Ransomware attacks, and ransom payments, are rampant among critical infrastructure organizations
80% of critical infrastructure organizations experienced a ransomware attack in the last year, with an equal number reporting that their security budgets have risen since 2020, a Claroty report reveals.
The report is based on an independent global survey of 1,100 information technology (IT) and operational technology (OT) professionals who work in critical infrastructure sectors, exploring how they have dealt with the significant challenges in 2021, their levels of resiliency, and priorities moving forward.
Of the 80% of respondents who experienced a ransomware attack, 47% reported an impact to their industrial control system (ICS) environment and over 60% paid the ransom, more than half of which cost $500,000 or more. Additionally, the majority of respondents estimated a loss in revenue per hour of downtime to their operations equal to or greater than the payout.
Even among those who did pay the ransom, 28% still experienced substantial impact to operations for more than a week. These findings suggest that, despite the well-known downsides of paying the ransom, the alternative (revenue loss due to prolonged operational downtime) is too costly for most victim organizations to justify.
The report also found that the combination of the ever-accelerating digital transformation and limited availability of skilled cybersecurity workers has resulted in several high-profile attacks on critical infrastructure.
In response, many C-suite executives have become heavily involved in the decision-making and oversight of their organization’s cybersecurity practices. In fact, more than 60% are centralizing both OT and IT governance under the CISO. In addition, 62% are supportive of government regulators enforcing mandatory and timely reporting of cybersecurity incidents that affect IT and OT/ICS systems.
Additional key findings and analysis
- Digital transformation, remote work, and staffing shortages persist: Digital transformation continues to accelerate since the start of the pandemic, as 73% of organizations plan to continue remote/hybrid work in some capacity. Nearly 90% of respondents are looking to hire more OT security staff, but 54% say it is hard to find qualified candidates.
- Gaps in processes and technology remain: While more than 65% rate their organization’s vulnerability management strategy as moderately to highly proactive, ransomware attacks are still highly successful. This could be due to the fact that nearly 30% are sharing passwords, 57% employ usernames and passwords, and only 44% use VPNs – all areas of opportunity to strengthen resilience in OT environments.
- Investments and priorities aimed at building resilience: More than 80% of respondents report that both their IT and OT/ICS security budgets have increased since 2020. The number is close to 90% in industries including IT Hardware, Oil & Gas, and Electric Energy. Implementing new technology solutions is the top cybersecurity priority, with the Oil & Gas and IT Hardware sectors leading the way, and training is second.
“Our research shows that critical infrastructure security is at a pivotal juncture, where threats are proliferating and evolving, but there’s also a growing collective interest and desire in protecting our most essential systems,” said Yaniv Vardi, CEO of Claroty.
“Security leaders looking to take their programs to the next level must account for all cyber-physical systems in their risk governance practices, segmenting their IT and OT networks and assets, extending their general IT cybersecurity practices to their OT devices, and consistently monitoring for threats across all networks.”