SYDNEY, AUS.ย โ July 3, 2023 โย Sophos, a global leader in innovating and delivering cybersecurity as a service, today announced a new sectoral survey report, โThe State of Ransomware in Manufacturing and Productionย 2023,โ which found that in more than two-thirds (68%) of ransomware attacks against this sector, the adversaries successfully encrypted data. This is the highest reported encryption rate for the sector over the past three years and is in line with a broaderย cross-sector trendย of attackers more frequently succeeding in encrypting data.
However, in contrast to other sectors, the percentage of manufacturing organisations that used backups to recover data has increased, with 73% of the manufacturing organisations surveyed using backups this year versus 58% in the previous year. Despite this increase, the sector still has one of the lowest data recovery rates.
โUsing backups as a primary recovery mechanism is encouraging, since the use of backups promotes a faster recovery. While ransom payments cannot always be avoided, we know from our survey response data that paying a ransom doubles the costs of recovery,โ said John Shier, field CTO, Sophos. โWith 77% of manufacturing organisations reporting lost revenue after a ransomware attack, this added cost burden should be avoided, and priority placed on earlier detection and response.โ
In addition, despite the growing use of backups, manufacturing and production reported longer recovery times this year. In 2022, 67% of manufacturing organisations recovered within a week, while 33% recovered in more than a week. This past year, only 55% of manufacturing organisations surveyed recovered within a week.
โLonger recovery times in manufacturing are a concerning development. As we’ve seen in Sophos’ย Active Adversary reports, based on incident response cases, the manufacturing sector is consistently at the top of organisations needing assistance recovering from attacks. This extended recovery is negatively impacting IT teams, where 69% report that addressing security incidents is consuming too much time and 66% are unable to work on other projects.โ
Sophos provides a look at a large-scale ransomware attack against a manufacturing company in its newly released three-part โThink You Know Ransomware?โ documentary series.ย In episode 2, Sophos interviews the chief information security officer of Norsk Hydro, a major aluminum production company, to learn about the aftermath and investigation of the attack against the company.
Sophos experts recommend the following best practices for organisations in manufacturing and across all other sectors:
- Strengthen defensive shields with:
- Security tools that defend against the most common attack vectors, includingย endpoint protectionย with strong anti-exploit capabilities to prevent exploitation of vulnerabilities, andย Zero Trust Network Accessย (ZTNA) to thwart the abuse of compromised credentials
- Adaptive technologies that respond automatically to attacks, disrupting adversaries and buying defenders time to respond
- 24/7 threat detection, investigation and response, whether delivered in-house or by a specialistย Managed Detection and Responseย (MDR) provider
- Optimise attack preparation, including making regular backups, practicing recovering data from backups and maintaining an up-to-date incident response plan
- Maintain good security hygiene, including timely patching and regularly reviewing security tool configurations
To learn more about the State of Ransomware in Manufacturing and Production, download the full report fromย Sophos.com.
The State of Ransomware 2023 survey polled 3,000 IT/cybersecurity leaders in organisations with between 100 and 5,000 employees, including 363 organisations in manufacturing and production, across 14 countries in the Americas, EMEA and Asia Pacific.
— END
Learn More About
- The State of Ransomware 2023
- Attacker behaviors, techniques and tactics in theย 2023 Active Adversary Report for Business Leaders,ย based on an analysis of Sophos incident response cases
- IT and cybersecurity leadersโ top challenges and priorities in โThe State of Cybersecurity 2023: The Business Impact of Adversaries on Defendersโ
- Different ransomware threat actors, their TTPs and Sophosโ latest ransomware research in theย Ransomware Threat Intelligence Center
- The threat landscape and trends likely to impact cybersecurity in theย 2023 Threat Report
- Sophos X-Ops and its groundbreaking threat researchย by subscribing to theย Sophos X-Ops blogs
About Sophos
Sophos is a worldwide leader and innovator of advanced cybersecurity solutions, including Managed Detection and Response (MDR) and incident response services and a broad portfolio of endpoint, network,ย email, and cloud security technologies that help organisations defeat cyberattacks. As one of the largest pure-play cybersecurity providers, Sophos defends more than 500,000 organisations and more than 100 million users globally from active adversaries, ransomware, phishing, malware, and more. Sophosโ services and products connect throughย itsย cloud-based Sophos Central management console and are powered byย Sophos X-Ops, the companyโs cross-domain threat intelligence unit. Sophos X-Ops intelligence optimises the entire Sophos Adaptive Cybersecurity Ecosystem, which includes a centralised data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity and information technology vendors. Sophos provides cybersecurity-as-a-service to organisations needing fully-managed, turnkey security solutions. Customers can also manage their cybersecurity directly with Sophosโ security operations platform or use a hybrid approach by supplementing their in-house teams with Sophosโ services, including threat hunting and remediation. Sophos sells through reseller partners and managed service providers (MSPs) worldwide. Sophos is headquartered in Oxford, U.K. More information is available atย www.sophos.com.