{"id":15439,"date":"2024-02-13T17:03:34","date_gmt":"2024-02-13T16:03:34","guid":{"rendered":"https:\/\/telecomkh.info\/?p=15439"},"modified":"2024-02-13T17:03:34","modified_gmt":"2024-02-13T16:03:34","slug":"cohesity-research-reveals-majority-of-aussie-companies-pay-millions-in-ransoms-breaking-their-do-not-pay-policies","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=15439","title":{"rendered":"Cohesity research reveals majority of aussie companies pay millions in ransoms, breaking their \u2018Do Not Pay\u2019 policies"},"content":{"rendered":"<p><strong>Majority of companies unable to recover their data and restore their business processes within three days<\/strong><\/p>\n<p>Research commissioned by Cohesity, a leader in AI-powered data security and management, reveals pervasive cyberattacks are forcing the majority of companies to pay ransoms and break their \u2018do not pay\u2019 policies, with data recovery deficiencies compounding the problem. The research polled from over 300 Australian IT and Security decision-makers shows that companies firmly operate in a \u2018when\u2019, not \u2018if\u2019, reality of cyberattacks. In fact, most companies have paid a ransom in the last two years, and the vast majority expect the threat of cyberattacks to increase significantly in 2024 compared to 2023.<br \/>\nAlarmingly, almost 3 in 4 (72%) respondents said their company had been the \u2018victim of a ransomware attack\u2019 between June and December. The cyber threat landscape is expected to get even worse in 2024, with over 99% of respondents saying the threat of cyberattacks to their industry will increase this year and 7 in 10 (70%) predicting it will increase by more than 50%.<br \/>\nOrganisations\u2019 attack surfaces are defined by the size and scope of their data environments. However, 88% of respondents said their data security risk has now increased faster than the growth in the data they manage. Respondents also believe organisations\u2019 cyber resilience and data security strategies are not keeping up with the current threat landscape, with less than 1 in 4 (24%) having full confidence in their company\u2019s cyber resilience strategy and its ability to \u2018address today\u2019s escalating cyber challenges and threats\u2019.1<\/p>\n<p><strong>Slow Data Recovery &amp; Lack of Cyber Resilience Results Ransom Payments<\/strong><br \/>\nCyber resilience is a technology backbone for business continuity. It defines companies\u2019 ability to recover their data and restore business processes when they suffer a cyberattack or adverse IT event. However, according to respondents, every company has cyber resilience and business continuity challenges:<\/p>\n<p>\u2022 No respondent said they could recover data and restore business processes within 24 hours<br \/>\n\u2022 Just 4% said their company could recover data and restore business processes within 1-3 days<br \/>\n\u2022 26% said they could recover in 4 to 6 days, and 42% need 1-2 weeks to recover<br \/>\n\u2022 Alarmingly, 28% need over 3 weeks to recover data and restore business processes<\/p>\n<p>Further demonstrating cyber resilience gaps, just 14% said their company had stress-tested their data security, data management, and data recovery processes or solutions in the six months prior to being surveyed, and 50% had not tested their processes or solutions in over 12 months or at all.<br \/>\nUnsurprisingly, 92% of respondents said their company would pay a ransom to recover data and restore business processes, while 6% said \u2018maybe, depending on the ransom amount.\u2019 Almost 2 in 3 (64%) said their company would be willing to pay over US$3 million to recover data and restore business processes, with 27% of respondents saying their company would be willing to pay over US$5 million.<br \/>\nThe research also showed the importance of being able to respond and recover, as 81% said their organisation had paid a ransom in the prior two years, despite 73% saying their company had a \u2018do not pay\u2019 policy.<br \/>\n\u201cOrganisations can\u2019t control the fact they face an increasing volume, frequency, and sophistication of cyberattacks like ransomware. What they can control is their cyber resilience, which is the ability to rapidly respond and recover from cyberattacks or IT failures, by adopting modern data security capabilities,\u201d said Michael Alp, Managing Director, Cohesity Australia &amp; New Zealand. \u201cIt\u2019s probably no surprise that the majority of Australian respondents said their company has been hit by cyberattacks in the past six months. However, what is alarming is that over 8 in 10 have paid a ransom, breaking their \u2018do not pay\u2019 policies, and most are willing to pay over US$3 million in ransoms \u2013 often because they can\u2019t recover their data and restore business processes, or do so fast enough.\u201d<\/p>\n<p><strong>Executive Management Should Be Accountable &amp; Aligned<\/strong><br \/>\nRespondents identified executive awareness and responsibility for data security as two areas for companies to improve, with just 36% saying their senior and executive management fully understands the \u2018serious risks and daily challenges of protecting, securing, managing, backing up, and recovering data.