Mitiga Appoints Charlie Thomas as CEO READ THE RELEASE

Mitiga Announces $30M Series B Led by SYN Ventures READ THE NEWS

It is hard to overstate the level of havoc generated on global enterprises by year-over-year increases in ransomware attacks. Verizon Data Breach Investigations Report provides one state-of-the-world snapshot noting that the 13% increase in reported ransomware instances last year was greater than those measured across the preceding 5 years combined. It’s not surprising that ransomware readiness has moved up the list of most CISOs crowded priority sheets. And it needs to. 

The fallout of hit-and-miss IR planning for ransomware attacks

Having an up-to-date incident response plan is a good foundational step for enhancing your organizational readiness for cyber incidents. However, when it comes to ransomware, the standard 48-hours-or-less response window associated with many double extortion ransomware attacks can create a real-world cybersecurity crisis for even those organizations with well-established IR plans. 

It’s important to note that not all IR planning is cerated equal. For example. organizational IR plans prepared by a third-party in order to demonstrate industry-standard compliance to auditors can largely be discounted here. Generally, these IR plans were not developed with the up-to-the-moment threat landscape in mind, nor are they purpose-built for the nuances of a ransomware attack.

Even with comprehensive incident response planning, lack of advanced readiness for a ransomware attack places in-house IR (incident response) teams and general-purpose IR vendors in a reactive, catch-up mode. All the while, the 48-hour clock rapidly ticks away.

Research conducted by Hitachi and Enterprise Strategy Group (source: "The Long Road Ahead to Ransomware Preparedness," March 2022) indicates that 79% of organizational respondents had been financially or operationally impacted by ransomware attacks in the last year. 56% of those hit by ransomware paid their ransom, just 1-in-7 reacquired their unencrypted data. 

Rethinking your ransomware readiness approach

Beyond the recent rise of double extortion ransomware attack instances, an evolving triple extortion model involves adding greater scale for cybercriminals by also extending the threat to the end-customers of the targeted company. In response, industry discussion of a ransomware preparedness model has emerged. For modern enterprises, effective ransomware readiness planning must involve:  

  • Up-front, automated, rapid collection of cloud, SaaS, IaaS, and PaaS log data, stored for longer-period timeframes than those stored by the providers themselves.
  • An investigation and crisis management platform that then enables cross-organizational executive and technical teams to continuously visualize their level of cyberattack preparedness – including ransomware. That same console should be equipped to analyze emerging threats, differentiate exposure levels based on analysis of the extended forensic data baseline, provide guidance on how best to quickly remediate and provide recommended-practices on organizational communications when a breach occurs – including internal business functions, impacted customers, business partners, and, as necessary, regulators.
  • Ongoing organizational ransomware readiness activities, including executive-level drills and tabletop exercises that review organizational processes and procedures to identify gaps and dependencies in incident response planning.

Taking the next steps toward ransomware readiness

Minimizing future risks associated with ransomware requires a strategic and proactive approach and the development of new organizational skillsets and technology to support appropriate action. Only then can security teams reach the response velocity that ransomware response timelines require.  

Learn how ransomware readiness can protect your enterprise against the most dangerous cyberthreats by downloading our eBook. 

LAST UPDATED:

January 23, 2025

Don't miss these stories:

Hunting Conditional Access Policy Bypass in the Wild: Leveraging Malicious Browser Extensions for Seamless Initial Access

Mitiga’s threat detection and investigation experts conduct a threat hunt showing how attackers can bypass credential collection techniques to gain access to further information.

Is Your CDR Vision Cloudy? Why Complete, Panoramic Visibility Across SaaS, Identity, and Infrastructure is a Must

Security teams need to recognize the shortcomings of traditional cloud security approaches and learn why agentless panoramic visibility is a must for effective CDR.

Understanding the Sisense Breach: A Guide to Cloud Threat Hunting for Sisense Customers

On April 11, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) announced its collaboration with private industry partners to address a significant security breach affecting Sisense, a prominent provider of data analytics services. This compromise, unearthed by independent security researchers, raised alarms within the cybersecurity community, prompting swift action from both government agencies and affected organizations.

The Rising Threat of AI-Enabled Adversaries: Preparing for the Next Wave of Cloud and SaaS Attacks

Learn how adversaries weaponize AI technology and strategies to defend against AI-enabled threats.

Cyber Trends for 2024: What Security Leaders Should be Executing Next

As we hurtle into this new year, it’s already clear that there is an evolving set of cyber risks that organizations will need to contend with successfully to manage threats and grow their organizational resilience in 2024. Below, I’ll outline three of the biggest ones, sharing recommendations and execution checklists that can help enterprises enhance their threat readiness and elevate security postures as the threat landscape continues to evolve.

Stop Ransomware Attackers From Getting Paid to Play Double-Extortionware Games

In the past, many companies relied on backups to get back to business quickly if they were attacked. Reliable, secure backups separated from the primary environment made it much more difficult for an attacker to access and encrypt them. That long-standing process no longer deters double-extortionware actors — instead, today’s attackers not only encrypt the data but also exfiltrate it.