Barracuda Networks shed light on the economic impact of cybercrime and the financial forces that drive the cyberattacks in its latest report titled “Cybernomics 101.” The results also showed the stark difference in time and effort between an attacker exploiting a vulnerability and cybersecurity professionals responding to each cyberattack.

For this report, Ponemon Institute surveyed a total of 1,917 IT security practitioners in the United States, the United Kingdom, France, Germany and Australia last September.

It revealed the staggering cost of cyberattacks -- the average total annual cost of responding to a compromise is $5.34 million. Here is how the number breaks down:

  • The average cost associated with the damage or theft of IT assets and infrastructure, along with subsequent technical support including forensic investigations, incident response activities, help desk and customer service operations, is $2.98 million.
  • The average cost of disruption to operations, including revenue losses due to system downtime or other availability problems, is $2.36 million.

The report also found that ransomware attacks continue to plague organizations globally, with 71% of surveyed respondents experiencing such cyberattacks last year. Alarmingly, 61% ended up paying the ransom, with the highest average payment reaching $1.38 million. In addition to ransomware, phishing remains a significant threat, with 92% of organizations reporting an average of six credential compromises over the past year. The consequences of these attacks were primarily the loss or theft of sensitive information or a lawsuit.

“The findings stand out to me as a spotlight on the uncomfortable truth – cybercrime is a constant and costly threat,” Barracuda CTO Fleming Shi told SDxCentral in an email.

Hackernomics: The shift in cyberattack motivations

Shi points out a shift in hacker motivations, moving from primarily for achieving notoriety and the thrill of breaking things to a business-like approach that their operations more closely resemble legitimate businesses seeking to maximize profitability.

The report delves into the perspective of ethical hackers, who have an average of 10 years of experience helping their organizations identify vulnerabilities. These professionals identified key cbyerattack vectors include weak authentication attacks (55%), phishing or spear phishing (48%) or exploitation of known vulnerabilities (45%).

While weak authentication attacks and phishing are common vectors, they are not the most portable. For malicious hackers, they need to balance between which types of cyberattacks will be most successful and which cyberattacks will be the best return on investment for their efforts, Barracuda pointed out.

Surveyed respondents listed target-specific exploits (58%), Application Programming Interface attacks (55%), zero-day exploits of widely used software (52%), and weak authentication attacks (49%) as the most profitable attack vectors.

“We want to give security pros insights into how cybercriminals operate. As the old saying goes, ‘knowledge is power,’ and if you know the attacker's objectives and preferred tactics, you can devise and implement a plan for how to mitigate the potential damage they cause,” Shi said.

The time and effort gap: security professionals vs. hackers

Beyond the economic impact, the report also showed the vast disparity in time and effort expended between cybercriminals and security professionals.

Security teams face a daunting task. The report details that each IT staff member assigned to remediation spent, on average 427 hours per attack for investigating, cleaning, fixing and documenting the cyberattacks.

When translated into financial terms, it amounts to an average of $30,744 per staff member and a total of $153,720 annually for the average team of five, based on an hourly rate of $72. If the organization outsourced the phishing response to a managed security service provider (MSSP), MSSP spent 504 hours completing its work on average.

On the flip side, a technically proficient hacker can exploit a vulnerability in as little as six hours. “so to put it in a way that stings, hackers can make their millions while the average worker is only 70% through their workday,” Shi said.

He added, for instance, a hacker might begin with a broad scope, examining around 2,500 potential target organizations, and then meticulously narrow down to about 60 organizations with a known vulnerability. The process continues to whittle down to two successful compromises, and finally, at the bottom of the funnel, secure one successful attack that brings value from the compromise. This methodical approach enables hackers to maximize their efforts with minimal time investment.

“This points to the larger trend we’ve seen over the years as cybercriminals and hacking rings run more and more like legitimate businesses and less for the glory of it all,” Shi said.

GenAI might widen the gap

This time gap might grow wider as cybercriminals figure out how to use generative artificial intelligence (AI) (genAI) to increase the volume and sophistication of their cyberattacks, Shi argues.

“What scares me most is that organizations seem to be completely unprepared,” he added.

Barracuda’s report showed while the majority of the respondents are aware that hackers are exploring how to use genAI, only about one-third (39%) believe their security infrastructure is capable of thwarting AI-powered cyberattacks.

“I’m worried that a year from now, we’ll learn that genAI-powered attacks are wreaking havoc and companies are finding themselves unable to defend themselves,” Shi said. “Organizations need to step up their defenses.”