SCORE Session 3 — Ransomware
A danger to your business and your wallet
How ransomware attacks actually unfold against small businesses, why backups alone no longer save you, what an attack really costs, and how to approach the decision to pay or not to pay.
In the third session of the SCORE Chicago cybersecurity series, Cyrus Walker explains why ransomware has become the leading threat to small businesses and the number one driver of cyber insurance claims. He covers how ransomware-as-a-service and AI have made attacks cheaper and faster, walks through real incidents at Change Healthcare, CDK Global and Joliet public schools, and breaks down the six stages of an attack, including double extortion and the destruction of backups. The session closes with the prevention basics — patching, air-gapped backups, MFA and security awareness training — the questions to answer before deciding whether to pay, and a live Q&A.
All righty. Good afternoon everyone. Thank you for joining us. We will be starting the presentation at 2 PM. Thank you.
Good afternoon everyone. Thank you for joining us. My name is Toyia Hemingway and I'll be your host this afternoon. A little bit about SCORE. Over 60 years.
SCORE, a resource partner of the US SBA, has been helping small businesses start, grow, and succeed. With thousands of volunteers nationwide, including over 60 right here in Chicago, our in our Chicago chapter, our mission has been simple. No one should have to navigate the entrepreneurial journey alone. We support you in two ways. One, we provide free and low-cost education, a lot of webinars on topics like business planning, marketing, web design, and as you see today, when ransomware, we also provide one- on-one mentoring that is free confidential, lowterm, long-term mentoring with experienced business leaders.
You can request a mentor or browse our team anytime by going to score.org/chicago during to today's webinar. A little housekeeping. We we feel free to drop your questions in the chat. I'll be monitoring it throughout and we will open the chat box up for live Q&A at the end and allowing about 20 minutes for the Q&A session. Also, I want to take the time now to give you some information about Cyrus, our presenter.
Cyrus Walker is the founder and CEO of Data Defenders LLC. He is an internationally recognized and published expert on electronic voting security and is an experienced cyber security industry exe executive. Cyrus has served as an a subject matter expert on cyber terrorism and incident response management for the Cyber Defense Analysis Center at the University of Arkansas which is funded and directed by the US Department of Homeland Security where he has trained over 5,000 law enforce enforcement professionals both at the federal, state and local levels from numerous agencies across the US. Cyrus has spent six years as the department chair and adjunct professor of computer security and computer forensics at Wright College, one of the city of Chicago city colleges. He has been a contributor on numerous media stations including CNN, Fox, Bloomberg, ABC, and the CBS networks on cyber security and terrorism related events.
Cyrus spent 20 years in various technology management roles where his engineering and management expertise in high-speed network design were used to design and test carrier broadband in interoperability sorry which served as the foundation for development of broad tongue twister based internet that currently serves the country today. Cyrus was recognized for his work and leadership in 1995 by President Bill Clinton. Cyrus also holds a bachelor deg bachelor's degree in electrical engineering from the University of Illinois. We are very fortunate to have you as a speaker today and thank you so much for this presentation. Turning it over to you Cyrus.
Thank you, Toyia, for that introduction. I greatly appreciate it and I am as usual happy to be here to continue this series that we started earlier this year on cyber security and various topics related to building your cyber security operations in your organizations. Here we are today at the third session of this series on a reminder we have three other sessions that we're offering this year of course all related to cyber security focused on developing your program dealing with the your the human behavior or the employees in your company and of course the last topic on phishing which we'll talk a little bit about here today as ransomware uses that as a a threat vector into your organizations. So, let's go ahead and get started. We got a little bit of material to cover today because it's such a deep and broad topic at the same time.
I'll try to get through it as quickly as possible. Feel free to put your questions in the chat. You can also ask those questions. I believe Toyia is going to be monitoring the chat chat box and so as questions come up, I'll try to answer them during the presentation. So, let's go ahead and get started.
So, as you recall in March, we talked about the incident response plan, which is a key component to cyber security operations, developing that that plan before the incident happens to help you outline how you'll respond to that incident in order to minimize time and damage and financial losses that result in a from a security incident that you might be dealing with. In June, we talked about insurance, the importance of insurance, and what insurance covers. Today we're going to talk about which is the bane of insurance companies. This is typically where insurance payouts or or insurance gets activated in dealing with cyber security incident. So we're going to delve deep into ransomware and talk a little bit about the relationship and the expectation that insurance companies have from companies who they ensure to and do their due diligence to protect themselves from ransom.
So let's so where are we today? Let's look at some statistics to set the stage for where we are today. First, as you might remember in some of in the the previous presentations, 86% of small businesses, small business breaches involve ransomware. That's a pretty hefty percentage versus just 39% of large organizations that deal with ransomware breaches. We're going to talk about why that is throughout this presentation.
Today, 43% of all cyber attacks target small businesses. And as you remember from the two previous presentations, that is because malicious actors see small businesses as low-hanging fruit or easy targets for a number of reasons. What's the real number as it relates to a ransom attack? First, you have the ransom demand, which is generally averaged around $115,000 today. But you also have the total cost of the incident.
How much is this in incident going to cost in in not only the ransom but also in the response in the downtime and the loss of customers and productivity that translate into the total financial challenge or loss that we're going to deal with when we deal with ransomware situations. The total average of an incident generally comes in around 4.4 to 5 million. That's 38 times greater than the ransom. And the reason why that is significant is because we're going to talk at the end of the presentation about whether to pay or not to pay, which has been a debate for a very long time related to this particular threat. The average recovery cost is about $1.5 million.
And that's actually falling. And the reason it is is because technology has gotten a lot better on the incident response side and organizations have gotten better in planning developing their incident response and testing them on an annual basis. As you can see that these numbers small businesses generally will find it very challenging to have to incur these kinds of financial losses. And this is why insurance becomes so important to help small businesses deal with the financial ramifications of a ransomware attack. Why attacks keep increasing and why walking away isn't a simple thing to do.
