Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Anti-Ransomware Day: promoting  best practices for prevention and response (Page 13)
Cyber resilience

Anti-Ransomware Day: promoting  best practices for prevention and response

May 12, 20258 Mins Read
A concept of a ransomware attack created out of numerals.

May 12th is Anti-Ransomware Day, established in 2020 by INTERPOL to commemorate the anniversary of the WannaCry ransomware attack that occurred on May 12, 2017. The purpose of Anti-Ransomware Day is to promote best practices for prevention and response.

To highlight Anti-Ransomware Day, Resilience Forward is highlighting resources published to support the event as well as asking various industry experts for their take on the current state of ransomware and resilience.

Kaspersky presents its annual report on the evolving global and regional ransomware cyberthreat landscape

Kaspersky was one of the original Anti-Ransomware Day supporters and has used the 2025 event to publish its annual State of Ransomware Report.

Current and emerging ransomware trends highlighted in the report include:

  • AI tools were increasingly used in ransomware development, as demonstrated by FunkSec, a ransomware group that emerged in late 2024 and quickly gained notoriety by surpassing established groups like Cl0p and RansomHub with multiple victims claimed in December alone. Operating under a Ransomware-as-a-Service (RaaS) model, FunkSec employs double extortion tactics – combining data encryption with exfiltration – targeting sectors such as government, technology, finance, and education in Europe and Asia. The group’s heavy reliance on AI-assisted tools sets it apart, with its ransomware featuring AI-generated code, complete with flawless comments, likely produced by Large Language Models (LLMs) to enhance development and evade detection. Unlike typical ransomware groups demanding millions, FunkSec adopts a high-volume, low-cost approach with unusually low ransom demands, further highlighting its innovative use of AI to streamline operations.
  • The RaaS (ransomware-as-a-service) model remains the predominant framework for ransomware attacks, fuelling their proliferation by lowering the technical barrier for cybercriminals. In 2024, RaaS platforms like RansomHub thrived by offering malware, technical support and affiliate programs that split the ransom. This model enables less-skilled actors to execute sophisticated attacks, contributing to the emergence of multiple new ransomware groups in 2024 alone.
  • In 2025, ransomware is expected to evolve by exploiting unconventional vulnerabilities, as demonstrated by the Akira gang’s use of a webcam to bypass endpoint detection and response systems and infiltrate internal networks. Attackers are likely to increasingly target overlooked entry points like IoT devices, smart appliances or misconfigured hardware in the workplace, capitalizing on the expanding attack surface created by interconnected systems. As organizations strengthen traditional defences, cybercriminals will refine their tactics, focusing on stealthy reconnaissance and lateral movement within networks to deploy ransomware with greater precision, making it harder for defenders to detect and respond in time.
  • The proliferation of LLMs tailored for cybercrime will further amplify ransomware’s reach and impact. LLMs marketed on the dark web lower the technical barrier to creating malicious code, phishing campaigns and social engineering attacks, allowing even less skilled actors to craft highly convincing lures or automate ransomware deployment. As more innovative concepts such as RPA (Robotic Process Automation) and LowCode, which provide an intuitive, visual, AI-assisted drag-and-drop interface for rapid software development, are quickly adopted by software developers, we can expect ransomware developers to use these tools to automate their attacks as well as new code development, making the threat of ransomware even more prevalent.
Read the report

Ransomware and resilience: comments from industry experts

The following comments have been provided to Resilience Forward for Anti-Ransomware Day.

Darren Thomson, Field CTO  EMEAI, Commvault

“Ransomware attacks continue to escalate year after year, and cybercriminals are no longer just chasing payouts – they’re hunting for headlines. Recent attacks targeting high-profile organizations and critical supply chains show a clear shift in strategy: aiming for maximum disruption and publicity by targeting the ‘big fish’.

“Recent research found that cyberattacks are costing UK businesses £64 billion a year, accumulated across ransom payments, lost business, and other related costs. Yet, despite the rising threat, too many organizations remain underprepared. True cyber resilience means more than just defence, it also requires the ability to recover fast. This is where tools such as cleanroom environments come in. By restoring critical cloud services in a secure, isolated space and using automation to speed up recovery, companies can minimise downtime. While recovery takes 24 days on average, some organizations don’t achieve business-as-usual for over 200, often due to poor preparation and a lack of understanding of their ‘minimum viable company’ – the essential systems needed to stay operational.

“But resilience isn’t just a concern for businesses. Individuals must also take responsibility for their cybersecurity. Consumers should start by evaluating their own situation: Could you manage without Internet access? Do you have a backup plan if payment terminals go down?

