Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

11/18/2020
12:30 PM
50%
50%

As Businesses Move to Multicloud Approach, Ransomware Follows

The average US company uses 16 cloud services, but only a third of IT professional believe their security measures have kept up with the change.

Companies' IT infrastructure continues to become more complex — with multicloud deployments becoming the norm — leaving many businesses with security holes that put them at risk of ransomware attacks, according to a survey of nearly 2,700 IT professionals in 21 countries.

The survey, conducted by Wakefield Research for data protection firm Veritas, found the nearly ubiquitous use of cloud services, with 92% of companies using public cloud infrastructure and applications. The average US company uses 16 cloud services but suffers from the complexity of managing the security of the heterogeneous infrastructure, with 42% of companies experiencing a ransomware attack, according to survey results.

Related Content:

Rising Ransomware Breaches Underscore Cybersecurity Failures

The Changing Face of Threat Intelligence

New on The Edge: We Secured the Election. Now How Do We Secure Trust in Results?

Part of the problem is the piecemeal approach that many businesses take toward cybersecurity, says John Abel, chief information officer of Veritas.

"It's easy to fall into the trap of considering each new application moved to the cloud as a unique item to protect," he says. "Treating security in this way allows protection architectures to multiply, fracture, and become more complex — making management challenging and mistakes more likely."

Ransomware has become a major threat to businesses. More than half of companies have suffered a ransomware attack in the past year, with criminals able to encrypt data in 73% of those attacks, according to a May survey of 5,000 IT managers conducted by Sophos. The survey found that 41% of ransomware victims suffered disruption to on-premises data, while 35% of companies had public cloud data affected. The remaining 24% had data across both infrastructure types affected.

The Veritas study found a similar breakdown, with 43% of companies with mostly on-premises infrastructure experiencing ransomware attacks, as did 33% of companies with mixed infrastructure and 43% of companies with mostly cloud infrastructure.

"The cloud is no safe haven from ransomware," the Veritas report states. "Ransomware attackers will target data and applications in the cloud as much as they will attack those in an enterprise's data center."

Only 12% of companies use either only on-premises or only in-the-cloud infrastructure. The vast majority of firms, 88%, use a hybrid of the two, combining on-premises and private cloud technology with public cloud infrastructure, according to the Veritas report.

The coronavirus pandemic has accelerated many cloud deployments, resulting in larger security budgets overall, with almost half — 46% — of IT security groups seeing more funding, compared with 26% seeing a decreased budget and the remaining 28% seeing no change.

Two-thirds of business IT leaders don't believe that their company could recover from a ransomware attack within five days. The perceptions of the threat also differ between executives, who often have a more strategic view, and directors, who may a more tactical view, according to the survey. CIOs were 10 percentage points more likely — 43% versus 33% — to believe that the company could recover within five days, compared with IT directors, according to the survey. 

"The difference in thinking between the IT directors and the CIOs might be one of the reasons why we're not seeing more of the IT investment we mentioned earlier being diverted toward data protection," Abel says. "This, in turn, helps to explain the growth of the resiliency gap."

Backups have become perhaps the most important countermeasure against business disruption due to ransomware. The report published by Sophos in May found that 56% of companies whose data was encrypted by ransomware recovered the data from backups, compared with 26% that paid the ransom. More importantly, the companies that used backups save money, experiencing only 51% of the various costs of ransomware, about $733,000 per incident, compared with companies that paid the ransom, who calculated total damages at $1.45 million.

Veritas recommends that companies increase their resiliency to business disruption by having at least three different copies of data, including two copies on different storage media, with one of those copies air-gapped to an off-site location. This "3-2-1" rule offers more reliability in the case of an attack, but only about a third of companies actually use that backup strategy, Abel says.

"There's no real way of avoiding a ransomware attack — we often say it's not a case of 'if' a company will be attacked, but 'when,'" he says. "No matter what defenses are in place, you can never close every hole or block every threat. There's always a weakest link."

 

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29529
PUBLISHED: 2020-12-03
HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.
CVE-2020-29534
PUBLISHED: 2020-12-03
An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimize unshare_fd(), aka CID-0f2122045b94.
CVE-2020-17527
PUBLISHED: 2020-12-03
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this woul...
CVE-2020-23736
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in DaDa accelerator 5.6.19.816,, attackers can use constructed programs to cause computer crashes (BSOD).
CVE-2020-23738
PUBLISHED: 2020-12-03
There is a local denial of service vulnerability in Advanced SystemCare 13 PRO 13.5.0.174. Attackers can use a constructed program to cause a computer crash (BSOD)