# Ransomware Resurgence: Is your Organization Prepared?
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-07-30
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Ransomware Resurgence: VMware&#039;s Global Security
Meta Description: Discover the dramatic increase in ransomware campaigns, sophisticated tactics, and the rise of ransomware-as-a-service impacting organisations worldwide.
URL: https://financedigest.com/ransomware-resurgence-is-your-organization-preparedhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/dm032420161762-sbi-300935013-1736838093522-compressed.jpg)

_By **Rick McElroy,** Principal Cybersecurity Strategist, VMware_

Ransomware made mainstream news when cybercriminal group, DarkSide, launched an attack on U.S. fuel company Colonial Pipeline, which [carries nearly half the fuel](https://www.financedigest.com/u-s-sanctioned-oil-tanker-stuck-in-indonesia-carries-venezuelan-fuel.html "U.S.-sanctioned oil tanker stuck in Indonesia carries Venezuelan fuel") consumed along the U.S. East Coast. The disruption of [critical infrastructure and the impact on our daily lives was a sobering reminder of the havoc that a successful](https://www.financedigest.com/five-critical-tips-to-create-a-successful-start-up.html "Five Critical Tips To Create A Successful Start-up") cyberattack can wreak.

While its scale and impact grabbed headlines, this [attack is only symptomatic of a dramatic resurgence in ransomware](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") campaigns over the past year. Alongside an increase in the number of attacks, VMware found ransomware [groups are becoming](https://www.financedigest.com/scottys-little-soldiers-become-incentive-fm-groups-chosen-charity-in-three-year-partnership.html "Scotty’s Little Soldiers Become Incentive FM Group’s Chosen Charity In Three Year Partnership") even more organized and sophisticated, while the rise in ransomware-as-a-service is enabling a much broader cybercriminal base to execute attacks using existing tools.

Understandably, this adds to the pressure already felt by CISOs, who are defending a more distributed environment than ever before.

**Ransomware is a leading cause of [security breaches](https://www.financedigest.com/transport-operator-go-ahead-flags-cyber-security-breach.html "Transport operator Go-Ahead flags cyber security breach") worldwide**

VMware surveyed 3,542 CISOs across 14 countries for its recently published [Global Security Insights report](https://www.carbonblack.com/resources/global-security-insights-report-2021/) and found ransomware attacks were the dominant cause of breaches for organizations. The average [number of ransomware attacks organizations](https://www.financedigest.com/boosting-your-organic-post-numbers-with-sponsored-posts-on-facebook.html "Boosting Your Organic Post Numbers With Sponsored Posts on Facebook") experienced have doubled over the past year. Additionally, the VMware [Threat Analysis Unit identified a 900% increase in ransomware](https://www.financedigest.com/how-to-press-cancel-on-the-threat-of-subscription-style-ransomware-services.html "How to press cancel on the threat of subscription-style ransomware services") over the first half of 2020.

Malicious actors have spent the pandemic capitalizing on the [rapid adoption of an anywhere workforce and the use of personal devices](https://www.financedigest.com/rapid-action-force-regarding-innovations-to-drive-the-medical-devices-market.html "Rapid Action Force regarding Innovations to drive the Medical Devices Market") and networks by remote workers.  Attackers now have an unprecedented opportunity to [launch social engineering](https://www.financedigest.com/mercedes-benz-launches-e-class-its-last-new-combustion-engine-model.html "Mercedes-Benz launches E-Class, its last new combustion engine model") attacks, such as phishing, on unsuspecting employees.

No [industry was off limits to attackers](https://www.financedigest.com/finance-industry-and-ddos-attacks-how-can-the-most-targeted-vertical-industry-protect-itself-from-ddos-attacks.html "Finance industry and DDoS attacks: how can the most targeted vertical industry protect itself from DDoS attacks?"), either. The [healthcare sector](https://www.financedigest.com/are-the-us-healthcare-sectors-frailties-treatable.html "Are the US healthcare sector’s frailties treatable?") – already in the grip of pandemic response – was disproportionately targeted with ransomware in 2020. One in five breaches [reported by the healthcare](https://www.financedigest.com/global-animal-healthcare-market-report.html "Global Animal Healthcare Market Report") CISOs we surveyed were caused by ransomware. In the same way that DarkSide targeted [critical national infrastructure](https://www.financedigest.com/hiding-in-plain-sight-finance-as-critical-national-infrastructure.html "Hiding in plain sight – Finance as Critical National Infrastructure"), ransomware groups have looked to cash in on the healthcare sector, an industry more likely to pay due to their critical nature of their business.