Attacks keep increasing because the technology gets is is getting better. As you see in some of the statistics that we have here, there are 83 new ransomware variants released in 2025. That's significant because as you'll see later on in the presentation, the FBI has done a really good job of tracking all the variants, the ransomware variants that have plagued organ businesses in this country and in some cases have collected decryption keys that make it easier for companies to recover from the ransom without having to pay. And we'll get into that a little bit later. Five, there have been 5,134 ransomware complaints in 2025. 74% of ransom cases involve data theft before the encryption.
We're going to get into the concept of double extortion as it relates to that and also on the preventative side, how you can protect yourself from being a victim of double extortion. There's been a nine a plus 9% increase in reported complaints. Now, the thing that's driving this to a significant degree is what we call ransomware as a service. that. And believe it or not, malicious actors, the bad guys, they do organize as well. And this new thing that we call ransomware as a service has manifested.
And what that is is a automated way that malicious actors can utilize the the ransomware threat vector without having to do the work actually themselves. So they can essentially rent infrastructure that's set up specifically to deliver ransomware variants to attack organizations based on the malicious actors direction without having to sit at a computer to do that. So they've streamlined their capabilities of attacking organizations. And so that's why we see the rise in ransomware variants. That's why we see the rise in cases reported to the FBI.
And also why we see a rise in what we call double extortion which is basically the exfiltration of your data out of your environment under the threat of that data being released into the general domain public domain if you don't pay additional dollars as a result of the the attack in the first place. So I talked mentioned about the sophistication or the streamlining of the ransomware attack vector AI is the craze today. Everybody is using it whether you think you're using it or not. AI is built into every smartphone or desktop or laptop or tablet that you use today. It is controlling the back end of most systems or functions that we use particularly in banking or in retail especially in transportation and is continuing to become prevalent in every aspect of our lives including the including cyber crime.
Over the last couple of years of AI coming online, what we've noticed is that 80% the ransomware variants being released today use some AI capability. And so what that means is that it has an ability to do footprinting and enumeration of your systems in a very efficient way. This also ties to the ransomware as a service scenario that I just talked about that allows them to collect data in a much more efficient and faster way and in a much more broader way. So now they can expand their attack surface increasing the number of victims that they go after in one single shot. AI is now being used to craft phishing emails.
I I I even though I am a security expert, cyber security expert, I do get phishing emails as well. We do have a system that can filter them out. And I tell you these phishing emails look very sophisticated. They look like the real thing. And so you have to be very careful these days about who you interact with via email, particularly clicking on links or downloading documents and so forth and so on because these emails are being crafted in very significant ways.
It used to be that when a phishing email was sent out there there was either bad grammar or misspellings and you could easily tell that an email with bad grammar or misspellings wasn't sent from Chase or from Citibank or from Amazon to get you to log into their systems. Nowadays, it's much harder to tell that to to tell the difference. And so, you really have to be on your P's and Q's and aware of how you've been interacting with these companies to determine whether or not that these emails are valid. I did talk a little bit about that in the previous presentations and I also get into that in a much deeper way in the uh upcoming presentations. As I also mentioned before, because of the ransomware as a service solution that's available, attack malicious actors have been able to cut their cost in executing phishing attacks against organizations by 95%.
And this is a significant development because what that means is that it has made the ransomware attack vector very lucrative. You don't have to spend a whole lot of money in order to launch a ransomware attack or a whole lot of time to do that. If my efforts can land me a 95% profitability, guess what? As a bad guy, I'm going to focus my time on my time and attention on. And AI has certainly helped to bring about this profitability in this particular cyber crime.
And it's not a good thing. On the horizon is quantum computing. That's not commercially available yet, but it is not far behind. Illinois is building the first, particularly here in the city of Chicago, the first quantum computing park that eventually will offer commercial services. And when that happens, not only are we talking about more streamlined capabilities, but we're also talking about the abilities to decrypt data.
So for instance, if you're using encryption to protect your data and that data is exfiltrated out of your environment with quantum computing, it is highly likely that data can be decrypted in a short amount of time. We'll look at that later on this year when we look at the right size cyber security development as it relates to how you build cyber security in your environment. That is a significant development that's really going to create a lot of havoc in the cyber crime space particular for the victims and it is something that we are certainly keeping our eye on. So, one of the biggest misconceptions about cyber crime is that the attacker only relies on sophisticated computers and expensive infrastructure. But in reality, many of the attackers we see today are launched from ordinary internet connected devices like firewalls and home routers and security cameras and streaming devices, gaming systems, and other smart technologies that people use every day.
Once compromised, these devices become part of a massive criminal network that attackers use to hide their identity and make their operations much more difficult for law enforcement to trace. The statistics that we show here demonstrate the scale of the problem that I'm talking about. Criminal organizations have successfully compromised millions of inter interconnected devices worldwide, creating enormous proxy networks that can route malicious traffic through innocent users equipment. We saw that happen about I guess 10 years ago or or less I should say with the Amazon attack that happened. It was the first time that we had seen an IoT attack or an IoT denial of service attack against a major organization.
And what that attack was is Amazon was hit with a denial of service attack. Some malicious actors had created what we call a botnet that was made up of all these devices that I'm talking about, smartphones, smart TVs, smart cameras, smart appliances, and they were triggered to transmit data to Amazon in effect flooding Amazon with data and preventing it from being able to deliver its services to the general public and in in effect creating what we call a denial of service attack and IoT or botnet denial of service attack. And while these devices are typically not used to deliver ransomware, they play a critical role in reconnaissance, credential attacks, phishing campaigns, making the origin of malicious activity or masking the origin of malicious activity, all of which increase the likelihood of ransomware attacks that will eventually succeed. The takeaway here is you have to be extremely due diligent in what you do to protect not only your business technology but also your technology at home and particularly if you are a remote worker and you work from home. There is definitely a necessity to ensure that your home technology is secure and that we'll talk quite a bit about in the upcoming session.
