Digital transformation has advanced businesses globally into a new era of efficiency and interconnectedness; but it also has exposed organizations to new levels of risk and network endpoints that require monitoring.
In the past year, ransomware attacks have exploded in frequency, with an overall global increase of 105%, and even greater increases across certain vulnerable industries: government agencies experienced a 1,885% increase in ransomware attacks, and healthcare agencies saw a 755% increase in attacks.
It’s not enough to just monitor your internal attack surface for indicators of ransomware; to effectively mitigate risk of ransomware attacks, it’s imperative to include vendor ransomware risk in your management strategy. Hackers utilizing ransomware are sneaky, and are constantly trying new ways to gain network access with as little trail as possible. This could mean that vendors that are normally low risk could be targets for undetected attacks, or that security performance blips that usually aren’t priority have a greater underlying story.
One of the biggest ransomware attacks on record occurred when software company Kaseya unknowingly downloaded a network update infected with ransomware. The attack had a significant impact throughout Kaseya’s expansive third party network of users, leaving over 1,500 impacted organizations scrambling to decide what to do while their operations were in limbo. The Kaseya attack highlights how just one organization in your supply chain can have costly effects when ransomware is at play.