{"id":7854,"date":"2024-05-29T13:13:02","date_gmt":"2024-05-29T11:13:02","guid":{"rendered":"https:\/\/partnernews.sophos.com\/en-us\/?p=7854"},"modified":"2024-06-04T09:09:08","modified_gmt":"2024-06-04T09:09:08","slug":"the-state-of-ransomware-in-manufacturing-and-production-2024","status":"publish","type":"post","link":"https:\/\/partnernews.sophos.com\/es-es\/2024\/05\/resources\/the-state-of-ransomware-in-manufacturing-and-production-2024\/","title":{"rendered":"The State of Ransomware in Manufacturing and Production 2024"},"content":{"rendered":"<p>The latest Sophos annual study of the real-world ransomware experiences of manufacturing and production organizations explores the full victim journey, from attack rate and root cause to operational impact and business outcomes.<\/p>\n<p>This year\u2019s report incorporates new areas of study for the sector, including an exploration of ransom demands vs. ransom payments. Plus, for the first time, it shines a light on the role of law enforcement in ransomware remediation.<\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=87855&amp;renderMode=Collection\">Download the report<\/a> from the Sophos Partner Portal to get the full findings.<\/p>\n<h2>Attack rates and recovery costs have both gone up<\/h2>\n<p>65% of manufacturing and production organizations reported they were hit by ransomware last year. This is a notable increase from the previous two years (56% in 2023 and 55% in 2022) and represents a 41% increase since 2020.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransomware-rate.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-955473 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransomware-rate.png\" sizes=\"auto, (max-width: 718px) 100vw, 718px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransomware-rate.png 718w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransomware-rate.png?resize=300,109 300w\" alt=\"\" width=\"718\" height=\"261\" \/><\/a><\/p>\n<p>93% of manufacturing organizations hit by ransomware in the past year said that the cybercriminals attempted to compromise their backups during the attack. Of them, 53% of backup compromise attempts were successful.<\/p>\n<p>Additionally, three out of four ransomware attacks on manufacturing organizations (74%) resulted in data encryption, the highest encryption rate for the sector in the last five years. This rate is also higher than the 2024 cross-sector average of 70%.<\/p>\n<p>In 2024, manufacturing organizations reported a mean cost of $1.67M to recover from a ransomware attack, an increase from the $1.08M reported in 2023.<\/p>\n<h2>Devices impacted in a ransomware attack<\/h2>\n<p>On average, 44% of computers in manufacturing and production are impacted by a ransomware attack. Having your full environment encrypted is extremely rare, with only 4% of organizations reporting that 91% or more of their devices were impacted.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/devices-impacted.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-955475 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/devices-impacted.png\" sizes=\"auto, (max-width: 910px) 100vw, 910px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/devices-impacted.png 910w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/devices-impacted.png?resize=300,151 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/devices-impacted.png?resize=768,387 768w\" alt=\"\" width=\"910\" height=\"459\" \/><\/a><\/p>\n<h2>Six in ten victims now pay the ransom<\/h2>\n<p>While 58% in manufacturing restored encrypted data using backups, 62% paid the ransom to get data back. The percentage of manufacturing organizations that paid the ransom has almost doubled from our 2023 study when the sector reported one of the lowest ransom payment rates (34%) across all sectors.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/data-recovery.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-955476 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/data-recovery.png\" sizes=\"auto, (max-width: 546px) 100vw, 546px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/data-recovery.png 546w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/data-recovery.png?resize=300,274 300w\" alt=\"\" width=\"546\" height=\"499\" \/><\/a><\/p>\n<p>A notable change over the last year is the increase in the propensity for victims to use multiple approaches to recover encrypted data (e.g., paying the ransom and using backups). This time around, almost half of manufacturing organizations (45%) that had data encrypted reported using more than one method, more than double the rate reported in 2023 (19%).<\/p>\n<h2>Ransom payments have soared \u2013 but victims rarely pay the sum demanded<\/h2>\n<p>157 manufacturing respondents whose organizations paid the ransom shared the actual sum paid, revealing that the average (median) payment has increased by 167% over the last year, from $450,000 to $1.2M.<\/p>\n<p>While the ransom payment has increased, only 27% of manufacturing victims said that their payment matched the original request. 65% paid less than the original demand, while only 8% paid more.<\/p>\n<p><a href=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransom-payment-pie-chart.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-955474 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransom-payment-pie-chart.png\" sizes=\"auto, (max-width: 548px) 100vw, 548px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransom-payment-pie-chart.png 548w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/05\/ransom-payment-pie-chart.png?resize=300,190 300w\" alt=\"\" width=\"548\" height=\"347\" \/><\/a><\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/s\/assets?collectionId=87855&amp;renderMode=Collection\">Download the full report<\/a> from the Sophos Partner Portal for more insights into ransom payments and many other areas.<\/p>\n<h2>Generate demand for your business<\/h2>\n<p>Make the most of Sophos partner marketing resources to run a successful partner marketing campaign to educate your audiences and generate demand for your business. The ready-to-run campaign kit includes the pdf report, a complete PowerPoint deck, and co-brandable email templates.<\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/c\/the-state-of-ransomware-campaign\" target=\"_blank\" rel=\"noopener\">Access partner marketing campaign assets<\/a><\/p>\n<h2>About the survey<\/h2>\n<p>The report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 5,000 IT\/cybersecurity leaders across 14 countries in the Americas, EMEA, and Asia Pacific, including 585 from the manufacturing and production sector. All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and February 2024, and participants were asked to respond based on their experiences over the previous year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>585 IT\/cybersecurity leaders working in manufacturing and production share their experiences, revealing new insights and five-year trends.<\/p>\n","protected":false},"author":59,"featured_media":3000007855,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[75],"tags":[201,139,109],"coauthors":[188],"class_list":["post-7854","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources","tag-campaigns","tag-ransomware","tag-threats-malware"],"jetpack_featured_media_url":"https:\/\/partnernews.sophos.com\/en-us\/wp-content\/uploads\/sites\/3\/2024\/05\/featured-image-sophos-state-of-ransomware-2024-manufacturing.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/7854","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/comments?post=7854"}],"version-history":[{"count":1,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/7854\/revisions"}],"predecessor-version":[{"id":7876,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/posts\/7854\/revisions\/7876"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/media?parent=7854"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/categories?post=7854"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/tags?post=7854"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/partnernews.sophos.com\/es-es\/wp-json\/wp\/v2\/coauthors?post=7854"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}