So ransomware has become an equal opportunity threat, but some industries experience a greater concentration of attacks more so than others. Manufacturing has been the number one targeted industry for four consecutive years. And healthcare continues to experience some of the highest financial losses from data data breaches, financial service, financial services remains a high value target obviously because of the product that it provides to the the general market. The numbers also illustrate that cyber security, I'm sorry, that cyber criminals understand the business impact of downtime in health care. Ransomware can delay patient care and interrupt clinical operations while attacks against manufacturers can stop production and disrupt global supply chains.
We saw that happen about two years ago with Lurie's, if you're from from the Chicagoland area. We saw that happen with the Lurie Children's Hospital situation that occurred and also last year with Ascension Hospital systems. Both systems were attacked or hit with ransomware. Their databases were encrypted. Lurie's, for instance, had to literally stop conducting operations because or providing medical services because they could not deliver those services in in the manner that they had been set up to to do.
They couldn't schedule them, they couldn't manage them, they couldn't bill, they couldn't do anything. It took them six weeks to recover from that. So, you can imagine the challenges that caused for families of children that required medical care, immediate medical care. If you remember about maybe 10 years ago as well the the Target attack where at that time the largest number of credit card numbers have been stolen from Target's computers that happened and what we call a supply chain or a vendor based attack where their HVAC vendor was attacked who had a direct connection into Target's infrastructure and as a result target was became a victim of that incident. So supply chain concerns are extremely important these days and we talk about that quite a bit when we look at vendor risk management.
We touched on that in the previous sessions but we'll look at that in much greater detail in the next session coming up in August. I mentioned this a little bit before, but because of the work of the FBI and trying to stay ahead of the curve in dealing with ransomware, they've been able to collect decryption keys for data related to known ransomware variants. As a result, they've been able to help victims avoid paying out upwards of about $800 million in ransom. Also, as we talked about the ransomware as a service, these variants can be either very new or very old or anywhere in between. And depending on the variant itself, there may be a decryption key available that the FBI can provide to you to help you decrypt your data so that you can avoid making out a payment.
Now, what this does require you to do is to report to to the FBI that you have been a victim of a ransomware attack. And that is a business decision that you need to make. Depending on the size of your organization, especially if you have a board in place, there are some ramifications of making that reporting. You certainly from a local municipality perspective and a state perspective, there might be some regulatory compliance that you need to adhere to like reporting to people who may be victims or may subsequently be victimized as a result of the attack on the organization. But at the end of the day, you might have an opportunity to avoid the financial loss due to the ransom by reaching out to the FBI and asking if they can provide you with a decryption key for the particular variant that you might have.
That's obviously going to require them to come in to get a sample of the variant to measure it against their database to see what they might have in order to confirm whether they can help you in that manner or not. Hopefully they can. If not, then you'll just follow the steps that we've outlined in our incident response planning session a few months ago to help you continue to recover from that attack. We'll also talk about to pay or not to pay at the end of this session because that's a decision also that you'll have to make with your board and certainly with your senior management in order to determine what you're going to do in that regard. Let's look at three quick incidents or situations that have occurred in various scenario various industries.
The first is Change Healthcare. I did mention Ascension and Lurie's. As with those two, Change Healthcare was hit with a ransomware attack. The scale of the attack was unprecedented affecting approximately 192 million individuals and making it the largest healthcare data breach in US history to date. This was not simply an attack on one company.
It disrupted a national system used to process prescriptions, insurance claims, and healthcare payments. Operate. The operational impact reached deeply into the healthcare community with 80% of physicians reporting lost revenue because claims could not be processed or paid. Many providers, particularly smaller practices with limited cash reserves, struggled to meet payroll and continued serving patients while payment systems remained unavailable. Recovery was not as was also uneven, taking anywhere from 2 weeks to 3 months for some physician practices to recover from the incident.
Now I can guarantee you that the variance in that time certainly is based on their preparation to respond to an incident and the availability of resources to help come in and respond and recover from that incident. And so this is again why the incident response planning that we talked about a couple of months ago is extremely important. It can shorten the amount of time that it will take for you to recover from that incident. CDK Global. The this attack demonstrates how ransomware again against a technology provider can disrupt thousands of otherwise unaffected businesses.
Approximately 15,000 automobile dealerships across the United States and Canada were brought to a standstill because they depended on CDK's systems for sales, financing, inventory, service, and payroll. Now you may have heard me mention in the two previous sessions about the benefits of cloud computing and I still stand by the benefits of cloud computing particularly from an infrastructure and expenditure perspective and also from a security pers perspective in your own domain. If you don't have to manage computers on premise that makes securing your environment a lot easier to do. Now it does shift the need for security to the cloud vendor like as we see here CDK global but it in that transfer and as part of that process what you need to be doing is again what we call a vendor risk management process that requires the vendor to demonstrate that they're doing everything in their power to ensure that your data and your access to their systems is going to be secure. The financial the downstream financial impact here extended far beyond the ransom payment.
Although CDK reportedly paid about $25 million in Bitcoin, the total economic impact across the automotive industry reached nearly $1 billion. If you remember in my first presentation, I talked about the total cost of cyber crime this year is going to top $10.8 trillion. Here we see 1 billion of that just in this situation alone. As a result of that, there was a 7.2% decline in US new vehicle sales compared with the prior year, which shows how effective that and the negative impact that cyber attack had on the industry. And lastly, again, if you're here in the Illinois area, the Joliet public school districts experienced a ransomware attack.
About 1,495 people had sensitive data, including their names, addresses, and social security numbers compromised as a result of this attack. The fact that similar attacks also affected other Illinois school districts and the state of Illinois shows that this was not an isolated event. Sometimes there can be coordinated attacks. And as you are communicating in your with your industry cohorts, you can see whether or not there's a trend or pattern that might require you to step up your defenses to pro to to protect you from being the next victim in that attack. The broader statistics are especially important for small organizations is the median ransomware victim had only 228 employees which means that they're typically not the target not the the Fortune 500 company targets that we might think because they have deeper pockets.
