Alternate Titles: Understanding Ransomware and its business risks
What Cryptoware (Ransomware) can do to your business
Business Risks of Ransomware / Cryptoware
The increasing cases of ransomware threats has made it necessary for business persons to understand what it is and how it might affect their business. Quite simply ransomware is software that takes charge of your data or applications, encrypts them, and then offers you decryption solutions for a fee. That’s the reason its also called cryptoware. The risks? Well here goes…
Ransomware is an out an out criminal activity. Its not merely an attempt to steal your data. It’s a blatant kidnapping of your computer and possibly your entire network! Not only is your data encrypted, the criminals – yes it’s a criminal activity – have access to that data and they can use it as they please! One thing to remember though is that they are after money and not the data itself. Often the data may be of no use to them.
Cryptoware encrypts your data using code which has a key. The criminals then offer you that key for a specified amount of money or else. They will threaten to make all your data unrecoverable after some time. Your data will then be in their control and they may publish sensitive information that could harm your business. Some of these criminals even pose as law enforcement officials and threaten to prosecute you! As time passes, they’ll increase the amount of ransom and worse harm even your bootstrap software so that your machine crashes. They will warn you that your entire network may become useless unless you purchase the key from them. They will give you deadlines by which you must purchase the key or risk losing your data.
When ransomware targets individual machines, it affects only that one machine but when it targets your business, if even one machine is affected, it can spread quickly over the entire network. This means all data on the server and cloud plugins like
OneDrive, Dropbox and Livedrive is affected. Once a gateway is opened through one computer on a network, the data on the entire network can be encrypted and your business held to ransom.
Says Mitchell Berenson of Intermedia, the dilemma for a business affected by ransomware is whether to pay ransom or spend precious hours recovering data from backup – which often is slack because of lack of time in the first place! Whatever you do, you’ll face serious downtime which means lost business. The downtime is anywhere from 2 days to more than 5 days. Imagine all the customers that would turn to competitors in that time, not to mention all your employees being paid for sitting around doing nothing! Add to that the overtime you would pay your IT staff for recovery. And if your backup procedure is slack…
Cryptoware is not limited to individuals or SMEs. It can impact big business just as easily. A survey by Intermedia found that 60% of the businesses impacted by Ransomware had 100 or more employees. 25% had more than a thousand employees. The impact began with 2 or more computers and quickly spread to over 20 in 86% of the cases. Quoting Luke Skibba – Gigabitgeek on Twitter, “After shutting down the computer of the affected user and taking her off the network, we determined she had been hit with the CryptoWall ransomware. We had 90 percent of our files be encrypted. This impacted every user in our whole company.”
Ransomware is a rapidly growing threat to businesses with even IT firms falling victim. The attacks are expected to increase in complexity. The time to take action is sooner rather than later. As they say, a penny in prevention is worth a pound in solution. Walter Chamberlee, Director (IT) from Signaturefd.com says, “Ransomware attacks are on the rise and are growing in complexity. Without the right protection measures in place, ransomware can be majorly disruptive to a business. In these cases, it’s the user downtime and the hassle for IT that’s far costlier, even if you pay the ransom.” That is not to say these attacks cannot be prevented. Managed antivirus protection can help you avoid an attack. So go for it now before it’s too late.