Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Ransomware trends: changes in approach are leading to greater potential for reputational damage (Page 14)
Cyber resilience

Ransomware trends: changes in approach are leading to greater potential for reputational damage

October 26, 20237 Mins Read
a concept picture showing a locked system.

Following two years of high but stable loss activity, 2023 has seen a worrying resurgence in ransomware and extortion claims as the cyber threat landscape continues to evolve, Allianz Commercial warns in a new report.

Hackers are increasingly targeting IT and physical supply chains, launching mass cyber attacks, and finding new ways to extort money from companies, large and small.

Most ransomware attacks now involve the theft of personal or sensitive commercial data for the purpose of extortion, increasing the cost and complexity of incidents, as well as bringing greater potential for reputational damage. Allianz Commercial analysis of large cyber losses shows the number of cases in which data is exfiltrated is increasing every year – doubling from 40% in 2019 to almost 80% in 2022, with 2023 significantly higher.

Cyber claims frequency has picked up again this year as ransomware groups continue to evolve their tactics. Based on claims activity during the first half of 2023, we expect to see around a 25% increase in the number of claims annually by year-end. The attackers are back, and focused again on Western economies, with more powerful tools, enhanced processes, and attack mechanisms. Given this dynamic, a well-protected company is necessary to stand up to the threat and, increasingly, the most important element of this is developing strong detection and fast response capabilities.

Scott Sayce, Global Head of Cyber, Allianz Commercial.

How is ransomware risk evolving?

According to the Allianz Commercial report the frequency of cyber claims stabilized in 2022, reflecting improved cyber security and risk management actions among insured companies. Law enforcement agencies targeting gangs, together with the Ukraine Russia conflict, also helped curtail ransomware activity. However, ransomware activity alone was up 50% year-on-year during the first half of 2023. So-called Ransomware-as-a-Service (RaaS) kits, where prices start from as little as US$40, remain a key driver in the frequency of attacks. Ransomware gangs are also carrying out more attacks faster, with the average number of days taken to execute one falling from around 60 days in 2019 to four.

Double and triple extortion incidents – using a combination of encryption, data exfiltration and Distributed Denial of Service attacks – to obtain money are not new but they are now more prevalent. Several factors are combining to make data exfiltration more attractive for threat actors. The scope and amount of personal information being collected is increasing, while privacy and data breach regulations are tightening globally. At the same time, the trends towards outsourcing and remote access leads to more interfaces for threat actors to exploit.

Michael Daum, Global Head of Cyber Claims, Allianz Commercial.

Data exfiltration can significantly add to the cost of a loss or cyber claim. Such incidents can take longer to resolve, while legal and IT forensics can be extremely expensive. If data has been stolen, companies must know exactly what data has been exfiltrated and will likely have to notify customers, who could seek to claim compensation or threaten litigation.

This year has also seen several large mass ransomware attacks as threat actors used exploits in software and weaknesses in IT supply chains to target multiple companies. For example, the MOVEit mass cyber attack, which exploited a data transfer software product, impacting millions of individuals and thousands of companies, contributed to the increase in the frequency of claims in 2023 to date, affecting multiple policyholders simultaneously.

More mass cyber attacks can be expected in the future. Companies and their insurers need to better understand the interconnectivity and dependencies that exist between organizations and within digital supply chains.

Michael Daum.

In the past the number of cyber incidents that became public knowledge was low. Today, it is a different story, as with data exfiltration, hackers threaten to publish stolen data online. Allianz Commercial analysis of large cyber losses (€1mn+) shows that the proportion of cases becoming public increased from around 60% in 2019 to 85% in 2022 with 2023 set to be even higher.

“Today, if you have data exfiltration it will likely go public, and every company needs to be prepared for this,” says Rishi Baviskar, Global Head of Cyber Risk Consulting, Allianz Commercial.

With potentially costly financial and reputational consequences, companies may feel under more pressure to pay ransoms where data has been stolen. The number of companies paying a ransom has increased year-on-year – from just 10% in 2019 to 54% in 2022, again based on analysis of large losses only (€1mn+). Companies are two-and-a half times more likely to pay a ransom if data is exfiltrated, on top of the encryption.

However, paying a ransom for exfiltrated data does not necessarily resolve the issue. The company may still face third party litigation for the breach of data, especially in the US. Indeed, there are few cases where a company should believe that there is no other solution other than paying the ransom to be able to re-access its systems or data. Any impacted party should always inform and cooperate with the authorities.

The importance of early detection and fast response

Protecting an organization against intrusion remains a cat and mouse game, in which cyber criminals have the advantage. Allianz analysis of more than 3,000 cyber claims over the past five years shows that external manipulation of systems is the cause of more than 80% of all incidents. Threat actors are now exploring ways to use artificial intelligence (AI) to automate and accelerate attacks, creating more effective AI-powered malware, phishing, and voice simulation. Combined with the explosion in connected mobile devices – Allianz Commercial has seen a growing number of incidents caused by poor cyber security in this area – attack avenues only look likely to increase.

Preventing a cyber attack is therefore becoming harder and the stakes higher. As a result, early detection and response capabilities and tools are becoming ever more important. Around 90% of incidents are contained early. However, if an attack is not stopped in the early stages the chances of preventing it becoming something much more serious and costly greatly reduce.

Traditional cyber security has focused on prevention with the goal of keeping attackers out of a network. While investment in prevention reduces the number of successful cyber attacks there will always be a ‘gap’ remaining that will enable attacks to get through. For example, it is not possible to stop all employees from clicking on increasingly sophisticated phishing emails.

Rishi Baviskar.

Companies should direct additional cyber security spend on detection and response, rather than just adding more layers to protection and prevention. Only one third of companies discover a data breach through their own security teams. However, early detection technology is readily available and effective.

Cyber breaches that are not detected and contained early can be as much as 1,000 times more expensive than those that are, the report highlights, with Allianz Commercial analysis showing that early detection and response can stop a €20,000 loss turning into a €20mn one.

Prevention drives frequency of attacks and response is responsible for how significant the loss will be – whether it is a minor IT incident or a corporate crisis. We believe companies can meaningfully prepare and there is room for improvement in how they respond to these attacker threats. Ultimately, early detection and response capabilities will be key to mitigating the impact of cyber attacks and ensuring a sustainable cyber insurance market going forward.

Michael Daum.

Obtain the Cyber Security Trends 2023 report.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleAmazon Web Services to launch AWS European Sovereign Cloud
Next Article ISO 22361:2022 – Crisis Management Guidelines: a closer look

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Multiracial people in a city wearing face masks.

UK Government publishes Pandemic Preparedness Strategy

March 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?