Phishing Holds the Top Spot as the Primary Entry Point for Ransomware Attacks
New analysis of ransomware attacks shows that phishing is the primary delivery method and organizations need to offer more effective security awareness training to mitigate the threat.
Hornet Security’s Q3 2024 Ransomware Attacks Survey report paints a pretty bleak picture of how organizations have fared this year against ransomware attacks.
- 18.6% of them have been the victim of an attack
- 16.3% of ransomware victims paid the ransom to recover their data
- 32.6% of ransomware victims were unsure if their data had been exfiltrated during the attack
So almost one in five organizations is a victim. According to the survey data, 52.3% of the attacks started with a phishing email. Hornet notes that phishing is “the most consistent attack vector over the years.”
If you’ve read my articles over the years, you know my answer to this problem – security awareness training. But according to Hornet, 81% of organizations “provide training to end users on how to recognize and prevent ransomware attacks.”
So, what is the problem?
Well, according to the survey, 52% of organizations need more ‘time-friendly’ end-user training.
In other words, the security awareness training needs to be personalized, relevant AND adaptive. And, speaking from experience, not all training is the same. It’s one of the reasons here at KnowBe4 we’ve put so much emphasis into making our training something employees want to keep up to date with.
The data is clear: training is going to be a key part of your organization’s ability to stop ransomware attacks. Just make sure the security awareness training you choose is efficient and effective!
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
RanSim
Free downloadable software tool
Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?
RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.
Here’s how it works:
- 100% harmless simulation of real ransomware and cryptomining infections
- Does not use any of your own files
- Tests 25 types of infection scenarios
- Just download the installer and run it
- Results in a few minutes!
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/ransomware-simulator-tool-partner?partnerid=001a000001lWEoJAAW