Retail sector regularly targeted by ransomware

Ransomware, a kind of malicious software, makes business data inaccessible until a ransom is paid. While it is used against businesses of all sizes, SMBs have become a prime target for attackers. The 2019 Datto Global State of the Channel Ransomware Report uncovered a number of ransomware trends specifically impacting the SMB market.

• Ransomware attacks are pervasive. The number of ransomware attacks against SMBs is on the rise. Eighty-five per cent of managed service providers (MSPs) reported attacks against SMBs over the last two years, compared to 79 per cent of MSPs who reported the same in 2018. In the first half of 2019 alone, 56 per cent of MSPs reported attacks against SMB clients. In Australia and New Zealand, 91 per cent of MSPs report attacks against SMBs in the last two years, the highest rate globally.

• A disconnect exists on the significance of ransomware as a threat. Eighty-nine per cent of MSPs report that SMBs should be very concerned about the threat of ransomware. However, only 28 per cent of MSPs report SMBs are very concerned about the threat. 

• The cost of ransomware is significant. Sixty-four per cent of MSPs report experiencing a loss of business productivity for their SMB clients while 45 per cent report business-threatening downtime. The average cost of that downtime is US$141,000, a more than 200 per cent increase over last year’s average downtime cost of US$46,800. The report also uncovered that the cost of downtime is now 23 times greater than the average ransom request of US$5,900.

One of the most basic and effective controls when it comes to ransomware preparation is being underutilised. MSPs report enabling 2FA on only 60 per cent of email clients and 61 per cent of password managers, despite the fact that the majority of MSPs (67 per cent) claim phishing emails are the leading cause of ransomware breaches at SMBs.

Business continuity and disaster recovery (BCDR) solutions have continued to prove to be the most effective in lessening the impact of a ransomware attack. Ninety-two per cent of MSPs report that their clients with BCDR solutions in place are less likely to experience significant downtime during an attack.

In addition, four out of five MSPs state victimised clients with BCDR tools in place recovered from an attack in 24 hours or less, while less than one in five MSP clients without BCDR were able to do the same. MSPs are in a unique position today to educate SMBs on how to protect against a ransomware attack, including employee training and the tools to implement.

“Ransomware attacks most often succeed through very sophisticated phishing techniques―for example, when someone clicks on something they shouldn’t and the malware infiltrates their contact list―the attackers then use those credentials to exploit further,” says Daniel Johns, head of services at Australian ICT company, ASI Solutions, which specialises in innovative technology solutions for businesses to gain a competitive edge.

“As such, a proactive approach to cybersecurity, including user awareness and training, is vital. As SMBs continue to be heavily targeted by ransomware, we’ll continue to work directly with our clients to help reduce the risk and impact of an attack, should it occur.”

SaaS applications are also a prime target for ransomware attacks, with MSPs globally reporting a 15 per cent increase in the attacks within Office 365 year on year. Of interest the highest rate globally was in Australia and New Zealand, with 37 per cent of MSPs reporting attacks on SaaS applications―including Office 365, Dropbox and the G-Suite; a nine per cent increase from the global average of 28 per cent.

“It is no surprise that the frequency and sophistication of ransomware attacks against SMBs in Australia and New Zealand is on the rise, but recording the highest rate globally of reported attacks in this region is a wakeup call for SMBs,” says James Bergl, regional director, APAC Datto.

“We understand that the cost of downtime that can cripple an SMB, as such we work closely with our MSPs to take a proactive approach to delivering tailored cybersecurity solutions for small and medium businesses.”