As I mentioned earlier, smaller organizations are seen as low-hanging fruit because of the lack of infrastructure, the lack of cyber security resources and protective countermeasures, the lack of expertise, and the lack of access to resources to help on a consistent basis. And so, as a result, small businesses being the number one target when it comes to these cyber crime threat vectors. For organizations with fewer than 100 employees, the median ransom demand was approximately $111,000 and at the same time only 25% of victims paid a record low that reflects a growing importance of tested backups, stronger response planning and preparation that gives organizations another option besides paying the attacker. So we can see how incident response planning and the right technology countermeasures in your organization can help you delay being a victim of having to pay the ransom. What is the common thread with all of these incidents?
The common thread was that they knew that they had these vulnerabilities but they had done nothing about them. And that is a a common scenario that we see as professionals in the industry when we come into an organization. They more than likely know that they have these vulnerabilities, but they don't have the available resources to remediate these vulnerabilities. And so, they bring in an organization like ours to do just that. You might have heard about the Atlanta incident that happened about 10 years, 10 or 12 years ago.
The city of Baltimore, same thing, same situation. They knew about the vulnerabilities that they had, but they did not implement the patches that were necessary to close those vulnerabilities. And as a result, the city of Atlanta incident was about a $15 million loss, total loss, including the ransom, which was only $75,000. But all the rest of that was as a result of the loss of productivity, the amount of time to recover from the incident, and financial penalties that they had to pay out. I mentioned earlier that there are typically three attack vectors that ransomware uses to execute the threat against the organization.
The first is what I just talked about exploited vulnerabilities. Every organization has vulnerabilities. What you do with those vulnerabilities is the next question. Vulnerabilities typically stem from unpatched software or misconfigured network devices or endpoints which is why effective system management is necessary. Excuse me.
We always say that 80% of most cyber activities stem from misu misconfigured devices. Credential compromised credentials. We see this all the time. An individual had their password and user ID compromised in some way, shape or form and that those credentials were used by the malicious actor to gain access into the environment. One day we get a call from a a very wealthy person here in the Illinois area.
He had been a victim of uh it was a compromised credential attack. What happened was he as he was traveling he needed to log into his email account and some of his other financial accounts but he did so using an unsecure computer. He used somebody else's computer to do that. Unbeknownst to him, that computer was already compromised and his credentials were collected and then used to attack or to gain access by the malicious actor to his accounts and to his systems. Thankfully, they were so greedy that when they initially tried to transfer money out of his accounts, it triggered alarms and stopped the transfers from happening. and he got alerts immediately and they were able to he was able to call us to have us come in and and do a a vulnerability analysis and to implement countermeasures to protect that prevent that from happening again.
Also, a lesson learned by him is don't use anybody else's computers to do your business. Use your own. And lastly, phishing and malicious email. We still see this as a a a prevalent attack vector. Again, we should all know what phishing and malicious emails are. basically emails that are sent out to appear to be real from unsuspecting vendors that have links in them that people click on that then open up doorways into or launch ransomware attacks.
We were called into a ironically major law enforcement agency here in the Illinois area. They one of their users had gotten a phishing email from Amazon or what they thought was from Amazon. They clicked on that link and it launched a ransomware attack against their entire infrastructure. And the way it did it is it replicated itself across the entire infrastructure. Now, I'm going to talk a little bit later about uh how that actually worked, but all starting from a phishing email and it took us a month to get out and get our arms around it to be able to begin to mitigate that attack because of the prevalence that it had established in the organization's environment.
So, let's quickly look at the anatomy of a ransomware attack. Basically, there's six parts to the the process of an attack, which starts typically from a user perspective. with a malicious email or some interaction with a malicious site that creates some connectivity into the end user's computer. Once that interaction happens with the the malicious email or the the website itself, then what happens is there are files or there's a call out to the ransomware server. We talked about ransomware as a service. This is where that comes into play.
So that once that that link is clicked or the interaction is completed, there's then a a call out to the ransomware as a service or the server that then uploads the ransomware variant onto the victim's computer and begins the process of encrypting the user's data. In that law enforcement situation I just talked about, we could literally sit that at the computer and see the data being encrypted while the attack was going on. That's how prevalent it was. Once that once the data is encrypted, in a lot of cases today, that data is then exfiltrated out of the environment. In our next session, we're going to talk about network security and how you can actually prevent the exfiltration of data out of your environment.
But in this situation, data is pulled out of the environment that as a part of the double extortion scenario that I mentioned earlier. And what then happens is a message is sent to the victim demanding the ransom. You can pay $500 in Bitcoin or 1,000 in Bitcoin, whatever the ransom is. It used to be that ransomware where attackers didn't really know who their victim was. So the ransom wasn't really that much.
It was enough to get a person to pay so that they can get the key to decrypt their to decrypt their data. But today they do know who their victim is. And if it's in the case of a large organization with deep pockets, you can bet that ransom is going to be very hefty. We saw CDK Global pay $25 million. organizations have paid tens of millions of dollars in order to stop the attack, get the decryption key so that they can get their operations back online. In some cases, even when the key is given, the key might not work.
There might be additional demands for ransom because the the ransomware attacker knows who you are and knows that you have deep pockets and more than likely knows that you have insurance as well. And so, as a result, they're making further demands for data. But typically if it's a nice attacker the once the payment is made the encryption key is sent or decryption key is sent to the user so that they can or the victim so that they can decrypt their data and then get themselves back online. On the double extortion part, what we see happening today is because of the data exfiltration, a second extortion request or demand is made in the form of if you don't uh pay this amount that we will release your data out into the general public. Now, a lot of organizations don't want that to happen because sometimes that data is is personal, contains personal identifiable information.
It may contain trade secrets. It may contain sensitive documents that shouldn't be in the public. It may affect their mark position in the marketplace. If I'm working on a new service or new product, I don't want my my my product strategies or my product development to be released to the marketplace because what that does is it diminishes my market position and value and threatens my business overall. So that hits the second uh extortion demand for not releasing that data.
