...
Skip to content

Businesses try to keep pace with hackers

Businesses may be running a race they ultimately cannot win as criminal hackers stay one step ahead in developing ransomware, but they can minimize their risk. 

The incidence of ransomware has become much more prevalent in recent months, while monetary demands have multiplied, observers say.

The issue may be further exacerbated by the recent increase in employees working from home during the COVID-19 pandemic, who may be using systems less secure than those in their offices. 

Hackers are becoming increasingly sophisticated as well as more targeted in their ransomware attacks, experts say, in some cases quietly penetrating and assessing businesses’ computers, including backup plans, long before they even make their presence known. 

Still, businesses can take steps to minimize if not eliminate their ransomware risk (see related story). 

Meanwhile, cyber liability insurers continue to offer ransomware coverage as an integral part of their policies, although there has been some discussion of introducing ransomware sublimits. (see related story). 

Beazley PLC said in a March report that reported ransomware attacks against its clients increased 131% in 2019, with the sums demanded increasing exponentially. 

Experts characterize ransomware attacks as falling into two general categories: The first is the more established “smash and grab” approach, in which cyber criminals hit a large number of easily penetrated companies and threaten to block access to their files unless they pay relatively small sums of money. 

The second approach, which is often used against more sophisticated, larger companies, is where hackers conduct reconnaissance on a firm’s system, learn as much information as they can, penetrate their backup systems, investigate through U.S. Securities and Exchange Commission filings their finances, and then make a ransomware demand calibrated to how much they can reasonably expect the company to pay. 

Ransomware “is becoming more of a problem because it’s happening far more often than it has in previous years,” said Brad Gow, Purchase, New York-based cyber product leader for Sompo International Holdings Ltd. 

Two or three years ago, ransomware was spread randomly, but “today, the bad guys have really gotten more serious about it, and they’re using phishing attacks or (remote desktop protocol) attacks to get into a network and spend three or four weeks escalating privileges, mapping everything out, understanding where the critical systems and backups are” before launching their attack, he said. 

Criminals target businesses that rely heavily on data and observe systems so they understand how that data is backed up and secured before they launch an attack, said Michael Born, senior vice president and cyber liability product leader at Berkley Re Solutions, a W.R. Berkley Corp. unit, in Overland Park, Kansas. 

Michelle Chia, New York-based head of professional liability and cyber for Zurich North America, noted that more people are now working from home, and “the home networks are not necessarily as secure as the ones in offices, and so those are situations that malicious actors can leverage.”

In some cases, more pressure is being placed on target companies. “Malicious actors have raised the bar. They’ve included a time element, which creates a sense of urgency,” Ms. Chia said. They demand ransom payment within a few hours under the threat of releasing sensitive records, she said. 

Some hackers threaten to reveal the identity of organizations that have been hacked, which could have a reputational impact on their business, although the threat’s effect has diminished as more companies become ransomware victims, said Dan Burke, San Francisco-based national cyber practice leader for Woodruff Sawyer & Co.? 

Prime targets

While every company is vulnerable, small to medium-sized enterprises are favorite targets. These are firms “big enough to be worth stealing from, but not big enough to have a dedicated (IT) staff,” Mr. Gow said.

“Those types of organizations tend to be less sophisticated and therefore the bad actors are looking at these organizations as more the low-hanging fruit in terms of looking to get that pay day out of a ransomware attack,” said Stephanie Snyder, senior vice president, commercial strategy leader-cyber solutions, in Chicago for Aon PLC. 

Managed service providers, companies that remotely manage customers’ IT infrastructure, are also favorite targets “because when (hackers) successfully attack an MSP, they can affect hundreds of thousands of organizations, so it’s sort of a one-stop shop,” said John Farley, managing director of the cyber liability practice for Arthur J. Gallagher & Co. in New York. 

Most ransom demands are for $100,000 or $150,000, “but there’s an increasing frequency of reports where hackers are demanding seven figures,” said Matthew McCabe, general counsel on cyber policy for Marsh LLC. 

Companies often conclude it is wise to pay the ransomware. While the FBI recommends against it, “in some cases it’s the most direct and reasonable method for a problem to go away,” so “it’s done very much on a case by case basis,” Mr. Gow said. 

“It depends on what is best for your business,” Mr. Born said. “If you’re looking at, in essence, going out of business, or losing a lot” from a ransomware attack, then paying it “might be the best business decision.” 

Even if companies pay the ransom, typically in cryptocurrency, it may take at least several days to return to full operation, experts say. 

“There is absolutely still a large delay in recovering and getting back to normal even after” the key is returned, which is “where business interruption (coverage) comes into play,” said Marcin Weryk, New York-based head of cyber-West and South at Axa XL, a unit of Axa SA. He said the “vast majority” of hackers provide the key once the ransomware is paid. 

Recovery time is directly proportional to the data, its complexity and the number of autonomous systems and hosts that make up an integrated system, said C.J. Dietzman, Charlotte, North Carolina-based managing director of Aon Cyber Solutions. 

Refuse to pay

Meanwhile, more companies that are confident about their backups are refusing to pay. “About half of ransomware demands are being paid. The other half have backups and are choosing not to pay,” said Anthony Dagostino, New York-based global cyber and technology practice leader for Lockton Cos. LLC. 

“Those that do choose to pay are able for the most part to negotiate the demand down, so that does help,” he said. 

“We’ve been seeing more and more companies taking the position they’re not willing to pay ransom, and that’s a decision insurance carriers leave to the business,” said Kelly Castriotta, Chicago-based head of product development and North American cyber underwriting lead for Allianz Global Corporate & Specialty SE, financial lines, North America. Companies are in a better position to do so if they have business continuity and incident response plans, she added. 

Stopping the ransomware perpetrators can be hard because many are in eastern Europe, where they are not vigorously pursued by their governments, experts say. 

“They’re outside the reach of the FBI and any U.S. enforcement,” Mr. Gow said. 

Criminals will probably always be one step ahead, experts say. “That’s the story of cybersecurity, and it always has been,” Mr. McCabe said. “The ultimate question is, are we keeping pace with the sophistication of the hackers, or are we closing the gap?”

More insurance and risk management news on the coronavirus crisis here.