“Taking practical steps like using secure password managers, avoiding password reuse, and steering clear of public Wi-Fi without a VPN are essential. On Anti-Ransomware Day, it’s time for both businesses and consumers to assess their cyber resilience.” 


Glenn Akester, Technology Director for Cyber Security & Networks, Node4        

“Ransomware remains a serious and evolving threat for UK mid-market businesses. With ransomware-as-a-service widely available, launching an attack no longer requires deep technical skill, just intent. At the same time, threat actors are starting to use AI to accelerate and adapt their tactics, from crafting more convincing phishing emails to mutating ransomware code in real time to bypass detection. This constant variation is making traditional, signature-based defences less effective, particularly for organizations without dedicated cyber teams.

“In this environment, resilience isn’t just about technology, it’s about preparedness. Defending against ransomware means getting the basics right – timely patching, strong endpoint protection, access control, and real-time monitoring to spot unusual activity. It’s not about adding more tools, but making sure existing ones are well managed, integrated, and focused on reducing risk rather than ticking compliance boxes.

“Backups play a critical role, but they’re a last line of defence. If ransomware gets through, the speed and reliability of your recovery is what prevents a security incident from escalating into a full-blown operational crisis. Increasingly, attackers are targeting backup environments directly, knowing they’re often the last lifeline for compromised organizations. That’s why they must be secure by design – immutable, segregated from live systems, and regularly tested. A backup that fails under pressure isn’t really a backup at all. Mitigation and recovery processes should be robust, rehearsed, and clearly owned across the organization.

“Worryingly, recent research has revealed that cybersecurity ranks only 7th among strategic priorities for both business leaders and IT professionals, with protection from ransomware and malware ranking below 10th among cybersecurity priorities. This Anti-Ransomware Day is a good moment to review your current posture. Are your defences keeping pace with the threat? Could you recover under real-world pressure? In today’s threat landscape, resilience can’t be assumed, it needs to be designed, tested, and maintained. Now is the time to close the gaps.”             


Shobhit Gautam, Staff Solutions Architect, EMEA, HackerOne 

“Ransomware continues to be the most common ‘end game’ that cybercriminals are working towards. Already, ransomware attacks reached a record high in March 2025, with criminals focusing their attacks on key sectors such as healthcare, retail, and manufacturing. These attacks may be increasing due to the growing reliance on digital systems within these industries, along with the higher use of third-party components and inadequately protected legacy systems, compounded by reduced funding for security measures.

“With the decentralization of the ransomware ecosystem, we are now witnessing a rise in ransomware attacks. Initial Access Brokers (IABs) and ransomware-as-a-service (RaaS) continue to be significant concerns for organizations. The accessibility of ransomware tools and the capabilities of AI mean that criminals no longer need an in-depth knowledge of programming or hacking to launch these attacks.

“The deepening role of artificial intelligence in the technology industry is leading to an AI arms race between security teams and cybercriminals. With more than 50% of security researchers saying so, it is vital that businesses take the necessary steps to reduce the ransomware threat.

“One of the most successful ways to counter the risk of ransomware is to adopt crowdsourced security. Bug bounty programs incentivise security researchers to highlight any weaknesses and potential vulnerabilities in businesses’ defences and can provide support to mitigate these threats. Working with security researchers is a critical step in identifying and fixing vulnerabilities before malicious actors can exploit them.”


Jakub Lewandowski, Associate General Counsel EMEA, Commvault

“Paying a ransom is a dangerous move – there’s often no guarantee that the criminals behind the attack will deliver the outcome they’ve promised, so in doing so, an organization is playing right into their hands. The more victims who pay, the more criminals will continue to attack – why wouldn’t they? And with research revealing that 78% of organizations who paid a ransom demand were hit by a second ransomware attack, there’s strong evidence to suggest that it makes them more of a target in future.

“Bans on paying ransoms could, if properly enforced, put a halt to this lucrative criminal business, which is only becoming more commonplace with the rapid rise in AI technology. If all public sector and critical infrastructure organizations are legally prevented from paying, then it makes them a less attractive target.

“In the meantime though, these organizations would need to be better prepared to prevent and recover from attacks, as they won’t have the failsafe option of paying up. The UK Government must therefore incentivize increasing investment in attack prevention, detection, and recovery to enable these critical organizations to continue to operate even when in a cyber crisis – or else risk a national disaster.”

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleBusiness continuity resources for smaller businesses: part one
Next Article London Business Networks for Resilience to launch on 29th May

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Corporate Governance Guiding Principles for Board Oversight cover

COSO releases guidance for board risk management and internal control oversight

April 8, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?