We see that happening more and more now with insurance companies. Also what you will find is not only will they participate in the response but there are also organizations out there that do nothing but negotiate with ransomware attackers. And when I found this out, I was didn't surprise me, but I I was floored that we have come to that where you now you have to have hostage negotiators basically that get involved in order to negotiate the ransom so that to minimize the payment, but also to ensure that the victim either gets their data back or is no longer going to be a victim of the attack. One of the things to also consider in this is that once you've been attacked once, you more than likely may be attacked again. And why?
Because the the attacker knows that you your defenses are weak. They were successful with you the first time. Why not try it again? So return to the scene of the crime does happen quite often. And we'll again talk about that in the next session as it relates to how to build your network infrastructure, how to secure it, and how to build your cyber security operations to keep you secure to prevent that from happening.
The dwell time right now the average is 4 days. And what that means is how long the attacker has been in your environment before they actually launch the attack against you. We've seen dwell times upwards of 8 months, a year. We've seen zero day attacks. The dwell time is really all over the place.
But what the thing that we've seen with dwell time is that it does relate somewhat to the type of entity that you are. If you're a large organization, more than likely the dwell time is going to be very long because there's a lot of complex infrastructure to get through by the bad guys. They are footprinting and enumerating and establishing prevalence in your environment. So, they're leaving various um various measures in your environment so that if you close one door, there's another door that they've established in your environment for them to continue their quest in your environment. And so that dwell time can be can vary depending on who you are.
For for small businesses, most likely the dwell time is is very small because again the counter measures is that the attacker or the victim has in place generally not that strong to stop an a malicious attacker from getting into the environment. So it varies. But again as I mentioned what are they doing during this time? They're recon. They're conducting reconnaissance.
They're learning who's who and what's what. They're trying to see if they can get access, administrative access into your Microsoft 365 account so that they can spoof. Wire transfer fraud is a big deal these days. And the reason is is because attackers can get into your Microsoft 365 account, read your emails, spoof your emails, and then pretend to be you with vendors requesting payments and and changing bank account information. and so forth and so on that then lead to that wire transfer fraud. Privilege escalation.
They're looking to increase their access into the environment in order to get to the place where they can do stuff like wire transfer fraud or launch ransomware variants in your environment or even exfiltrate your data. They need to have access to do that. And so privilege escalation is one of their goals. And then lastly, backup destruction. They know that backup that having backups is a way to alleviate your need to pay the ransom.
And so if they can attack your backups, that makes it even more plausible that you're going to have to pay that ransom in order to get your data back because now not only your primary set of data has been encrypted, but also your backup set as well. And in that next session, we'll talk about ways to prevent your backup data from being a victim of a ransomware attack. Restoring from backup used to be the whole answer. Again, it's not anymore. Again, in the initial ransomware attack, your initial data is encrypted.
Because of the dwell time and the work that they do during that dwell time in order to identify your backup, they go and they encrypt that data and exfiltrate it out of your environment. And again this is where the double extortion comes into play because for instance in the situ in the scenario of the Change Healthcare incident their data was exfiltrated out of the environment. If they had had the right countermeasures in place like network monitoring to to show them spikes in data traffic uh outward of their environment they would have known that something was happening and would have been able to stop it in an effective way. But as a result they weren't. and they wound up paying $22 million in order to stop their data from being released into the marketplace because what would have happened is they would have been exposed to regulatory liability as well. So on top of the losses they're dealing with related to the recovery and the ransom.
Now you got to deal with regulatory fines as a result of personal data being released out into the general public. So, what it actually cost to survive an attack, as I talked a little bit about earlier, the average cost is about $4.4 million. As a result, SMBs have seen their or small and medium-sized businesses have seen their insurance premiums rise about 200%. Now, one of the things we did talk about when dealing with insurance companies today is it is no longer a process of checking a box to say you have a firewall or an incident response plan or a malware detection and remediation in place. You now have to prove that.
You now have to show hard evidence that you have these countermeasures in place before you get insured. So the underwriter is going to take you through this due diligence process to make sure that you are doing everything necessary to protect your environment which minimizes your exposure to being a victim and reduces the possibility or potential of the insurance company having to pay out as a result of your negligence. What makes up that that that $4.4 million? Again, the ransom if paid, operational downtime, meaning the loss of productivity, whether you are a manufacturer or service-based business, the forensics and incident response labor. Sometimes that's covered by the insurance company, but it depends on again the nature of the incident.
But there is going to be a cost to have professionals like us come in to conduct an incident response and do digital forensics in order to help you recover from that that that incident. Legal and regulatory notifications. Most municipalities do have on the books, local and state, local county and state I should say. They do have that on the books that require you to make reporting to people who you do business with that may be victimized as a result of the incident. For every day that you don't make reporting, there is a fine or liability that you will incur as a result.
So the other thing you need to do is understand what your regulatory laws and ordinances are in the municipality that your business sits in so that you can make sure that you stay in compliance with it during an incident. And then loss of revenue and reputation. There have been a number of companies that that we've dealt with that have lost business as a result of the experience of a cyber attack. And that's because it's just simply a loss of trust. We don't trust you with our data.
We don't trust you with our business. And so we're going to go somewhere else who to another company that can demonstrate due diligence. What does the business going dark look like? Again, loss of of capability really is what it looks like. loss of ability to deliver services, loss of an ability to produce products, and that can be anywhere from billing and invoicing, a loss of customer records, point of sale where you can't you can no longer conduct financial transactions, credit card transactions, and so forth and so on, which is especially important if you're retail business, emails and comms where you can't talk to your staff. One of the things we talked about in the ransomware, I'm sorry, in the incident response session that we did earlier this year is having a secondary set of communications available, a secondary secure set of communications available so that you can continue to communicate with your employees in a safe way and also with those folks that are participating in the response scheduling and payroll.
And we saw all of these happen in the Lurie's incident and in the Ascension incident and a number of other incidents where they just lost complete functionality and literally had to go back to using paper to run the business. What does the damage do to the business? It's not just the balance sheet that's affected or the P&L that's affected. It's also your reputation. It's a loss of trust.
