Sophos has released the results of their annual “State of Endpoint Security Today”, and it doesn’t paint a pretty picture. A full 54% of companies surveyed reported having been hit by a ransomware attack in 2017. Another 31% reported that they expect to be on the receiving end of such an attack in the near future.
If the headline statistic wasn’t bad enough, it only gets worse from there. According to the data collected, the average cost of a ransomware attack (including network costs, manpower, downtime, and device replacement cost) was $133,000. Five percent of respondents reported total costs between $1.3 million and $6 million, before factoring in the cost of any ransom paid.
As bad as those figures are, what makes them even more painful is the frequency. On average, survey respondents report having been struck an average of twice in the past year.
Dan Schiappa, the Senior VP and General Manage of Products at Sophos explains: “Ransomware is not a lightning strike – it can happen again and again to the same organization. We’re aware of cyber criminals unleashing four different ransomware families in half-hour increments to ensure at least one evades security and completes the attack.
If IT managers are unable to thoroughly clean ransomware and other threats from their systems after attacks, they could be vulnerable to reinfection. No one can afford to be complacent. Cybercriminals are deploying multiple attack methods to succeed, whether using a mix of ransomware in a single campaign, taking advantage of a remote access opportunity, infecting a server, or disabling security software.”
In light of this relentless attack methodology, and in spite of the headlines all last year warning of the dangers, Schiappa warns that most companies are starting 2018 woefully unprepared for a ransomware attack. With all that said if you haven’t done so already, it’s well past time to review the state of your network security.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Security researchers from around the web are reporting finding an increasing number of instances of proof of concept (PoC) code that incorporates the recently discovered Spectre and Meltdown vulnerabilities.
Oracle is currently the third-largest provider of POS (Point of Sale) software on the market today, which means that there’s a fairly good chance you’re using an Oracle POS system. If you are, there’s trouble ahead. A recently discovered security flaw could put your system at risk.
Google recently released their Play Store stats for 2017. The results are both encouraging and disheartening. Overall, Google caught and removed more than 700,000 malicious apps from the Play Store, minimizing their impact on the company’s massive Android user base.
Recently, Apple found itself in hot water with its normally adoring user base. This happened when it became known that the company was intentionally throttling (slowing down) the speed of older iPhones.
Recently a critical flaw was found inside every Intel chip made during the last decade. The flaw makes two different exploits possible. These exploits have been dubbed “Meltdown” and “Spectre.”
All companies collect data on their customers, but some are better than others when it comes to being upfront about what kinds of data are collected. Over the past year, Microsoft has made many moves that have been well-received by their enormous user base. They’ve become increasingly transparent and offer an unprecedented level of control to the users themselves.
Do you play Blizzard online computer games such as World of Warcraft, Diablo III, Hearthstone, Starcraft II, or Overwatch? If so, there’s a potential problem you need to be aware of.
By now, we’ve seen enough large-scale Point of Sale (POS) credit card thefts that patterns are beginning to emerge. Some companies follow the general arc of the narrative better than others and deserve credit for doing so, but in the end, the story is about the same.
It’s official, the first macOS malware of 2018 is here. Discovered by an independent security researcher and dubbed “OSX/MaMi,” the code is functionally similar to DNSChanger malware.