We deliver trusted Advisory Automation Audit | that drives results.

Resources
  • All Resources

    Your central hub for security and compliance content.

  • Blog

    Stay informed with expert insights and practical advice on cybersecurity, privacy, and compliance challenges.

  • News

    Get the latest company updates, industry developments, and regulatory changes impacting the cybersecurity landscape.

  • Whitepapers

    Access in-depth research and strategic guidance on risk management, regulatory compliance, and cybersecurity best practices.

  • Case Studies

    See how organizations like yours solved complex cybersecurity and compliance challenges with TrustNet’s solutions.

Knowledge Hub
Guides
  • All Guides

    Get practical step-by-step guides designed to help you navigate audits, improve security posture, and meet compliance requirements.

Edit Template
Login

Secure login to iTrust Platform

Basic Security Lapses Pave the Way for Ransomware Attacks in 2021

Expert Security Insights

Stay informed with expert-driven security content

Ransomware Attacks in 2021

On the surface, ransomware attacks seem sophisticated and complex. Seemingly out of nowhere, criminals gain access to a company’s or institution’s data or systems, locking the rightful owners out unless and until they pay a hefty price. Due to their random and devastating nature, it is easy for security teams to adopt a fatalistic attitude about ransomware attacks, mistakenly believing that they can do little or nothing to avoid them.

In its 2021 State of Ransomware Preparedness report, Axio revealed the fallacy of this line of thinking. As it turns out, many organizations have severe flaws in the underlying foundations of their security practices that make them more vulnerable to ransomware attacks.

Specifically, there are seven key areas where organizations are falling short when it comes to security policies and practices:
• Basic cybersecurity hygiene
• Managing who has access to administrative privileges
• Supply chain risk assessment
• Security incident management
• Network monitoring
• Vulnerability management
• Training and security awareness.

The vast majority of the organizations surveyed are ill-prepared for a ransomware attack. For instance, the data indicates the following:
• Almost 80 percent of them have either not implemented or only partially put in place a privileged access management strategy;
• Only 36 percent of the surveyed organizations audit the use of service accounts
• Only 26 percent deny the use of command-line scripting tools by default
• Only 31 percent limit internet access to their Windows domain controller hosts
• Only 29 percent conduct thorough evaluations of third-party vendors’ security postures before allowing them access to their data and systems
• Only half of those surveyed conduct yearly training regarding email and web-based security threats.

While ransomware and other cybercrimes seem to be a permanent fixture on the threat landscape, enacting preventive measures to bolster these cybersecurity foundations can minimize organizational risk.

 

Request Your Cybersecurity and Compliance Quote