It's a loss of customers. It's regulatory exposure. Some businesses have ceased to do business as a result of being exposed to these things which can be in a lot of cases much heavier than the incident itself. And one of the things we we bump up against when we are talking to potential customers is this idea that I am too small to be a target of a malicious actor. I'm a little fish in a big pond.
With AI and quantum computing, particularly right now with AI, you are just a fish in a pond. And it's not a matter of if you get attacked, it's a matter of when you get attacked. These things that we're talking about right now, loss of customers, public disclosure, regulatory exposure are all things you're going to be subjected to after the incident. So, as as part of the incident response team that we talked about, crisis management is a necessary component of that team to help you deal with these three aspects of the aftermath of the incident. I talked about insurance quite a bit, but here ransomware is the number one driver of cyber insurance claims today.
That's exactly why insurance companies have changed how they underwrite cyber liability insurance, requiring much more stricter due diligence. And not just the one time you do you take out the policy, but on a recurring basis. You're having to do penetration testing, having to do cyber security assessments and having to demonstrate that on an annual basis in order to continue to remain covered by the insurance company. The the previous slide we showed that ransomware attacks usually begin through one of three entry points and exploit software vulnerability, compromised credentials or phishing email. This slide brings those same three doors forward because effective prevention starts by prevention by practical defenses that you probably already have available to you or can get without a herculean effort to do so.
The message here is that you need to be very proactive in how you manage your IT environment. I mentioned earlier 80% of cyber security related issues are stem from poorly managed IT infrastructure and the other 20% or 15% of that generally comes from attacks on the human being or the social engineering piece that I I mentioned in our last session. If you can get your arms around your IT infrastructure, ensure that you have the right processes and procedures in place to manage things like privilege access management, data storage, uh, and usage. Having the right policies in place and ensuring that your employees know and understand those policies, you can significantly reduce your amount of exposure or the amount that you make these threats viable to your organization in a very significant way. Again, ransomware can be traced directly back to software vulnerabilities.
Patching is one of the most important actions a business can take against ransomware along with managing your IT environment. Ensuring that your software is patched on a regular basis is extremely important because that reduces the vulnerabilities in that software or your risk profile of footprint that can be exposed to the attacker and not everybody does patching right. For instance, Microsoft, of course, the largest software company on the planet, was a victim of what we call a SQL injection attack, probably about about 5 years ago or so. SQL injection attacks have been known to us for about two to three decades now. So, imagine the company that produced the patch to mitigate SQL injection attacks was a victim of that attack on its own.
And that's typically because their infrastructure is just so large. Keeping track of all these endpoints and servers and so forth and so on to ensure that they're patched can be a daunting effort. But it is absolutely necessary because it will help to reduce the vulnerability to cyber attacks down the line. So about 93% of ransomware attacks do target the backup repositories. about 75% of victims lose at least some of their backups in the attack and 39% lose their backup repository entirely. This is a these are statistics that are meant to highlight the importance or the focus that the attacker has on the backup and while attacking the backup is like cutting your legs from underneath you.
There are some strategies to ensure that the attacker can't get to your backups. The primary strategy that we use today is what we call air gapping. And what that basically is is you conducting your backups like you normally would, but then taking those backups offline and disconnected from the network. So you literally have air between your backup and your infrastructure or no connectivity at all so that the attacker cannot get to your your your backups. Back in the day, what we used to do and we used to do this for disaster recovery and when we use tapes for backup when we were using mainframes and mini computers and so forth and so on is those tapes would back up the data.
Those tapes would literally be be shipped off premise to a storage facility to be used in the case of needing a backup or a loss of primary systems and now you need those tapes to recover. We're back there now where we have to create physical separation between our backups and our primary infrastructure to ensure that in the event that we need them, we can get at them. Now, one of the things I will mention is that when you're restoring your systems after an attack, the thing you need to be very mindful of is that what that what you're restoring your systems from doesn't also have those vulnerabilities in the the applications themselves. And so what that means is if you've conducted an image backup of a computer and you stored it away, but then as you go over time and you are updating that software, you're patching it. You're closing vulnerabilities and then you get attacked and now you resort to that backup that you made some time ago, you are in effect reintroducing those vulnerabilities right back into your environment.
And so you need to make sure that your backups stay lockstep with your current with the current state of your system. Also, what one of the things you need to do is to make sure that when you are restoring systems that you're doing everything necessary to ensure that all known vulnerabilities in that image are remediated before that system is put back into production because again of the return to the scene in a crime scenario that I talked about, it'll just make that system vulnerable and susceptible to that threat again. We've talked about some things that you can do in order to keep your environment secure. MFA we spoke about in our last two sessions. MFA is actually one of the number one things or is the number one thing that insurance companies will ask you about and ask you to demonstrate.
MFA is basically multi-factor authentication. It's a process by which the user who is attempting to get access to a an account has to use multi-factor authentication to prove that it is them that's accessing that that account either through something they have something they know or something that they are meaning your fingerprint. uh in that session on in in March we talked about the concept of compartmentalization credential uh account compartmentalization and what that is not repeating the same password for all of your accounts that is generally what an attacker is going to assume that you're doing and if you remember for instance attack scenarios like Ring swatting that was all the rage about two years ago that was simply enabled because victims have been using or reusing their credentials across all of their accounts. And so once they were able to compromise those credentials from one account, they go and test Ring and Amazon and Chase and Citibank and many other major retailer, which you more than likely have an account with to see if you do. And in a lot of cases, you did. And that that made Ring swatting a very viable threat as a result. with MFA.
One of the things I'll certainly suggest and continue to suggest this is that for the secondary authentication step that you never use the same device that you're doing the initial communic authentication on. You always want to use a separate device like a mobile phone or some other separate device, a tablet, another computer to execute that secondary authentication process. Reason being is because if the attacker does not have control over that secondary device, if they try to get into your account, then of course they can't confirm the the the secondary access part of that and so the access is stopped dead in its tracks. So how much time does it does an employee have to recognize and stop a phishing attack? On average, it takes about 21 seconds for someone to click a malicious link and another 20 another 21 seconds, another 28 seconds I should say, to enter credentials on a fake website.