\u2019 Three in four said executive management (C-Level) and boards should share the responsibility for their company\u2019s data security strategy, while 68% said their company\u2019s CIO and CISO, in particular, could be better aligned.<br \/>\nPrioritising their biggest concerns about a successful data breach or cyberattack, respondents selected a drop in share price \/ investment \/ profitability (36%), brand and reputational damage (34%), a loss of stakeholder trust (31%), and a direct hit to revenue (30%). When asked who is most impacted by a data breach or cyberattack, respondents said existing customers (30%), the IT team (29%), third-party partners (28%), and employees (27%). Interestingly, only 25% of Australian respondents said the \u2018Security team\u2019 compared to respondents globally who had the \u2018Security team\u2019 ranked first alongside customers at 29%.<br \/>\n\u201cCyber resilience and data security should be a holistic organisational priority because the use of data and technology occurs in every function by every employee. The severe impact of a successful cyberattack or data breach on business continuity, revenue, brand reputation, and trust is enough to keep any business, IT, and Security leader awake at night,\u201d said Alp. \u201cTo rapidly respond to and recover from cyberattacks, organisations need modern AI-powered data security and management solutions that protect their data, detect when it is under attack, and recover it as fast as possible to restore their business processes.\u201d<\/p>\n<p><strong>Regulation Isn\u2019t Driving Companies\u2019 Cyber Resilience &amp; Data Security Best Practices<\/strong><br \/>\nDespite governments and public institutions going to great lengths to encourage stronger cybersecurity and data management, just under half (49%) of respondents said government initiatives, legislation, and regulations are actually driving their companies\u2019 data security, data management, or data recovery initiatives. Of the respondents that said specific government initiatives, legislation, and regulations are driving their data security, management, and recovery approaches, close to 1 in 4 (23%) named these specifically as the most influential:<\/p>\n<p><strong>Australia:<\/strong><br \/>\n1. Privacy Act 1988<br \/>\n2. Digital Transformation Agency Guidelines<br \/>\n3. Office of the Australian Information Commissioner\u2019s Notifiable Data Breach (NDB) Scheme<\/p>\n<p>\u201cIt may seem surprising that more than 1 in 2 respondents said government efforts and policies aren\u2019t driving their companies\u2019 data security, management, and recovery initiatives. However, organisations should not be basing their entire data security, risk, management, or recovery strategy around a set standard or compliance framework,\u201d said Alp. \u201cWhile organisations should certainly adhere to legislation, regulation, and standards, these should be seen as a starting point or baseline. The security risks to a company\u2019s data and operational continuity should be what drives their data management, security, and recovery practices.\u201d<\/p>\n<p><strong>About the survey:<\/strong><br \/>\nThe findings are based on a survey of 902 IT and Security decision-makers (split as close to 50:50 as possible) commissioned by Cohesity and conducted by Censuswide. Survey respondents were polled from businesses in Australia (301), the United Kingdom (300), and the United States (301). The top five industries selected by Australian respondents as best representing the industry their company operates in were: Finance, IT &amp; Telecommunications, Education, Manufacturing &amp; Utilities.<\/p>\n<p><span style=\"color: #999999;\"><em>Above, image credited to Cohesity<\/em><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Majority of companies unable to recover their data and restore their business processes within three days Research commissioned by Cohesity, a leader in AI-powered data security and management, reveals pervasive cyberattacks are forcing the majority of companies to pay ransoms and break their \u2018do not pay\u2019 policies, with data recovery deficiencies compounding the problem. The &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=15439\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abCohesity research reveals majority of aussie companies pay millions in ransoms, breaking their \u2018Do Not Pay\u2019 policies\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":15440,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/15439"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15439"}],"version-history":[{"count":1,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/15439\/revisions"}],"predecessor-version":[{"id":15441,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/15439\/revisions\/15441"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/15440"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}