Research by Bridewell has looked in detail at the impacts of ransomware to consider the wider organizational effects.
Bridewell surveyed 521 staff responsible for cyber security at UK critical national infrastructure (CNI) organizations in sectors such as civil aviation, telecommunications, energy, transport, media, financial services, and water supply.
60% of organizations surveyed experienced at least one ransomware attack over the previous 12 months. More than a third (35%) suffered up to five ransomware attacks, but a small percentage of organizations (2%) experienced more than a hundred attacks.
The research findings expose the multiple consequences of a ransomware attack, with more than a quarter of respondents citing a psychological impact on employees (27%). Disruption (42%), downtime (40%) and data-loss (39%) are all repercussions that respondents say their organizations have suffered, along with reputational damage (35%).
Almost a third of organizations (32%) are also facing increased insurance premiums, and 34% have also incurred financial losses from legal fees or fines.
Impacts are exacerbated by the length of time it takes organizations to respond to ransomware attacks, with the average now being 11.4 hours.
Almost nine-in-ten (87%) UK respondents in the research agree that attacks are more sophisticated, with ransomware-as-a-service (RaaS) deployed with greater knowledge and cunning. Threats are on the rise through increasing professionalisation in the ransomware world and the entry of organized crime groups from other areas of criminality.






