Bookkeeping Service Providers

  • Accounting
  • Bookkeeping
  • US Taxation
  • Financial Planning
  • Accounting Software
  • Small Business Finance
You are here: Home / IOT / The real cost of ransomware: Protect yourself from cyberattack fallout

The real cost of ransomware: Protect yourself from cyberattack fallout

April 22, 2020 by cbn Leave a Comment

Ransomware remains the most common malware threat to small and medium-sized enterprises (SMEs). In the first half of last year alone, 61% of managed service providers (MSPs) reported attacks against their clients, sometimes multiple attacks in a single day.

At the same time, says Ryan Weeks, CISO at Datto, a recent survey of over 150 European MSPs reported that two in five SMEs had fallen victim to ransomware.

Ransomware report

Published annually, Datto’s European State of the Channel Ransomware report examines the threat from the perspective of the IT Channel and their SME clients – and it reveals that ransomware is impacting businesses more than ever before. Tracked year-on-year, the average ransom demanded by cybercriminals has increased, and is now around £2,000 (€2,274).

While this figure might come as a nasty shock to affected businesses, it is, however, in the aftermath of the attack when the real nightmare begins. Ransomware causes system downtime, and the downtime related to such attacks is also quickly increasing. It is up by 300% in Europe, while the global average is 200%.

Even more of a concern, system downtime from ransomware is hitting small organisations harder than their bigger counterparts. Currently, such attacks cost European businesses around £108,000 (€123,000) on average per incident, an eye-watering 54 times more than the ransom requested.

Lost productivity

And that is not all. More than half of the MSPs surveyed say their clients suffered a loss of business productivity after a ransomware attack, alongside lost data or devices and decreased client profitability (33%). One in five businesses admitted ransomware had damaged their reputation, with further repercussions down the line. What’s more, in a third of attacks the infection spread to other devices on the network – and in some cases, it even remained on the network and struck again.

It’s not surprising then that over half of MSPs think the devastating effects of a ransomware attack have the potential to bankrupt entire companies.

Reliance on workable back-ups

Ryan Weeks

While recovery is possible – and paying the ransom is not recommended – the ability to restore systems quickly relies on valid and workable system back-ups. Since it can be difficult to pinpoint the source of a threat or how long it has been in an IT environment, MSPs usually rely on a multitude of methods to help their clients recover.

These methods typically include reimaging the server, virtualising the system from a back-up image and running clean-up software. Every organisation, no matter how small, should have a robust remediation plan in place.

Here are nine steps every business should take to minimise its risks of being critically affected by ransomware.

  1. First of all, understand the threat and take it seriously: Datto’s survey found a staggering disconnect between MSPs and SMEs: 82% of MSPs are ‘very concerned’ about ransomware but only 8% reported that their SME clients feel the same, despite the business-threatening downtime implications.
  2. Be wary of phishing emails: These are still the leading cause of successful attacks (65%), followed by a lack of security training and weak passwords or poor access management. Poor user practices could be your weakest link, so educate all employees on how to deal with suspicious emails or websites. Training must be regular and mandatory.
  3. Consider two-factor authentication: Strong identity and access management reduces the risk of intruders.
  4. Review your patching practices: Fixing known security vulnerabilities should be the number one priority, so install patches as soon as they are released.
  5. Don’t rely on your defences: Clients regularly fall victim to ransomware despite having antivirus software, email filters and endpoint detection. These traditional solutions are an essential part of any security programme, but on their own they are not enough.
  6. Agree a business continuity and disaster recovery (BCDR) strategy: To minimise downtime, focus on how to maintain operations during and after an attack. A reliable BCDR solution that creates regular system back-ups is part of that strategy and the most effective tool to combat ransomware. Two in three MSPs reported that victims with a BCDR solution recovered from their attack in 24 hours or less.
  7. Remember your cloud is at risk, too: One in five MSPs reported ransomware attacks in SaaS applications such as Office 365 and Dropbox. Since ransomware is designed to spread across networks and applications, endpoint and SaaS back-up solutions for fast restores are critical.
  8. Outsource your IT: Strategy Analytics found that SMEs who don’t outsource are at greater risk from attacks. If you cannot afford full-time, qualified IT staff for 24/7 cyber security monitoring, use an MSP who has the resources to anticipate, and react to the latest threats.
  9. Choose your MSP carefully: MSPs are now also becoming targets of ransomware attacks. Make sure your MSP can implement a solid disaster recovery plan for all eventualities. Check if they have cyber liability insurance, and if they can fall back on external expertise in the event of a large-scale attack that affects both them and their clients.

Nine in ten MSPs predict the ransomware threat is only going to increase – and Internet of Things (IoT) devices and social media accounts will be among the next targets. Act now, and be prepared.

The author is Ryan Weeks, chief information & strategy officer at Datto.

Comment on this article below or via Twitter: @IoTNow_OR @jcIoTnow

Share on FacebookShare on TwitterShare on Google+Share on LinkedinShare on Pinterest

Filed Under: IOT, SECURITY

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • May 2021
  • April 2021
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • March 2016

Recent Posts

  • FabCon Vienna: Build data-rich agents on an enterprise-ready foundation
  • Agent Factory: Connecting agents, apps, and data with new open standards like MCP and A2A
  • Azure mandatory multifactor authentication: Phase 2 starting in October 2025
  • Microsoft Cost Management updates—July & August 2025
  • Protecting Azure Infrastructure from silicon to systems

Recent Comments

    Categories

    • Accounting
    • Accounting Software
    • BlockChain
    • Bookkeeping
    • CLOUD
    • Data Center
    • Financial Planning
    • IOT
    • Machine Learning & AI
    • SECURITY
    • Uncategorized
    • US Taxation

    Categories

    • Accounting (145)
    • Accounting Software (27)
    • BlockChain (18)
    • Bookkeeping (205)
    • CLOUD (1,321)
    • Data Center (214)
    • Financial Planning (345)
    • IOT (260)
    • Machine Learning & AI (41)
    • SECURITY (620)
    • Uncategorized (1,284)
    • US Taxation (17)

    Subscribe Our Newsletter

     Subscribing I accept the privacy rules of this site

    Copyright © 2025 · News Pro Theme on Genesis Framework · WordPress · Log in