This Encryption Rate Was the Third Highest Across All Sectors Surveyed and Was 7% More Than the Cross-Sector Average

OXFORD, U.K. — September 28, 2022 —

Sophos, a global leader in next-generation cybersecurity, today published a new sectoral survey report, The State of Ransomware in State and Local Government 2022, which found that 72% of state and local government organizations attacked by ransomware had their data encrypted—7% more than the cross-sector average. In fact, only 20% of state and local government organizations were able to stop the ransomware attack before data could be encrypted —significantly less than the cross-sector average of 31% (8% had their data held for ransom but not encrypted). However, at the same time, the government sector had one of the lowest attack rates with only 58% hit by ransomware in 2021.

“Traditionally, government organizations haven’t been prime targets for ransomware attackers, since they don’t have as much money as traditional businesses, and criminal groups are reticent to attract attention from law enforcement. However, when these organizations do get hit, they have little in the way of protection because they don’t have the budget for additional, in-depth cybersecurity support, including threat hunting teams or security operations centers. And, there are a couple reasons for this. One is that, while they collect a large amount of sensitive information, they need to keep this information easily accessible. Second, they need to spend the majority of their budget on their actual municipality. Taxpayers can see if the streets are clean or if their schools are reaching their education goals. They can’t ‘see’ a cyberattack or understand why a Managed Detection and Response (MDR) provider might be necessary to defeat ransomware,” said Chester Wisniewski, principal research scientist, Sophos. 

In addition to experiencing a high encryption rate, the government sector also experienced a significant drop in the amount of encrypted data recovered after paying the ransom when compared to 2020—58% in 2021 versus 70% in 2020; this was also lower than the cross-sector average of 61%.

Additional findings include:

  • 2021 saw a 70% rise in the number of ransomware attacks against local government organizations; 58% were targeted when compared to 34% in 2020
  • The cost for government organizations to remediate an attack was three times the average ransom the sector paid

"If we look at what happened with the city of Atlanta, Georgia, back in 2018, they ultimately ended up paying $17 million to recover from an attack that asked for $50,000 dollars in ransom. This is often the case with local and state government organizations—they spend far more on recovering and catching up with current security practices than they do on the actual ransom demand, should they choose to pay it. While getting the initial buy-in may be hard, in the long term, preemptive cybersecurity measures are a far better alternative than bolstering defenses after an attack,” said Wisniewski.

In the light of the survey findings, Sophos experts recommend the following best practices for all organizations across all sectors:

  • Install and maintain high-quality defenses across all points in the environment. Review security controls regularly and make sure they continue to meet the organization’s needs
  • Proactively hunt for threats to identify and stop adversaries before they can execute attacks – if the team lacks the time or skills to do this in-house, outsource to a Managed Detection and Response (MDR) team
  • Harden the IT environment by searching for and closing key security gaps: unpatched devices, unprotected machines and open RDP ports, for example. Extended Detection and Response (XDR) solutions are ideal for this purpose
  • Prepare for the worst, and have an updated plan in place of a worst-case incident scenario
  • Make backups, and practice restoring them to ensure minimize disruption and recovery time

 

To learn more about the State of Ransomware in State and Local Government 2022, download the full report from Sophos.com.

The State of Ransomware in State and Local Government 2022 survey polled 5,600 IT professionals in mid-sized organizations across 31 countries, including 199 respondents from the state and local government sector.

Über Sophos

Sophos ist ein führender Anbieter im Bereich Cybersicherheit und schützt weltweit 600.000 Unternehmen und Organisationen mit einer KI-gestützten Plattform und von Experten bereitgestellten Services. Sophos unterstützt Unternehmen und Organisationen unabhängig von ihrem aktuellen Sicherheitsniveau und entwickelt sich mit ihnen weiter, um Cyberangriffe erfolgreich abzuwehren. Die Lösungen von Sophos kombinieren maschinelles Lernen, Automatisierung und Echtzeit-Bedrohungsinformationen mit der menschlichen Expertise der Sophos X-Ops. So entsteht modernster Schutz mit einer 24/7 aktiven Erkennung, Analyse und Abwehr von Bedrohungen.
Das Sophos-Portfolio beinhaltet branchenührende Managed Detection and Response Services (MDR) sowie umfassende Cybersecurity-Technologien– darunter Schutz für Endpoints, Netzwerke, E-Mails und Cloud-Umgebungen, XDR (Extended Detection and Response), ITDR (Identity Threat Detection and Response) und Next-Gen-SIEM. Ergänzt wird das Angebot durch Beratungs-Services, die Unternehmen und Organisationen helfen, Risiken proaktiv zu reduzieren und schneller zu reagieren – mit umfassender Transparenz und Skalierbarkeit, um Bedrohungen immer einen Schritt voraus zu sein.
Der Vertrieb der Sophos-Lösungen erfolgt über ein globales Partner-Netzwerk, das Managed Service Provider (MSPs), Managed Security Service Provider (MSSPs), Reseller und Distributoren, Marketplace-Integrationen und Cyber Risk Partner umfasst. So können Unternehmen und Organisationen flexibel auf vertrauensvolle Partnerschaften setzen, wenn es um die Sicherheit ihres Geschäfts geht.  Der Hauptsitz von Sophos befindet sich in Oxford, Großbritannien. Weitere Informationen finden Sie unter www.sophos.de.