{"id":8047,"date":"2024-07-11T15:28:24","date_gmt":"2024-07-11T13:28:24","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=8047"},"modified":"2024-07-23T16:15:00","modified_gmt":"2024-07-23T14:15:00","slug":"the-state-of-ransomware-in-education-2024","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/en-us\/2024\/07\/resources\/the-state-of-ransomware-in-education-2024\/","title":{"rendered":"The State of Ransomware in Education 2024"},"content":{"rendered":"<p>Sophos\u2019 latest annual study of the real-world ransomware experiences of educational organizations explores how ransomware\u2019s impact has evolved in the last four years. It focuses on the full victim journey, from attack rate and root cause to operational impact and business outcomes.<\/p>\n<p>This year\u2019s report explores new areas of study for the sector, including an exploration of ransom demands vs. ransom payments and how often educational organizations receive support from law enforcement bodies to remediate the attack.<\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-education\">Download the report<\/a>\u00a0to get the full findings.<\/p>\n<h2>Attack rates have declined, but recovery costs have more than doubled<\/h2>\n<p>63% of lower education and 66% of higher education organizations were hit by ransomware in the last year, a considerable decrease from the 80% and 79% reported in 2023, respectively. However, the attack rates in education remain higher than the global cross-sector average of 59%.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956203 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1_e81e95.png\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1_e81e95.png 726w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image1_e81e95.png?resize=300,148 300w\" alt=\"The State of Ransomware in Education 2024\" width=\"726\" height=\"359\" \/><\/p>\n<p>95% of educational organizations hit by ransomware in the past year said that the cybercriminals attempted to compromise their backups during the attack. Of them, 71% were successful, which is the second highest rate of successful backup compromise across all sectors after the\u00a0<em>energy, oil\/gas and utilities<\/em>\u00a0sector.<\/p>\n<p>85% of ransomware attacks on lower education and 77% on higher education organizations resulted in data encryption in the last year, slightly higher than 81% and 73%, respectively, reported in the previous year. For lower education, this is the second consecutive year of an increase in encryption rate, with only\u00a0<em>state\/local government<\/em>\u00a0(98%) more likely to have data encrypted in an attack.<\/p>\n<p>The mean cost in 2024 for lower education organizations to recover from a ransomware attack was $3.76M, more than double the $1.59M reported in 2023. Higher education organizations reported a mean cost of $4.02M, almost four times higher than the $1.06M reported in 2023.<\/p>\n<h2>Devices impacted in a ransomware attack<\/h2>\n<p>On average, 52% of computers in lower education and 50% in higher education are impacted by a ransomware attack, slightly above the cross-sector average of 49%. Having a full environment encrypted is extremely rare. Only 2% of lower education organizations and 1% of higher education organizations reported that 91% or more of their devices were impacted.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956204 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2_cb5442.png\" sizes=\"auto, (max-width: 816px) 100vw, 816px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2_cb5442.png 816w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2_cb5442.png?resize=300,148 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image2_cb5442.png?resize=768,378 768w\" alt=\"The State of Ransomware in Education 2024\" width=\"816\" height=\"402\" \/><\/p>\n<h2>The propensity to pay the ransom has increased<\/h2>\n<p>62% in lower education paid the ransom to get encrypted data back, while 75% restored encrypted data using backups. At the same time, 67% of higher education organizations paid the ransom to restore data, whereas 78% used backups.<\/p>\n<p>Higher education reported the second-highest propensity to use backups for data restoration along with\u00a0<em>state\/local government<\/em>\u00a0organizations. It also ranks second highest in the propensity to pay the ransom to restore encrypted data, whereas lower education organizations rank third.<\/p>\n<p>The three-year view of the education sector reveals an increase in backup use. In 2023, higher education was among the bottom three sectors globally for backup use, jumping to second place in 2024, alongside\u00a0<em>state\/local government<\/em>. Unfortunately, the propensity to pay the ransom has progressively increased for both lower and higher education organizations in the last three years.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956205 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3_3b7242.png\" sizes=\"auto, (max-width: 889px) 100vw, 889px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3_3b7242.png 889w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3_3b7242.png?resize=300,134 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image3_3b7242.png?resize=768,343 768w\" alt=\"The State of Ransomware in Education 2024\" width=\"889\" height=\"397\" \/><\/p>\n<p>A notable change over the last year is the increase in the propensity for victims to use multiple approaches to recover encrypted data (e.g., paying the ransom and using backups). This time, 65% of lower education and 69% of higher education organizations that had data encrypted reported using more than one method, almost three times the rates reported in 2023 (23% in lower education and 22% in higher education organizations.)<\/p>\n<h2>Victims rarely pay the initial ransom sum demanded<\/h2>\n<p>99 lower education and 92 higher education respondents whose organizations paid the ransom shared the actual sum paid, revealing that the average (median) payment in lower education was $6.6M last year. For higher education, the average (median) payment was $4.4M.<\/p>\n<p>Only 13% of education victims said their payment matched the original request. 32% of lower education and 20% of higher education respondents paid less than the original demand, while 55% of lower education and 67% of higher education organizations paid more. Globally, higher education is the sector most likely to pay more than the original demand.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956206 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4_dbd1c0.png\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4_dbd1c0.png 912w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4_dbd1c0.png?resize=300,117 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/image4_dbd1c0.png?resize=768,299 768w\" alt=\"The State of Ransomware in Education 2024\" width=\"912\" height=\"355\" \/><\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-education\">Download the full report<\/a>\u00a0for more insights into ransom payments and many other areas.<\/p>\n<h2>Generate demand for your business<\/h2>\n<p>Make the most of Sophos partner marketing resources to run a successful partner marketing campaign to educate your audiences and generate demand for your business. The ready-to-run campaign kit includes the pdf report, a complete PowerPoint deck, and co-brandable email templates.<\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/c\/the-state-of-ransomware-campaign\" target=\"_blank\" rel=\"noopener\">Access partner marketing campaign assets<\/a><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><strong>About the survey<\/strong><\/p>\n<p>The report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 5,000 IT\/cybersecurity leaders across 14 countries in the Americas, EMEA, and Asia Pacific. 600 respondents were from educational organizations, split into 300 from lower education (catering to students up to 18 years) and 300 from higher education (for students over 18 years). All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and February 2024, and participants were asked to respond based on their experiences over the previous year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>600 IT\/cybersecurity leaders share their ransomware experiences, revealing the realities facing education providers today.<\/p>\n","protected":false},"author":59,"featured_media":8048,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[12,125,21],"coauthors":[98],"class_list":["post-8047","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources","tag-campaigns","tag-ransomware","tag-threats-malware"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2024\/07\/featured-image-sophos-state-of-ransomware-2024-education.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/comments?post=8047"}],"version-history":[{"count":1,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8047\/revisions"}],"predecessor-version":[{"id":8049,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8047\/revisions\/8049"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media\/8048"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media?parent=8047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/categories?post=8047"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/tags?post=8047"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=8047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}