**[Double extortion tactics](https://www.financedigest.com/double-and-triple-extortion-tactics-cornering-financial-services-organisations.html "Double and triple extortion tactics cornering financial services organisations ") pile pressure on victims**

New tactics are making ransomware a much more nuanced threat, too. Instead of locking up systems immediately, attackers are aiming to infiltrate systems undetected and establish persistence on the target network, moving laterally and [extracting data](https://www.financedigest.com/from-sec-edgar-to-business-applications-exploring-an-alternative-to-manual-data-extraction.html "From SEC EDGAR to Business Applications: Exploring an Alternative to Manual Data Extraction") that can be monetized even if no ransom is ultimately paid. A system encryption and ransom demand will not be made until the perpetrator has covered their tracks and [established a route back](https://www.financedigest.com/2016-the-fight-back-of-the-established-brand.html "2016 – THE FIGHT BACK OF THE ESTABLISHED BRAND") into the target network.

This gives cybercriminals greater hold over victims. As well as needing to decrypt their systems, organizations also [face the possibility that critical assets](https://www.financedigest.com/analysis-investors-face-expensive-quest-for-year-end-cash-and-safe-assets.html "Analysis-Investors face expensive quest for year-end cash and safe assets") such as customer data or trade secrets will be released for sale to the dark web and the breach will be made public. The reputational and [regulatory risk](https://www.financedigest.com/is-regtechs-rise-one-way-tackle-the-international-regulatory-game-of-risk.html "Is Regtech’s rise one way tackle the international regulatory game of Risk?") tied to ransomware means the pressure to pay ransoms is often significant. However, unless the attacker’s presence in an organization’s network is fully removed, they are likely to return for another [strike on a target that has shown willingness to pay](https://www.financedigest.com/in-inflation-hit-germany-massive-strike-over-pay-to-cripple-transport.html "In inflation-hit Germany, massive strike over pay to cripple transport").

The cybercriminal community has capitalized on the growing profitability of this approach, with [nearly 40%](https://www.carbonblack.com/blog/2021-cybersecurity-outlook-attackers-vs-defenders/) of security professionals saying double-extortion ransomware was the most observed new ransomware attack technique in 2020.

**Strengthening defenses against ransomware**

As businesses [adapt to supporting the anywhere workforce and malicious actors continue](https://www.financedigest.com/scholz-if-germany-continues-to-adapt-we-will-make-it-through-winter.html "Scholz: if Germany continues to adapt, we will make it through winter") to target the expanded threat landscape, CISOs have a once-in-a-generation opportunity to strengthen defenses against ransomware and protect their organization by:

_Delivering security as a distributed service:_ To protect the anywhere workforce, regardless of the devices and networks workers are using, deliver endpoint and [network controls as a distributed service that follows the assets being protected](https://www.financedigest.com/emergency-call-services-telcos-urge-eu-to-protect-telecoms-networks-from-power-cuts.html "Emergency call services, telcos urge EU to protect telecoms networks from power cuts") throughout the environment.

_Prioritizing visibility:_ Better visibility over endpoints and workloads [delivers contextual insight](https://www.financedigest.com/research-delivers-insight-into-the-global-polymer-surfactants-market-during-the-period-2021-2029.html "Research Delivers Insight Into The Global Polymer Surfactants Market During The Period 2021-2029") and situational intelligence to help defenders prioritize and remediate risk with confidence.

_Conducting regular threat hunting:_ The first [step of a multistage ransomware campaign is gaining undetected access to networks](https://www.financedigest.com/single-broadband-network-is-right-step-for-italy-vivendi-says.html "Single broadband network is ‘right step’ for Italy, Vivendi says"). Regular threat hunting can detect silent incursions and the presence of adversaries in the environment by spotting anomalous behavior.

_Keeping monitoring “quiet” to_ [avoid counter-incident response: Assume the adversary has multiple means of gaining access](https://www.financedigest.com/auditors-could-have-unfettered-access-to-internal-business-processes-to-avoid-another-carillion.html "Auditors could have unfettered access to internal business processes to avoid another Carillion") to the environment. Watch and wait before taking action – don’t start [blocking malware or terminating](https://www.financedigest.com/climate-activists-plan-daily-protests-after-blocking-10-uk-oil-terminals.html "Climate activists plan daily protests after blocking 10 UK oil terminals") C2 systems until you are sure you understand all possible avenues of re-entry.

_Engaging with an incident response partner:_ It is not a matter of if, but when organizations will be targeted, so it is essential to be prepared. Engage with an IR partner to devise a response plan and retain them to put it into [action when needed](https://www.financedigest.com/new-uk-pm-will-need-to-take-urgent-action-on-energy-bills-ofgem-ceo.html "New UK PM will need to take urgent action on energy bills – Ofgem CEO"). This should include post-incident remediation and analysis to root out any remaining adversary presence and avoid repeat attacks.

As organizations rethink their approach to security, defending against ransomware should be a [top priority](https://www.financedigest.com/survey-finds-regulation-remains-top-financial-services-priority-for-2017.html "Survey finds Regulation Remains Top Financial Services Priority for 2017") as the impact and scope of attacks increases. The anywhere workforce must be [supported by a security strategy that surrounds and protects](https://www.financedigest.com/supporting-a-fair-and-resilient-society-by-protecting-access-to-cash.html "Supporting a fair and resilient society by protecting access to cash ") employees to let them work safely and productively without putting the infrastructure, reputation, and competitive position of the business at risk.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

