After last week’s catastrophic cyber incident targeting Colonial Pipeline, could more U.S. Oil and Energy companies be at risk of a ransomware attack?
Bitsight reviewed the cybersecurity performance data we have collected on more than 2,000 of the largest U.S.-based Oil and Energy companies. We find that:
- 62% of these companies are roughly 2X more likely to experience a ransomware attack due to their cybersecurity performance.
- Nearly 100 companies are at least 4.5x more likely to experience a ransomware attack due to their cybersecurity performance.
U.S. Oil and Gas companies should assess their security programs to discover any gaps that could be exploited by attackers, particular with respect to vulnerability management, patching, configuration management, and endpoint security. Bitsight believes that achieving consistently strong security performance is critical for organizations to reduce the risk of experiencing a ransomware event.
Our Methodology
Bitsight reviewed the cybersecurity performance ratings of more than 2,000 Oil and Energy sector companies headquartered in the United States as of April 30, 2021.
Bitsight continuously and non-intrusively assesses organizational cybersecurity performance by evaluating security performance observations across 23 different categories, including compromised and exposed systems, critical vulnerabilities, patching rates, software security, and other key issues. Bitsight processes more than 250 billion security measurements on a daily basis to provide an objective security rating (using a 250-900 scale) based on its observations that is independently verified to be correlated with breach risk.
Weaker Security Performance = Higher Probability of Ransomware
In recent years, the number of ransomware events has increased dramatically, resulting in significant financial losses for global organizations -- according to Aon’s 2020 Cyber Insurance Snapshot, ransomware attacks have increased 486% over the past two years. According to data compiled by the GeoTech Center, the global cost of ransomware attacks soared from $11.5 billion in 2019 to $20 billion in 2020, with the average downtime for an organization rising from 6.2 days to 16.2 days.
Bitsight has collected hundreds of publicly disclosed ransomware incidents affecting organizations over the last several years. We have identified trends, correlations, and other relevant connections between security performance as measured by Bitsight and ransomware probability.