592 IT/cybersecurity leaders share their ransomware experiences from the final yr, revealing recent new insights into the realities going through them as we speak.
The newest annual Sophos research of the real-world ransomware experiences of economic companies organizations explores the total sufferer journey, from assault charge and root trigger to operational influence and enterprise outcomes.
This yr’s report sheds mild on new areas of research for the sector, together with an exploration of ransom calls for vs. ransom funds and the way typically monetary companies organizations obtain help from legislation enforcement our bodies to remediate the assault.
Obtain the report to get the total findings.
Assault charges have remained regular, however restoration is dearer
65% of economic companies organizations have been hit by ransomware in 2024, according to the 64% charge reported in 2023 however above the speed reported within the earlier two years.
90% of economic companies organizations hit by ransomware previously yr stated that cybercriminals tried to compromise their backups through the assault. Of the makes an attempt, just below half (48%) have been profitable – one of many lowest charges of backup compromises throughout sectors.
49% of ransomware assaults on monetary companies organizations resulted in information encryption, a considerable drop from the 81% encryption charge reported in 2023. The sector reported the bottom information encryption charge throughout all sectors and the very best success charge in stopping assaults earlier than information will be encrypted.
The imply value in monetary companies organizations to get better from a ransomware assault was $2.58M in 2024, a rise from the $2.23M reported in 2023.
Units impacted in a ransomware assault
On common, 43% of computer systems in monetary companies organizations are impacted by a ransomware assault, a little bit under the cross-sector common of 49%. Having your full surroundings encrypted is extraordinarily uncommon, with solely 4% of organizations reporting that 91% or extra of their units have been impacted.
The propensity to pay the ransom has elevated in monetary companies
62% of economic companies organizations restored encrypted information utilizing backups, and 51% paid the ransom to get information again. As compared, globally, 68% used backups and 56% paid the ransom.
The three-year view of economic companies organizations reveals that the hole between the usage of backups and ransom cost has narrowed over the past 12 months. In 2023, 69% of economic companies organizations used backups, and 43% paid the ransom to revive encrypted information after the assault.
A notable change over the past yr is the rise within the propensity for victims to make use of a number of approaches to get better encrypted information (e.g., paying the ransom and utilizing backups). On this yr’s research, 37% of economic companies organizations that had information encrypted reported utilizing multiple technique, greater than double the speed reported in 2023 (16%).
Monetary companies victims hardly ever pay the preliminary ransom sum demanded
90 monetary companies respondents whose organizations paid the ransom shared the precise sum paid, revealing that the typical (median) cost has elevated 18X over the past yr, from $109,000 to $2M.
Solely 18% paid the preliminary ransom demand. 67% paid lower than the unique demand, whereas 15% paid extra. On common, throughout all monetary companies respondents, organizations paid 75% of the preliminary ransom demanded by adversaries.
Obtain the total report for extra insights into ransom funds and lots of different areas.
In regards to the survey
The report relies on the findings of an impartial, vendor-agnostic survey commissioned by Sophos of 5,000 IT/cybersecurity leaders throughout 14 nations within the Americas, EMEA, and Asia Pacific, together with 592 from the monetary companies sector. All respondents symbolize organizations with between 100 and 5,000 workers. The survey was carried out by analysis specialist Vanson Bourne between January and February 2024, and individuals have been requested to reply based mostly on their experiences over the earlier yr.