2017勒索软件报告(英文版)_57页-4mb
报告摘要
2017 Ransomware Report Summary
Core Content
The 2017 Ransomware Report by Cybersecurity Insiders provides an in-depth analysis of the ransomware threat landscape, its impact on organizations, and the measures being taken to defend against it. The report highlights that ransomware has become one of the fastest-growing cybersecurity threats, with 80% of cybersecurity professionals perceiving it as a moderate or extreme threat. It is a significant concern for businesses of all sizes, from small and medium-sized businesses (SMBs) to large enterprises and government agencies.
Key Survey Findings
-
Ransomware Growth and Perception:
- Ransomware is the fastest-growing security threat.
- 79% of organizations predict it will be a larger threat in the next 12 months.
- 75% of affected organizations experienced up to five attacks in the last 12 months, with 25% facing six or more.
-
Infection Vectors:
- Email and web use are the most common vectors.
- 73% of ransomware infections occur through malicious email attachments.
- 54% are due to phishing emails.
- 28% result from visiting compromised websites.
-
Data at Risk:
- Financial data (62%) and customer information (61%) are the most vulnerable.
- Employee information (51%) and company IP (50%) are also at risk.
-
Impact of Ransomware:
- 41% of organizations experienced system downtime.
- 39% faced productivity loss.
- 30% suffered data loss.
- 16% reported a loss of confidence in existing cybersecurity solutions.
-
Response and Recovery:
- 54% of organizations can recover from ransomware within a day.
- 39% estimate recovery to take more than one day to a few weeks.
- 96% of respondents have a data backup and recovery strategy in place.
- 74% of cybersecurity professionals consider data backup and recovery as the most effective response to ransomware.
-
Confidence in Defense:
- Only 12% are extremely confident in their organization’s ransomware defense capabilities.
- 28% are very confident.
- 51% are only slightly to moderately confident.
- 8% are not confident at all.
-
Response Tactics:
- 81% of organizations respond by identifying the ransomware strain, containing the damage, eradicating malware, and recovering from backups.
- 77% of organizations would not pay the ransom.
- Only 3% of companies have set up a Bitcoin account in preparation for paying ransoms.
Ransomware Threat Landscape
-
Ransomware Types:
- Encrypting ransomware (cryptoware) is the most common type, affecting 88% of organizations.
- Other types include lock screens, MBR/NTFS encryption, leakware, and mobile device ransomware.
-
Attack Frequency:
- 75% of organizations experienced up to five ransomware attacks in the last 12 months.
- 25% experienced six or more attacks.
- 78% of security professionals expect an increase in attack frequency.
-
Main Obstacles to Defense:
- Lack of budget (52%).
- Evolving sophistication of attacks (42%).
- Lack of human resources (33%).
- 60% of organizations expect to increase their ransomware security budget.
Cybercriminals Behind Ransomware
- Top Culprits:
- 69% of cybersecurity professionals believe organized cybercriminals are responsible.
- 58% think non-organized opportunistic hackers are behind attacks.
- 28% believe state-sponsored hackers are involved.
- Other motives include political beliefs (17%), hacking for fun (25%), and revenge (8%).
Ransomware Defense and Budget
-
Effective Prevention:
- User awareness and training is the most effective preventive measure (77%).
- Endpoint security solutions (73%) and patching systems (72%) are also highly effective.
-
Detection Tools:
- 83% of ransomware attacks are detected through endpoint security tools.
- 64% are detected via email and web gateways.
- 46% are detected through intrusion detection systems.
-
Recovery and Backup:
- 96% of organizations have a data backup and recovery strategy.
- 74% of cybersecurity professionals view data backup and recovery as the most effective response to ransomware.
Conclusion
The report emphasizes the need for a multi-layered approach to ransomware defense, including user training, robust endpoint security, and regular system patching. It also highlights the importance of having a solid data backup and recovery strategy to mitigate the impact of successful ransomware attacks. Despite the challenges, there is a growing awareness and willingness among organizations to invest in ransomware security.
试读结束,高清完整版pdf/doc/ppt,请点下载