https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures


ransomware detected

The High Cost of Ransomware

  • Written by Edward Gately
  • February 24, 2022

Companies are spending an average of $6 million annually on ransomware mitigation resources.

That’s according to CBI‘s new research report, “The Cost and Consequences of Ransomware.” Ponemon Institute conducted the research.

Eighty percent of companies surveyed have experienced a ransomware attack, despite spending millions on ransomware mitigation resources.

According to the research, the average IT security budget for 2022 is about $24.4 million. Of that, 25% is expected to be spent on preventing, detecting, containing and resolving ransomware attacks.

Only 32% are confident in their security controls, indicating the need to use more effective approaches to prevent ransomware attacks.

Shaun Bertrand is CBI’s chief services officer.

“It’s hard to remain confident when we see the success that ransomware threat actors continue to have,” he said. “Every day there is another organization that has made headlines for being compromised with ransomware. In addition, organizations are still challenged in many areas like risk visibility, phishing attacks and their ever-changing topology. Despite the investment in ransomware protections, organizations still face a grueling uphill battle.”

The report uncovered other significant takeaways relating to organizations’ approaches to and experiences with ransomware incidents:

  • Seventy-five percent are concerned about the ransomware risks posed by third parties, but only 36% of organizations evaluate their third parties’ security and privacy practices.
  • The average ransomware payment is approximately $1 million.

The report found that companies are spending $170,000 per ransomware incident on staffing alone, with an average of 14 staff members each spending 190 hours on containment and remediation activities. The report also uncovered a significant lack of trust in the ransomware alerts respondents receive as nearly one out of two weekly alerts are considered unreliable.

Fifty-three percent of companies who experienced an attack paid the ransom. The most common reason given was to avoid operational downtime. Of those that didn’t pay, 39% said they had an effective backup strategy. However, 55% of organizations felt that full and accurate data backups are not enough to properly mitigate a ransomware incident, likely because, in 41% of cases, sensitive data was also exfiltrated during the attack.

“There are two things organizations can do more effectively to protect themselves,” Bertrand said. “The first is to understand that ransomware attacks are evolving. From data leakage to denial of service (DoS), the adversaries are changing their approach. Organizations can stay ahead of the curve by better understanding the anatomy of these changes, and establishing effective controls and countermeasures. The second thing organizations can be do better is to not try to boil the ocean when it comes to preventing and detecting attacks. There are hundreds, probably thousands of techniques, tactics and procedures (TTPs) that malicious adversaries can leverage. Instead of trying to protect against every single technique an adversary may use, organizations should conduct threat modeling exercises to narrow down the most probable TTPs and focus detection and prevention resources on those more viable attacks.” 

Tags:

Edward Gately

Edward Gately

As news editor, Edward Gately covers cybersecurity, new channel programs and program changes, M&A and other IT channel trends. Prior to Informa, he spent 26 years as a newspaper journalist in Texas, Louisiana and Arizona.

Related Content

  • Ukraine cyberattack
    Microsoft Helping Ukraine Government Against Mounting Russia Cyberattacks
  • Microsoft 365
    Microsoft 365 Price Increases Now in Effect After Last-Minute Rush
  • Call Center Contact Center
    GoTo Unveils First New Product Since Rebrand from LogMeIn
  • cx
    Has the Channel Forgotten About the Customer?

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Enterprise Connect: RingCentral, LiveVox, Google Cloud, More Intro Latest AI, CX Innovations

March 27, 2023

The Gately Report: Live Patching Beneficial Tool for MSSPs, CISA Launches Early Ransomware Notification

March 27, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

Channel Conflict, Controversy: @Avaya #bankruptcy, massive #layoffs, @RobRae exits @KaseyaCorp, latest @TMobile hac… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

At #EnterpriseConnect, @googlecloud and @RingCentral are among companies releasing dramatic new #AI solutions for t… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

#CPExpo preview: @EntaraCorp's journey from MSP to XSP. #cybersecurity dlvr.it/SlZblp https://t.co/NjFRMW5Psp

March 27, 2023
ChannelFutures

.@dish facing class-action lawsuits stemming from recent #ransomware attack. dlvr.it/SlZFXk https://t.co/WrDozjZRR1

March 27, 2023
ChannelFutures

.@Microsoft, @Zoom gain, @Cisco declines in 2022 #UCC market. dlvr.it/SlZ6wR https://t.co/1OhlDpb6dL

March 27, 2023
ChannelFutures

IT industry mourns death of @intel co-founder Gordon Moore #MooresLaw dlvr.it/SlYs9K https://t.co/0ZXwcF3hEP

March 27, 2023
ChannelFutures

We asked women in the communications & IT channel to relate the most surprising thing said/done to them at work. Th… twitter.com/i/web/status/1…

March 27, 2023
ChannelFutures

Channel people making waves include: @jmcbain, @NetworkMoe, @ajassy, @JulieSweet, @Elvia_Valdes_M, @GovITDave… twitter.com/i/web/status/1…

March 24, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X