Hacking groups with increasing scale and sophistication challenge every sized enterprise to defend themselves
There are only two types of enterprises it seems. Enterprises who have paid cyber extortionists to recover data, and those that have not yet paid.
The outlook is bad and getting worse
According to IBM Security’s report on Ransomware (pdf – sign in required):
“Almost one in two executives (46 percent) has some experience with ransomware attacks in the workplace, and 70 percent of that 46 percent have paid to get data back.”
IBM attributed the entry point for most ransomware attacks to phishing emails. Ransomware encrypts the victim’s data with a key held for ransom by the perpetrator. The rate of ransomware as a percent of all malware spiked since February to over 40 percent as cyber criminals have adapted to this new malware monetization scheme as defenses have become hardened against old exploits such as botnets and bank and identity credential theft.
A study by Friedrich-Alexander University found more than half of computer users will click on any email or social media link even though three-fourths of them understood the risk. No wonder 46 percent of the executives have experience with malware. And, no wonder that bad actors target users with social media and email messages that have phishing exploit links and attachments.
+ Also on Network World: The year ransomware became one of the top threats to enterprises +
If a cyber extortionist can penetrate a business and encrypt company data, 70 percent of companies will pay the ransom, with over half paying $10,000 or more—and 20 percent paid more than $40,000. The price set for recovery seems set intentionally low to make the decision to pay easy instead of attempting decryption or data recovery.
According to Reuters, during the first quarter of 2016, the FBI reported that cyber extortion reached $209 million up $24 million year over year. Sometimes after paying, the cyber extortionists do not provide the key to decrypt and restore the data.
Sophisticated cyber criminals and lax defenses explain the steep rise in ransomware
IBM’s report explains a complex exploit using malware that starts with the execution of malware on an endpoint from an attachment. The attachment gets access and scans the network for data files and backups and then encrypts them. But successful cyber extortion may not require wasting a zero-day exploit and informing virus scan and endpoint security companies that will distribute the malware’s signature to block its future use, thwarting access to harder more lucrative targets.
Rob Joyce, head of the NSA’s elite hacking unit, the Tailored Access Unit (TAO), gave a speech at the Usenix Enigma conference in which he said:
“A lot of people think that nation-states are running on zero-days. But there are so many more vectors that are easier, less risky than going down that route.”
It implies that the sophisticated exploits described by IBM to inject ransomware or exfiltrate data may not be necessary. Joyce’s entire speech is recorded and publically available on YouTube.
Cyber criminals have gained scale while they innovated
Less understood is that ransomware is an organized crime with scale. In the same report, Reuters said:
“Some players in the booming underworld employ graphic artists, call centers and technical support to streamline payment and data recovery.”
Scale matters. Though Yahoo is an exception, platform companies such as Amazon, Google and Microsoft are rarely successful targets because they have enormous security budgets, sophisticated tooling and large security staffs that not only defend but research possible future attacks. The list of large enterprises in the tier below, which have significant budgets but lesser cybersecurity capability, breached in 2016 makes an ominous statement on unpreparedness. This list includes the U.S. Justice Department, the IRS, Verizon, LinkedIn, Dropbox and Cisco. Enterprises need to punch above their weight-class.
Of the companies surveyed, 57 percent of medium-sized companies and 53 percent of large companies had experience with ransomware, according to IBM, compared to 29 percent of the smaller companies.
Small businesses don’t have the scale to match their cyber opponents
According to the Small Business Administration (pdf), small businesses account for almost half of the economy with 49.2 percent of private-sector employment and 46 percent of private-sector output. The SBA defines a small business as an enterprise that has fewer than 500 employees. Small businesses have tiny budgets to fight increasingly sophisticated bad actors that include nation-states that operate at scale.
IBM’s recommendations are not new: employee awareness and training, system updates, software patches and firmware updates, regular and securely stored backups, endpoint antivirus and malware detection software, safe browsing by setting email and Microsoft Office to prevent attachments from executing macros, and, of course, a disaster response plan. Implementing the recommendations is beyond the reach of most small companies that have small budgets. It is like putting a flyweight in the boxing ring against a heavyweight.
Machine learning-based endpoint protection from companies such as Cylance and Symantec that detect malware is promising because they do not require the signature updates of the most recently identified malware to detect and stop malware. Just like machine learning can identify a cat in an image after training the models with datasets of cats in many different images, malware can be detected even though the presentation, code lengths and signatures are different.
Note: The security budgets by company size were estimated using data from census.gov categorized by company size, estimated to be 1 percent of revenue.




