Study reveals 82% of organisations choose to pay ransomware demands

A study by security firm ‘Proofpoint’ has revealed that 82 per cent of UK organisations whose systems were infected by ransomware in 2021 opted to pay the ransom.

Despite cybersecurity and government agencies warning against paying, Proofpoint’s ‘2022 State of the Phish’ report states that this UK figure for 2021 is the highest in any region surveyed and is 40 per cent higher than the global average.

Phishing Attacks & Ransomware 

Phishing attacks are one of the main ways that criminals deliver ransomware (and other malware) or direct victims to a site where they download the ramsomware that allows criminals to access their networks. Proofpoint’s report showed that more than three-quarters of organisations (78 per cent) saw email-based ransomware attacks in 2021 and 91 per cent of UK organisations reported facing bulk phishing attacks in 2021. In fact, In the first three quarters of 2021, 15 million phishing messages with malware payloads were linked to later stage ransomware. For example, these malware families included Dridex, The Trick, Emotet, Qbot, and Bazaloader.

Why Not Pay? 

The National Cyber Security Centre (NCSC) states that “even if you pay the ransom, there is no guarantee that you will get access to your computer, or your files” and that “occasionally malware is presented as ransomware, but after the ransom is paid the files are not decrypted. This is known as wiper malware.” 

Also, organisations that pay the ransom will still have infected computers, will be paying criminal groups allowing them to continue and bring suffering to others, and it makes organisations that are known to pay to be more likely to be targeted in the future.

What Does The Survey Say Happened To Those Who Paid? 

As the Proofpoint study showed, 60 per cent of organisations chose to at least negotiate with the attackers, and 82 per cent paid.  However, despite advice against paying, only 4 per cent of those organisations who paid a ransom were unable to retrieve their data. This is likely to be either because the key didn’t work properly, or the attackers had simply made off with the money.

Is No Backup A Reason To Pay The Ransom? 

It would seem logical that a lack of an effective back up may be a reason why organisations would pay a ransom. A report by cyber security company Emsisoft (2020), however, showed that some victims of attacks have been capable of restoring their networks from backups but have still opted to pay the ransom.

It should also be noted that one tactic that ransomware attackers often use is to threaten to publish an organisation’s data if the ransom isn’t paid.

Protecting Your Business From Ransomware Attacks 

Ways in which businesses can protect themselves from falling victim to ransomware attacks include:

Educating staff about the risk of phishing emails and emails carrying malware, how to spot phishing/suspicious emails, and to never open emails that appear suspicious. Make regular backups of the most important files, keep them off-site (e.g., the cloud) and make multiple copies of files using different backup solutions. Make sure that the devices containing the backup are not permanently connected to the network, scan backups for malware before files are restored, and regularly patch products used for backup. Stop malicious content reaching company devices – e.g. by filtering to only allow file types you would expect to receive, blocking websites known to be malicious, actively inspecting content, and using signatures to block known malicious code. Prevent attacks via Remote Desktop Protocol (RDP), or unpatched remote access devices by disabling RDP if it’s not needed, enabling MFA at all remote access points into the network, using a VPN, and patching known vulnerabilities in all remote access and external-facing devices. Prevent malware running on devices – e.g. by centrally managing devices to only allow trusted apps and disabling or constraining scripting environments and macros. Plug vulnerabilities in devices – e.g. by installing security updates as soon they are available and enabling automatic updates for operating systems, applications and firmware.

What Does This Mean For Your Business?

Making sure there are strong security measures in place (particularly where email is concerned) and checking data is definitely being backed up securely on a regular basis (and that it is accessible when needed) can help towards effective ransomware protection. Attackers can pressurise businesses into paying (e.g. by threatening to destroy and/or publish data), and an attack may simply come at a bad time for a business where a long disruption could seem less costly than paying.

The fact is, however, that paying may not guarantee the return of data and may make a business more likely to be attacked again because they paid. Ultimately, businesses will, as the stats show, make their own decisions, but by their very nature, attackers can’t be trusted, and paying now could lead to even bigger problems later, and will fuel the continuing cycle of attacks for others too.

About J700 Group Limited

J700 Group are a Lancashire-based, family-run, professional, and responsive, Managed Solutions Provider helping Businesses, the Education Sector, and the Healthcare Sector to utilise Innovative IT Consultancy Services, Cloud Solutions, Cyber Security, Microsoft 365, Telecoms, Web Design and SEO solutions to propel their organisation to the next level and beyond.

As an experienced IT Support Provider, helping businesses across Lancashire & Manchester, if you need any assistance with your IT including IT Hardware, a Disaster Recovery Policy or Managed Backup Solutions; Call us today: 0333 7721 700  to see how we can help your business.