In less than one minute, an attacker has everything they need in order to begin compromising your business. Now, one thing to to be mindful of here, and we see this all the time for small businesses, typically the owner of the business or senior management in the business also have administrative access to the systems that they use on a daily basis like your Microsoft 365 accounts or your Google or your Amazon. And generally if generally and don't mean to be critical but this is again what we see uh quite often owners and senior leaders and business and man managers and directors are some of the worst offenders when it comes to credential management meaning they'll do things like because they're on the run and on the move and might need to respond to this or get access to that. They might log into an account on the device that's not theirs or that is insecure. and as a result become susceptible to a credential attack. You can with the use of training like security awareness training using an application like or a solution like KnowBe4 to help raise the level of vigilance of users to make sure to reduce the impact or the potential of this happening.
Security awareness and training basically causes users to be more mindful of what they're doing on a a regular basis. gives them a way to report suspicious phishing messages, which we see is up these days compared to what it used to be before. That means that trained employees are more than four times as likely to recognize and report a potential threat before it spreads. That's a big deal. In that law enforcement issue I talked about earlier, the user did not report that they had clicked on a link. We found that out by doing our internal triage and traced it back to where it started.
As we see reporting is absolutely necessary. Yes, there might be some repercussions which is generally a fear of an employee reporting but it is absolutely necessary in order to give the IT staff and management the time required in order to respond to the incident. So you built the plan in March that we talked about which looked at isolation or triage, notifying, contacting, and restoring from the the incident. These things need to be solidly built into your plan so that you're not figuring it out on the fly. This is why it's necessary to not only develop your plan before an incident happens, but also to test it on a regular basis to make sure that it works for you.
To pay or not to pay, that is the question. FBI for a very long time has stipulated not to pay because you never know who you're funding by paying. If you're funding a terrorist organization or if you're just uh establishing the viability of the threat itself because now there's money to be made by executing that threat. They have long stipulated that you should not pay. But at the end of the day, it really is a business decision.
And as you've heard in some of the cases that I've shared with you, the ransom compared to the actual cost of recovery. In some of those situations, the ransom was minuscule compared to what they wound up having to spend to recover. In one case, the ransom was $75,000. The cost of recovery was $17 million. What do you think they would have saved by paying a ransom decided not to pay?
So, this is a decision that you have to make. If you're the owner of the business, obviously you have to make that decision based on your your cash flows and so forth and so on. If you have a board in place, this is absolutely something that you need to uh run by your board, but also something that you need to discuss with your insurance company uh uh as well because they may have options in place that might help you to minimize what you might have to pay. And as I mentioned before, the FBI might have capabilities to help you recover from the incident without having to pay at all. But if you're dealing with a situation where data has been exfiltrated, you might that's a different scenario that you're certainly going to have to think about and make sure that you have the right countermeasures in place to prevent that from happening in the first place.
So some of the questions that you should ask, do we have clean and tested backups and are they offline? Is this double extortion? What data do they really have? Do you have the capability to go back and see what data did they actually exfiltrate out of your environment? What does your insurance policy require or authorize you to do?
In some cases, if you make decisions without consulting with your insurance company, that may nullify your policy. So, you should always consult with your cyber liability policy provider first before you make any decisions to make sure that you're going to be covered along the way. Has law enforcement been notified and given guidance? Again, going back to the FBI situation, they might be able to help. So, here's what actually happens when business is paid.
Hi, I'm sorry to interrupt, but there are a couple of questions and I believe Chloe the person that that posed the questions on, but since we're at 3:10, do you want the questions now or to wait? I'm at the the last few slides. So, I can go these. Okay. And then we can get to the questions and I'll go through these quickly.
Okay. So, 49% of businesses still pay the ransom. 65% of data is recovered on average. A third of that data is still lost. 20% of decryption tools fail to decrypt or have corrupt files. So the the encryption process corrupted the files. This is why it's even more important to have those data backups in place and secure it offline to ensure that you can get all of your data back.
And then 55% of companies who paid the ransom once paid again because of the double extortion. So some final guidance here that I'll give you. You've heard me mention this over the time, but I'll reiterate here. Make sure you have your backups in place secure and offline and up to date. If you're backing up from old backups, you're more than likely reinstituting vulnerabilities back into your environment.
Make sure that your insurance that you're lockstep with your insurance. They're going to require you to do the to to do the due diligence necessary to ensure that you're doing everything possible to mitigate these your susceptibility and viability of these attacks, but also you want to get them involved upfront to make sure that you will remain covered while you're in your recovery efforts. And then law enforcement, have they been brought in? Can they support you in your recovery? And a lot of times they won't because obviously they're taxed for resources as well, but they might be able to do things like give you guidance on how to recover from a particular variant or even give you the key as well.
But also reporting helps them to be on notice and to notify others in the industry that there's a trend going on that people are industry cohorts might be want might want to be mindful of. Four things you can do this week. Patching is very easy to do. patches are free, especially if you use Microsoft. Make sure that your backups are up to date and offline. Make sure that you've got MFA turned on all of your endpoints and applications as much as you possibly can and make sure that your plan is update.
This might be a good time to test that plan to ensure that you could you could recover your attack. So, that's that's it for our discussion on ransomware. I'll take those questions now and then afterwards I'll I'll close out with some last thoughts about the upcoming sessions and uh feedback you might want to offer about the program. Okay. Right now there are two questions in the Q&A.
If anyone else has any other questions, please put them in the Q&A and we can get to those as well. So the first one again from Chloe was how much does being plugged into an all- inone SaaS as was the case with the dealership customers of CDK Global increase the risk of these attacks seems a way to head off IT management. Yeah. So that's a great question. There are significant pros and there are significant cons.
Now the pro side fall more on the customers side of that equation in that as I mentioned before using a SaaS-based service alleviates the need for you to have to manage on-prem technology like software and hardware which you have to ensure is secure. You are essentially transferring the responsibility of securing that function to the vendor. So you really don't know what the vendor is doing. You can go through the vendor risk management process and have them show assessments like SOC 2 and CIS and NIST audits and so forth and so on. But at the end of the day, you don't control their operations.
