{"id":8063,"date":"2024-07-25T12:47:21","date_gmt":"2024-07-25T10:47:21","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=8063"},"modified":"2024-07-25T12:47:21","modified_gmt":"2024-07-25T10:47:21","slug":"the-state-of-ransomware-in-critical-infrastructure-2024","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/en-us\/2024\/07\/resources\/the-state-of-ransomware-in-critical-infrastructure-2024\/","title":{"rendered":"The State of Ransomware in Critical Infrastructure 2024"},"content":{"rendered":"<p>The latest annual Sophos study of the real-world ransomware experiences of energy, oil\/gas and utilities sector \u2013 a core element of the critical infrastructure supporting businesses \u2013 explores the full victim journey, from attack rate and root cause to operational impact and business outcomes.<\/p>\n<p>This year\u2019s report sheds light on new areas of study for the sector, including an exploration of ransom demands vs. ransom payments and how often energy, oil\/gas and utilities organizations receive support from law enforcement bodies to remediate the attack.<\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-critical-infrastructure\" target=\"_blank\" rel=\"noopener\">Download the report\u00a0<\/a>to get the full findings.<\/p>\n<h2>Attack rates and recovery rates have remained steady<\/h2>\n<p>67% of energy, oil\/gas and utilities organizations were hit by ransomware in 2024, identical to the attack rate reported in 2023.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956280 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/atttack-rate.png\" sizes=\"auto, (max-width: 685px) 100vw, 685px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/atttack-rate.png 685w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/atttack-rate.png?resize=300,102 300w\" alt=\"atttack rate\" width=\"685\" height=\"232\" \/><\/p>\n<p>98% of energy, oil\/gas and utilities organizations hit by ransomware in the past year said that the cybercriminals attempted to compromise their backups during the attack. Four in five (79%) of these backup compromise attempts were successful, the highest rate of successful backup compromise across all sectors.<\/p>\n<p>80% of ransomware attacks on energy, oil\/gas and utilities organizations resulted in data encryption in 2024, in line with the encryption rate reported by this sector in 2023 (79%) but higher than the 2024 cross-sector average of 70%.<\/p>\n<p>The mean cost in energy, oil\/gas and utilities organizations to recover from a ransomware attack was $3.12M in 2024, similar to the $3.17M reported in 2023.<\/p>\n<h2>Devices impacted in a ransomware attack<\/h2>\n<p>On average, 62% of computers in energy, oil\/gas and utilities are impacted by a ransomware attack, considerably above the cross-sector average of 49%. Unlike other sectors where only a small percentage of organizations have their full environments encrypted, approximately one in five energy, oil\/gas and utilities organizations (17%) reported that 91% or more of their devices were impacted.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956281 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/devices-impacted.png\" sizes=\"auto, (max-width: 881px) 100vw, 881px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/devices-impacted.png 881w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/devices-impacted.png?resize=300,146 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/devices-impacted.png?resize=768,374 768w\" alt=\"devices impacted\" width=\"881\" height=\"429\" \/><\/p>\n<h2>The propensity to use backups for data recovery has decreased<\/h2>\n<p>61% of energy, oil\/gas and utilities organizations paid the ransom to get encrypted data back, whereas only 51% restored encrypted data using backups \u2013 the lowest rate of backup use reported across all sectors. This is the first time that energy, oil\/gas and utilities organizations have reported a higher propensity to pay the ransom than use backups. In comparison, globally, 56% paid the ransom, and 68% used backups.<\/p>\n<p>This year\u2019s findings represent a marked change from the previous two years when the sector enjoyed impressive rates of backup use (70% in 2023 and 77% in 2022).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956282 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/data-recovery.png\" sizes=\"auto, (max-width: 522px) 100vw, 522px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/data-recovery.png 522w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/data-recovery.png?resize=300,216 300w\" alt=\"data recovery\" width=\"522\" height=\"375\" \/><\/p>\n<p>A notable change over the last year is the increase in the propensity for victims to use multiple approaches to recover encrypted data (e.g., paying the ransom and using backups). This time, 35% of energy, oil\/gas and utilities organizations that had data encrypted reported using more than one method, higher than the 26% reported in 2023.<\/p>\n<h2>Critical Infrastructure victims don\u2019t often pay the initial ransom sum demanded<\/h2>\n<p>86 energy, oil\/gas and utilities respondents whose organizations paid the ransom shared the actual sum paid, revealing that the average (median) payment was $2.5M in 2024.<\/p>\n<p>A little less than half (48%) of respondents said their payment matched the original request. 26% paid less than the original demand, and 27% paid more.<\/p>\n<p>Looking at the data by industry, energy, oil\/gas and utilities has the highest propensity to pay the original ransom amount demanded by attackers. It is also the sector with the second lowest propensity to pay less than the original demand.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956283 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/ransom-payment.png\" sizes=\"auto, (max-width: 536px) 100vw, 536px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/ransom-payment.png 536w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/07\/ransom-payment.png?resize=300,181 300w\" alt=\"ransom payment\" width=\"536\" height=\"323\" \/><\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-critical-infrastructure\">Download the full report<\/a>\u00a0for more insights into ransom payments and many other areas.<\/p>\n<p>&nbsp;<\/p>\n<h2>Generate demand for your business<\/h2>\n<p>Make the most of Sophos partner marketing resources to run a successful partner marketing campaign to educate your audiences and generate demand for your business. The ready-to-run campaign kit includes the pdf report, a complete PowerPoint deck, and co-brandable email templates.<\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/c\/the-state-of-ransomware-campaign\" target=\"_blank\" rel=\"noopener\">Access partner marketing campaign assets<\/a><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><strong>About the survey<\/strong><\/p>\n<p>The report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 5,000 IT\/cybersecurity leaders across 14 countries in the Americas, EMEA, and Asia Pacific, including 275 from the energy, oil\/gas and utilities sector, a core element of the critical infrastructure supporting businesses around the globe. All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and February 2024, and participants were asked to respond based on their experiences over the previous year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>275 IT\/cybersecurity leaders from the energy, oil\/gas and utilities sector share their ransomware experiences, providing new insights into the business impact of ransomware.<\/p>\n","protected":false},"author":59,"featured_media":8064,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[3],"tags":[12,125,21],"coauthors":[98],"class_list":["post-8063","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources","tag-campaigns","tag-ransomware","tag-threats-malware"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2024\/07\/featured-image-critical-infrastructure-shutterstock_2194316465.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8063","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/comments?post=8063"}],"version-history":[{"count":1,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8063\/revisions"}],"predecessor-version":[{"id":8065,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/posts\/8063\/revisions\/8065"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media\/8064"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/media?parent=8063"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/categories?post=8063"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/tags?post=8063"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=8063"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}