Where to find us: Prinny Mill Business Centre, 68 Blackburn Road, Haslingden, Lancashire, BB4 5HL

Enjoyed this? Read more from J700 Group Limited

Latest news

1

Blackburn snack firm lands Aldi listing after impressing on TV Cluster Club Aldi

Blackburn snack firm lands Aldi listing after impressing on TV

25 Apr 2024

2

Radio 2 music festival heading to Preston Richie Anderston At Moor Park

Radio 2 music festival heading to Preston

25 Apr 2024

3

Roadshow Promotions to help deliver numeracy initiative in Stoke Councillor Majid Khan, Lord Mayor of Stoke-on-Trent and Lisa Capper, MBE, Principal and CEO of Stoke-On-Trent College on a visit to the promotional bus.jpg.jpg

Roadshow Promotions to help deliver numeracy initiative in Stoke

25 Apr 2024

4

New graphic design appointment for Studio LWD Callum Weiss Studio LWD.jpg.jpg

New graphic design appointment for Studio LWD

25 Apr 2024

5

The SUMO Guy to inspire Blackpool businesses at growth event Paul Event LBV.jpg.jpg

The SUMO Guy to inspire Blackpool businesses at growth event

25 Apr 2024

Background image for hub sign up block

LBV Hub

Reach 50,000 members of the Lancashire business community

Post your news
Post your events
Post your offers
Company profile
Social reach
Magazine coverage
Sign-up
Events
Help to Grow Management Course
HTG2.png.png
LBV Hub Seminars
15 Apr 2024 - 17 Jul 2024

Help to Grow Management Course

Preston Campus , Preston , PR1 2HE

09:30 - 14:00

Business Networking in Preston- BNI Brunch
EVENT LISTING SIZING Brunch .png.png
LBV Hub Networking
26 Apr 2024

Business Networking in Preston- BNI Brunch

Samlesbury Preston Hotel, Preston New Road, Preston, PR5 0UL

09:30 - 11:00

Business Networking in Blackburn - BNI Infinity
EVENT LISTING BNI Infinity.png.png
LBV Hub Networking
26 Apr 2024

Business Networking in Blackburn - BNI Infinity

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:30 - 08:30

Business Networking in Blackburn - BNI Vista
EVENT LISTING SIZING Vista.png.png
LBV Hub Networking
30 Apr 2024

Business Networking in Blackburn - BNI Vista

Hampton by Hilton, 2 Frontier Ave, Blackburn, BB1 3AL

06:45 - 08:30

Driving Energy Efficiency and Sustainability: Software Solutions for the Metal Industry
LBV Hub Webinar
30 Apr 2024 - 30 Apr 2024

Driving Energy Efficiency and Sustainability: Software Solutions for the Metal Industry

Online - Zoom, Blackpool, FY4 2FG

10:00 - 11:00

Business Networking in Chorley - BNI Endeavour
EVENT LISTING SIZING Endeavour.png.png
LBV Hub Networking
30 Apr 2024

Business Networking in Chorley - BNI Endeavour

Oak Royal, Bury Lane, Chorley, PR6 8SW

06:30 - 08:30

FREE online event - 30 Minutes: How to decarbonise your business
BU 2024 Events2.jpg.jpg
LBV Hub Webinar
01 May 2024

FREE online event - 30 Minutes: How to decarbonise your business

Online, Blackpool , FY4 1EW

10:00 - 10:30

Business Networking in Lancaster - Eden Business Network
EVENT LISTING Eden Business Network.png.png
LBV Hub Networking
01 May 2024 - 01 May 2024

Business Networking in Lancaster - Eden Business Network

The Borough, 3 Dalton Square, Lancaster, LA1 1PP

18:30 - 20:30

Business Networking in Preston - BNI Diamond
EVENT LISTING BNI Diamond.png.png
LBV Hub Networking
01 May 2024

Business Networking in Preston - BNI Diamond

The Marriot Hotel, Garstang Road, Broughton, PR3 5JB

07:15 - 09:00

Business Networking in Accrington - BNI Zeus
EVENT LISTING SIZING Zeus.png.png
LBV Hub Networking
01 May 2024

Business Networking in Accrington - BNI Zeus

The Mill House, Corn Mill Yard, Accrington, BB5 5HX

06:45 - 08:30

Business Networking in Lancaster - BNI Castle
EVENT LISTING BNI Castle.png.png
LBV Hub Networking
02 May 2024

Business Networking in Lancaster - BNI Castle

Vale of Lune RUFC, Powder House Lane, Lancaster, LA1 2TT

06:45 - 08:30

Business Networking in Burnley - BNI Kudos
EVENT LISTING BNI Kudos.png.png
LBV Hub Networking
02 May 2024 - 02 May 2024

Business Networking in Burnley - BNI Kudos

Prairie Sports Village, Windemere Avenue, Burnley, BB10 2FU

06:45 - 08:30

Advertise with us

Reaching 50,000 members, our print, digital and event platforms offer a fantastic way to raise your business profile and help you grow.

Find out more Lbv115 Online Graphic
Subscribe now

Weekly news bulletin