So you're really relying on them to keep your data secure once you forge that relationship with you. There is one thing that you should be mindful of and that is the limits of liability in your contract with the with the vendor. You need to make sure that those limits cover you financially should they wind up affect should an incident that they have wind up affecting your business. I actually I sit on a board of an organization and I recently helped them negotiate higher limits in in the contract limits of liability in the contract that covered the the customer or the the organization whose board I sit on more so than what the vendor was originally willing to do. Those are negotiable and you want to make sure that they are adequate enough to ensure that they protect you financially should they have an incident.
Okay, her follow-up question was, "Do password managers help?" Yeah, I get that question all the time. I'm not such a fan of password managers. I do know the convenience of them, but password managers is another SaaS-based solution that is potentially potentially susceptible to an attack. If you go out to our YouTube site, we do talk about credential management and account compartmentalization, which gives practical password management strategies that uh alleviate you from having to use password managers in order to remember passwords and get access to accounts and so forth. So, I would recommend taking a look at that YouTube video.
It's just five five or six minutes and it outlines a number of strategies that you can use without having to rely on another piece of technology. for for your security. Sonia was ask is asking if she can get a copy of the program and yes, Sonia, you can. It we will be sending out the slides as well as a copy of the recording or you'll have access to a copy of the recording. So, don't worry about that. Those are the the questions that we have right now.
Is anyone else in Oh, Sonia says thank you. Anyone else have another question? Okay, right now that looks like it. And I know you want to get to that last slide. So maybe you can do that now.
We still have a few minutes. Yeah, if you can. So our next session is September 17th. It focuses on what we call the maturity model. It is as we described right cyber security operations for your business.
So we're going to get into what does cyber security operations look like for you? We get this question often. How much should we do? What should we do? How should we do it?
And so we're going to look at we developed this pyramid. our maturity model that outlines based on the maturity of your business, here's where your main focus from a cyber security operations should be. And that'll be on September 7 17th. To help us to continue to improve this series, we're going to offer a a survey that you can take. I think believe it's five or six questions that'll help us to continue to get better at delivering this content to to the audience. And we've already had the questions.
That that's that's all I have for today. Okay. I'm sorry. I'm going to throw one in. You were talking about backup and that's a sensitive topic because people think that they're backing up, but how frequently should they back up?
So, infrastructures are quite complex these days. It's not just how frequently, but it is what also are they backing up mainly their data repositories, their critical devices like their servers and their uh critical endpoints. They should be backing those up at least every other day. And now you can do what's called full backup or incremental or differential backups. Once you do the full backup, then you can go into incremental and differential backup modes, which doesn't do the whole it just backs up the changes that you can do every day.
But it also depends on what your infrastructure looks like. If you have a gigabit network in place that can handle that traffic, if you're if you have up-to-date devices that can handle that traffic. So it really depends on the condition of your infrastructure which will determine how often you should back up but you should definitely be doing it on a regular basis. If not weekly you can do it more frequently than that. So that that would be my recommendation.
Excellent. Okay. I don't see any other questions. So I think that's it for us unless you you have this slide up with questions. Is it is this something you wanted to address?
No, I'm good. But I don't have anything else. Oh, sorry. Let's see what this one says. Oh, okay.
Another final question. What about your personal banking? How do we protect ourselves? Yeah, account account compartmentalization is the best way to go there. So, take a look at that video on our Data Defenders YouTube channel.
It's a five-minute video that talks about how you can create compartmentalization across your online accounts. Typically users today maintain about 40 different online accounts whether they know it or not and most likely they've used the past the same user ID and passwords across all or emails across all those accounts. So using this account credentiing compartmentalization strategy, you can harden your digital life by making it very difficult for a user to get across your account uh set if you will because you've used one set of user IDs, passwords, and emails. So that would be the main strategy that I would look to employ to protect financial accounts is making sure that your credentials are solid, your passwords are are strong, and that you haven't used them in any other accounts that could be susceptible to an attack. Excellent.
Thank you, Cyrus. I really appreciate you're taking the time to do this. This is a critical subject. We hear every day about breaches and we everyone has a question about how do I protect myself and this series is an excellent way to figure out how to protect yourself. Just even if you don't pick up every single top tip, some of them will definitely help or go back and as as Cyrus said, revisit the the recordings because there's a lot of useful information and we can take it in a little bit at a time.
I encourage you to take his next webinar which will be in September and look for the advertisements regarding that. Cyrus, how can people get in touch with you if they want to? They can visit us at data-defenders.com. They can also visit my website at cyrusjwalker.com which has a direct link to me if you have any questions or you can visit us on LinkedIn, Facebook. We do have the whole social media contingent now.
Uh and so th those are the best ways to get in touch with us. Okay. Thank you once again everyone. Remember if you want a mentor go to score.org/chicago, reach out for a mentor or if you'd like to volunteer, you can also go to score.org and volunteer with SCORE. Thanks again, Cyrus.
Really appreciate your time. Thanks you everyone for spending the afternoon or some of your afternoon with us. Have a great rest of your day. Bye.
Key takeaways
- 86% of small-business breaches involve ransomware, compared with 39% at large organizations, and the median ransomware victim had only 228 employees. Attackers see small businesses as low-hanging fruit.
- The ransom is a small part of the bill. The average demand is around $115,000, but the total cost of an incident averages $4.4–5 million once downtime, response, legal notification and lost customers are counted.
- Backups alone are no longer the answer. About 93% of ransomware attacks target backup repositories, so backups need to be air-gapped — physically disconnected from the network — and kept current so a restore doesn’t reintroduce old vulnerabilities.
- Most attacks come through three doors: unpatched software, compromised credentials and phishing. Regular patching, MFA confirmed on a separate device, and security awareness training close most of them.
- Whether to pay is a business decision, not a rule. First check for clean offline backups, confirm what data was stolen, consult your cyber insurer — acting without it can void coverage — and ask the FBI, which may already hold a decryption key.