a result of a ransomware attack. The most common motives are financial gain (54 percent), simple disruption to a successful business (47 percent) and cyber espionage (42 percent). Employee information, financial data and customer information, meanwhile, are the types of knowledge most likely to be affected by an attack.

Building a Stronger Operation

The continued threat of ransomware, however, does leave some executives feeling perplexed. Evidence suggests business are willing to spend to help mitigate the security risk, yet the scale of the potential challenge can lead some business managers to question the success of their investments.

The Vanson Bourne research revealed that 54 percent of executives believe their organizations have lost faith in traditional cybersecurity techniques such as antivirus, Help Net Security reported. Seventy-one percent of respondents indicated that their business needs a new solution to meet the challenges associated with ransomware.

Jeremiah Grossman, chief of security strategy at SentinelOne, recognizes the scale of the technological challenge. “It’s clear that there’s an immediate need for a new generation of security technologies that can discover, stop and adapt to the new breed of threats and hacker strategies,” Grossman said.

The Ransomware Epidemic Is Spreading

The Proofpoint Threat Report released earlier this year also highlighted the ever-increasing risk posed by ransomware. The research suggested attackers’ exploits are more likely to be successful if security teams are unprepared.

The key message for cybersecurity executives is to use increased business awareness of the risk posed by ransomware to support a new, targeted approach that draws on the expert resources of trusted technology partners.

For the ransomware report, Vanson Bourne surveyed 500 cybersecurity decision-makers at organizations around the world with more than 1,000 employees. Interviews were conducted with 200 executives in the U.S., 100 in the U.K., 100 in France and 100 in Germany.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today