{"id":48327,"date":"2020-05-14T15:28:38","date_gmt":"2020-05-14T14:28:38","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/05\/14\/is-the-growth-of-cybersecurity-insurance-behind-the-recent-resurgence-in-ransomware\/"},"modified":"2020-05-20T13:41:49","modified_gmt":"2020-05-20T12:41:49","slug":"is-the-growth-of-cybersecurity-insurance-behind-the-recent-resurgence-in-ransomware","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/05\/14\/is-the-growth-of-cybersecurity-insurance-behind-the-recent-resurgence-in-ransomware\/","title":{"rendered":"Is the growth of cybersecurity insurance behind the recent resurgence in ransomware?"},"content":{"rendered":"\n<p><em>Unfortunately for business leaders, ransomware is an ever-growing security issue. Jan van Vliet, VP EMEA, Digital Guardian, considers whether an intended solution to cybercrime has inadvertently contributed to a large part of the ransomware problem.<\/em><\/p>\n\n\n\n<p>Ransomware has been an ever-present threat to businesses of all shapes and sizes for almost two decades. While it was originally conceived as a means to extort money from individuals, it wasn\u2019t long before cybercriminals realised it was just as effective \u2013 and far more profitable \u2013 to use against organisations as well. Within just a few years, ransomware like Reveton, CryptoLocker and more recently, Wannacry, was being used to bring businesses around the world to their knees, with victims ranging from corporate entities and local governments, to universities and medical centres. In short, no one was safe.&nbsp;<\/p>\n\n\n\n<p>As awareness of the threat grew, many organisations upped their cybersecurity game significantly and it wasn\u2019t long before additional investment in both technology and employee security training started to translate into a noticeable fall in ransomware attack volumes globally. For a while, it even seemed like ransomware was heading for the rubbish heap. However, a recent resurgence has propelled ransomware right back to the top of the cyberthreat list. The question is, what\u2019s behind it?<\/p>\n\n\n\n<p>As unlikely as it may sound, there\u2019s a growing body of evidence to suggest that the rise of the cybersecurity insurance industry may well have played a key role in ransomware\u2019s renaissance. In this article, we\u2019ll look at some of this evidence and evaluate whether something designed to be part of the solution to cybercrime has unintentionally become a large part of the problem.<\/p>\n\n\n\n<p><strong>Cybersecurity insurance \u2013 an unlikely villain?<\/strong><\/p>\n\n\n\n<p>Most cybercriminal operations are highly organised and extremely ambitious in their scope. Rather than simply encrypting victims\u2019 data and demanding money for its return like they used to, many have quickly learned that threatening to release it publicly is a great way to expedite a desired response. That\u2019s because in the age of the Internet, public exposure poses far greater risks to many victims, including potentially fatal reputational damage, as well as significant regulatory fines in some cases. For this reason, it\u2019s no surprise that cybersecurity insurance has exploded in recent years, as organisations scramble to protect themselves as best they can against such a potent threat.<\/p>\n\n\n\n<p>However, this rise in cybersecurity insurance has quickly created unexpected problems, primarily because so many victims are now finding it far quicker and easier to simply pay the ransom through their insurance rather than trying to deal with the fallout themselves.&nbsp;The more victims use insurers to pay ransoms this way, the more criminals are encouraged to keep carrying out attacks. It\u2019s created a vicious cycle that\u2019s proving to be both profitable and rewarding for hackers, while motivating more and more organisations to invest in insurance policies to cover themselves.<\/p>\n\n\n\n<p>What\u2019s more, many ransomware victims are paying off cybercriminals with the full agreement \u2013 and even encouragement &#8211; of their insurers, for whom paying the ransom is by far the cheapest option when compared to footing the bill for extensive data recovery. To put this into context, below are two recent examples of ransomware attacks that were handled very differently by the victims, leading to starkly contrasting outcomes.<\/p>\n\n\n\n<p>In 2019, Lake City in Florida fell victim to a ransomware attack that crippled its government systems. Rather than pursuing data recovery options, it chose to pay the ransom of around \u00a3350,000 via its insurance policy. The government itself was only liable for the \u00a37,500 policy excess, with insurance firm Beazley paying the balance under the terms of the policy. It was later discovered that the decision to pay was made on Beazley\u2019s own recommendation after analysis suggested the work needed to recover the stolen data from data backups would likely have run into millions of dollars.<\/p>\n\n\n\n<p>The pragmatism of such a decision is difficult to dispute in the face of the evidence. Not only was a significant amount of money saved in the long run, it allowed the government to get back to work much faster than would otherwise have been possible. Unfortunately, it also meant the perpetrators got away with both the crime itself and almost half a million dollars in ill-gotten gains.<\/p>\n\n\n\n<p>By contrast, when the city of Atlanta fell victim to a SamSam ransomware attack in 2018, it refused to pay the \u00a342,000 ransom demand and instead chose to recover the data at its own expense. While this decision left the criminals empty handed, it\u2019s estimated that the total cost to the city was an eye-watering \u00a36.8 million.<\/p>\n\n\n\n<p><strong>Criminals are getting bolder<\/strong><\/p>\n\n\n\n<p>As more and more organisations look to their insurance in the event of an attack, cybercriminals are also starting to demand ever-increasing payments. In the last 12 months alone, the average ransomware payment has risen six-fold to \u00a327,000. What\u2019s more, it appears that criminals are actively targeting organisations known to have cyber-insurance policies in place. The inevitable result is that insurance providers are steadily raising the cost of their premiums to cover the growth in claims \u2013 bringing us back to that vicious cycle again.<\/p>\n\n\n\n<p>Ultimately, prevention is better than cure and businesses need to start treating cybersecurity insurance as a line of last resort instead of a strategy in its own right. Instead, they should focus on investing in security technology and training that will prevent them from falling victim in the first place. Until that starts happening again, ransomware\u2019s renaissance looks set to continue for some time to come.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Unfortunately for business leaders, ransomware is an ever-growing security issue. Jan van Vliet, VP EMEA, Digital Guardian, considers whether an intended solution to cybercrime has inadvertently contributed to a large part of the ransomware problem. Ransomware has been an ever-present threat to businesses of all shapes and sizes for almost two decades. While it was [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":48330,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1741,5,6,4115,3629,13,79],"tags":[11752,1175,1043],"class_list":["post-48327","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-finance","category-enterprise-security","category-insights","category-intelligent-technology-newsletter","category-newsletter","category-top-stories","category-used","tag-cybersecurity-insurance","tag-digital-guardian","tag-ransomware"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/48327","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=48327"}],"version-history":[{"count":3,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/48327\/revisions"}],"predecessor-version":[{"id":48343,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/48327\/revisions\/48343"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/48330"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=48327"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=48327"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=48327"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}