Ransomware Detection Time Shortens by 44% as Organizations Attempt to Keep Up with Attackers
New data shows organizations are improving their ability to detect and respond to ransomware attacks, but is it fast enough to make a difference and stop attacks?
The key to stopping a ransomware attack involves speed and efficacy. Organizations need to detect an attack and stop it before data is exfiltrated and/or encrypted.
Cybersecurity vendor Mandiant’s latest M-Trends 2024 report shows that organizations improved their speed of detection (which Mandiant refers to as “Dwell Time,” or the number of days from an attacker being present in the environment to detection) from 9 days in 2023 to just 5 days in 2023. That’s a 44% improvement for organizations.
But we also saw another “dwell time” stat – this one from last October citing that ransomware threat actors only take an average of 1 day from initial access to encryption.
So, it’s great that organizations are detecting ransomware attacks more quickly. But is it enough? If threat actors are completing their attacks in 1/5th the time, is detection something to even boast about? What’s not so obvious is, when you dig into the report’s data, you find that 55% of attacks took more than a week to detect.
The real answer here is to prevent attacks in the first place. By the time detection even happens, threat actors have completed their attack and may have “left the building.” Through new-school security awareness training, organizations can stop phishing and social engineering-based attacks by educating users on common techniques, helping to elevate the employee’s understanding of such attacks and the need for continual vigilance when interacting with email and the web.
KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Free Ransomware Simulator Tool
Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?
KnowBe4’s “RanSim” gives you a quick look at the effectiveness of your existing network protection. RanSim will simulate 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.
Here’s how it works:
- 100% harmless simulation of real ransomware and cryptomining infections
- Does not use any of your own files
- Tests 25 types of infection scenarios
- Just download the install and run it
- Results in a few minutes!
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/ransomware-simulator-tool-partner?partnerid=001a000001lWEoJAAW