Pub. 14 2024 Issue 2

• The $1.1 billion tally of ransoms paid in 2023 was particularly shocking because it nearly doubled the $567 million in ransoms paid out in 2022. • Not including the payouts, the average cost of a ransomware attack — including detection and escalation, notification, post-breach response and lost business — rose to $5.13 million in 2023, which represents a 13% increase from 2022. • Federal and international law enforcement have deployed extensive efforts to minimize ransomware attacks on a global scale. In fact, the FBI and UK National Crime Agency made headlines as they implemented “Operation Cronos” and disrupted one of the world’s most potent ransomware attackers. • Despite law enforcement’s efforts to smother these cyber threats, experts project an increase in cyber syndicates in 2024. Allan Liska, threat intelligence analyst at cybersecurity firm Recorded Future, commented, “A major thing we’re seeing is the astronomical growth in the number of threat actors carrying out ransomware attacks.” Recorded Future reported 538 new ransomware variants in 2023. 5-Step Plan for Businesses to Prevent Costly Ransomware Attacks in 2024 1. Provide Updated Cybersecurity Training You should provide updated and robust cybersecurity training to all your employees (including very busy executives) on an annual basis. According to the 2023 Cost of Data Breach Report (CODBR), phishing and compromised credentials were the most common initial attack vectors for data breaches, demonstrating that threat actors still count on a shortfall in employee oversight to gain access to valuable, confidential data. The latest data from the CODBR also suggests that cybersecurity training is a wise investment for employers. In 2023, organizations with a high level of employee training that suffered a data breach incurred a significantly lower-than-average cost in managing and responding to the data breach incident. On average, data breaches cost $770,000 less for organizations with a high level of employee training and $640,000 more for organizations with low levels of employee training. This data underscores the importance of ensuring that all employees with access to sensitive data are familiar with the basic principles of data security. Make sure to train them to understand the red flags that will help them detect phishing emails and other common tactics used to compromise credentials. 21 Illinois Automobile Dealer News

RkJQdWJsaXNoZXIy MTg3NDExNQ==