By Ray Birch
ABINGDOM, U.K.—The rise in ransomware attacks, and the mounting costs from recovering from an incident, should be all the motivation any credit unions needs to line up resources today to help them get back on their feet if they are victimized by hackers tomorrow, asserts one security expert.
And those costs are high—$2 million on average, and higher for financial institutions, a new study reveals.
John Shier, senior security advisor at U.K. security firm Sophos, told CUToday.info that wise organizations are now securing services that will get them back and operating in the event of a ransomware attack, at the lowest cost possible.
He said that includes attorneys on retainers, PR firms and security consultants that will be needed if a credit union’s data is being held for ransom by cyber-thieves.
Shier said every organization, including credit unions, must adopt the thinking that they will get hit someday by a ransomware attack, and recognize it is simply too costly and too slow of a process to recover when scrambling to find assistance and attempting to learn what it needs to do after the attack has occurred.
“That is sound thinking, preparing in advance,” Shier said. “As these attacks will not be slowing down.”
A new report from the U.S. Financial Crimes Enforcement Network (FinCEN) reveals that more than $5 billion in Bitcoin transactions were linked to ransomware payments during the first half of 2021. According to FinCEN, 635 reports and 458 ransomware transactions were reported as of June, more than the total incidents from the previous year.
And those are just the incidents that were reported.
Global financial services firms spent more than $2 million on average recovering from a ransomware attack last year, according Sophos data. Shier said recovery costs for financial institutions tend to be higher than many other organizations because they are highly regulated.
Growing Recovery Costs
“What's driving up the ransomware cost so high? Recovery costs have increased over the last several years,” explained Shier. “Companies today are having to leverage a whole bunch of different resources—deploying additional technologies, hiring consultants and legal counsel—all of those costs are contributing to the cost of recovering.”
And then, there are other, more internal expenses, Shier noted.
“There's some additional costs that are being added onto the final bill, specifically the financial services side of it, because of the type of data organizations are holding,” he said. “There are regulatory fines to consider.”
The Price of Reassurance
Then there are the reputational costs.
A strong marketing or public relations firm can play a key role in an organization protecting its reputation and keeping its customers or members, said Shier.
“There are costs related to reassuring your customers through PR campaigns and marketing efforts to get them comfortable again with doing business with you,” Shier said.
There are also the costs for those who pay the ransom, said Shier, who explained the $2 million average is a mix of all organizations in the study that were hit with ransomware attacks, some paying the ransom and some not.
He also said the price tag for the ransom is typically scaled to the organization’s ability to pay.
“These crooks know what they are doing,” said Shier. “Before they make the final attack, they get inside the organization. They get a good grasp of the company’s financials. They know what the business can afford to pay, and they make their demand accordingly.”
Costs Add Up
Legal costs can be large, noted Shier, adding that while an organization’s size could affect overall costs, lawyers are going to charge their same hourly rate no matter what the asset size a credit union might be reporting on its 5300.
Ransomware victims will also be paying to restore their network and data, which includes both hardware and software costs, he said.
“And don’t forget the costs associated with downtime—when the organization cannot conduct business,” Shier said.
The first step any credit union should take, and it’s not expensive, is to pay careful attention to its processes for backing up data, according to Shier.
“If you’ve got a system that seems to be working and you're making backups daily or weekly, assess this process,” he advised. “Will what you are doing actually rescue you from a ransomware attack? Make sure it will. Review your policies and the technology you're using. Review how you're doing the backup itself. And then test. Testing should always be part of the backup plan. Some companies fall into the trap of just thinking that what they have always been doing will work, and then they find after an attack their backup plan does not work well enough. Run tabletop exercises and really understand where you stand.”
A Poor Defense
Some of the costs associated with a ransomware attack are for replacing aging technology that may have provided a poor defense against the hackers, added Shier.
“A lot of companies are just operating with older protection technologies,” Shier said. “For example, they might want to consider a more modern protection strategy that relies on AI…Protection that brings in all aspects of the network environment and includes the ability to threat hunt. If you don't have those capabilities you have to look at partnering with a third-party…I think a lot of companies now are starting to realize there is a lot more to be done here.”
Shier pointed out that a ransomware attack typically starts quietly, as crooks slowly begin to steal passwords and gain greater access to the organization’s network. He said that companies should be wary of threats that are detected and then blocked, and not to think that the stymied attempt means the organization is safe.
“The bad guys will keep chipping away and working away at your environment until they get the penetration they need to launch a full-scale attack. Remember, the ransomware notice is just the last thing you see from the crooks’ whole campaign,” noted Shier. “They can be in your network for weeks or months before that. When it comes to detection response, be able to look into incidents that have occurred on your network even if they've been blocked. Even if a threat is blocked, that could be cause for alarm.”
One Specific Threat
Shier said organizations should pay special attention to threats from Mimikatz, an open source malware program that steals login credentials, that are detected and blocked. He explained this password-stealing malware is often used to pave the way for a ransomware strike.
“This should be cause for alarm, if you see that you have blocked a Mimikatz threat. This should be investigated,” he said.
