Lightning Often Strikes Twice for Ransomware Victims

Lightning Often Strikes Twice for Ransomware Victims

1 in 15,300

Your chances of getting struck by lightning once

1 in 9 million 

The chances that it would happen to you again

What are the odds that your business would be targeted by a cybercriminal? Many small business owners think they’re too small to be considered a target, but they couldn’t be more wrong. And unfortunately, unlike a lightning strike, once you’ve been hit once, you’re more likely to be struck again. 

But first, let’s step back and examine the basics, as ransomware attacks have evolved over the past few years…

Lightning

What Is Ransomware? 

Ransomware is a specific type of malware that encrypts data. Hackers can use ransomware to make your files inaccessible unless you have the appropriate keys to unlock or “decrypt” them. Hackers will then demand that you pay a ransom to get your files back — often in the form of cryptocurrency. 

More recently, some hackers will also threaten to publicly release sensitive information if you don’t pay up. They may even threaten to alert the media or directly contact your customers — notifying them that you’ve failed to protect their data. In fact, these secondary forms of extortion are becoming far more commonplace

Unfortunately, cybercriminals don’t always honor their promises. Even if you pay the ransom, recovering your data is not a given. Worse yet, paying the ransom can actually double the overall cost of the attack. 

Recent Ransomware Attack Statistics

The CyberEdge Group recently released their 2023 Cyberthreat Defense Report, which included a few statistics that are hard to unsee: 

  • 7% of organizations have been the victims of a ransomware attack so far in 2023 
  • 7% of these organizations paid the ransom
  • 73% were able to recover some data
  • 21.6% only had their data encrypted, with no additional form of extortion

The True Cost to Business Study 2022 also revealed critical findings that point to another alarming trend — repeat attacks: 

73% of organizations had at least one ransomware attack in 2022

80% of those who paid the ransom were attacked again

68% were attacked less than a month later with a higher ransom

Our Analysis of Recent Ransomware Data

It’s been incredibly frustrating for many small business owners to deal with a pandemic and then a ransomware epidemic on top of it. But here are our takeaways of where this data is pointing:

Ransomware

  1. If you haven’t already been the victim of a ransomware attack but you aren’t currently following cybersecurity best practices, you’re at high risk of becoming a victim.
  2. Do not pay the ransom. It’s tempting to try to minimize the damage, but it’s more likely to have the opposite effect. 
  3. Reliable backups are important, but they aren’t enough. Cybercriminals find that they can get even more money by releasing your information online and telling your customers and the media about it.  
  4. It’s important to develop an Incident Response Plan. Preparing for a potential incident, like ransomware, ahead of time can help companies define their processes, establish roles and expectations, increase their ability to properly identify an incident, respond quickly, and contain the incident before it spreads. This can save the company a tremendous amount of time and money if an incident was to occur.

How To Reduce Your Risk of Ransomware Attacks

How about some good news for a change? You’re not alone in the fight against cybercrime. The U.S. government has put together a list of cybersecurity best practices to help businesses and nonprofit organizations protect themselves, and we’ve compiled those recommendations into a Cybersecurity Checklist designed with small to midsize businesses in mind. 

Security awareness training is a key component of your overall cybersecurity posture — one that can transform your staff from your biggest liability to your star defenders against phishing, malware (including ransomware), and fraud. 

But if your IT team is already overwhelmed with other day-to-day tasks, perhaps the quickest way to update your cybersecurity posture is to book a security assessment from a leading technology provider. Many providers will offer you a free remote scan, but that scan won’t uncover weaknesses in your policies and settings, and you’ll get a mountain of data back without a good way to filter it. Ours is a bit different — we conduct a thorough investigation of your business’s risks and leave you with a list of custom recommendations, prioritized by what vulnerabilities pose the biggest risk to your business and why. 

Learn More About a Marco Cybersecurity Assessment

Related Posts

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...

The Security Strategy AI-Powered Attacks Demand
The Security Strategy AI-Powered Attacks Demand

The threat environment changed. Not gradually. Abruptly. Tools like Anthropic’s Claude Mythos and the latest generation of AI-assisted exploitation capabilities have fundamentally ...

Data Security Governance Best Practices for 2026
Data Security Governance Best Practices for 2026

Data security has reached a breaking point. Sensitive information now lives in more places than ever, sprawled across SaaS applications, cloud drives, on-premises servers, and incr...

Top Cybersecurity Laws and Regulations To Know About in 2026
Top Cybersecurity Laws and Regulations To Know About in 2026

Many companies are now facing the challenges posed by malicious hackers attacking their IT environment. Unfortunately, the fallout continues even after the attack is contained, inc...