Ransomware is far more prevalent and a much larger problem than it seems, with one in 10 organizations experiencing at least one attack each day, according to new ransomware research from Menlo Security.

The report, which details the impacts of ransomware attacks and preparation, found that one-third of organizations fall victim to a ransomware attack at least once per week.

Mark Guntrip, Menlo Security senior director of cybersecurity strategy, explained this "demonstrates how prevalent ransomware is becoming, and even though it gets significant coverage in the media, the actual volume is much more," he wrote in an email to SDxCentral.

Geographically speaking, the United States and the United Kingdom are most often targeted for ransomware. Sixty-one percent of U.S. organizations and 44% of U.K. organizations said they've been victims of a successful ransomware attack in the past 18 months, with customers and prospects the most common attack entry points.

Cybersecurity Insurance Gap

Another key finding Guntrip highlighted is that the difficulty of recovering from an attack is often underestimated from a financial perspective. Nearly 25% of survey respondents were unaware what their cybersecurity insurance covered — or if they even had insurance.

For the companies that did know the details of their cybersecurity insurance, Guntrip noted it was surprising to see that they believe their insurance is enough to cover ransomware costs, even though their ransomware attack cost estimations "were much lower than most industry averages," he said.

This gap in coverage threatens "substantial financial pain to companies who get hit" if they aren't sufficiently insured, he explained.

The research also found IT security concerns remain largely in-house, despite the volume of outside threats. "It is still disturbing to hear that IT's biggest concern is still the risk of employees ignoring corporate security advice and clicking on links or attachments containing malware," Guntrip said, adding that respondents are more worried about employee security flubs (46%) than their own job security (26%).

"What makes this especially concerning is the constant stress CISOs are under today and resulting rate of burnout. There is already a shortage of CISOs, [and] this is just adding to that problem," he wrote.

Guntrip noted that as long as threat actors continue to hold the "winning formula," there won't be any slow down in the velocity with which enterprises are targeted. Threat actors' focus will likely continue to be web and email entry points, though Guntrip expects applications to be an increasingly popular point of entry.

Because of the ability to establish persistent access to apps, particularly with app-to-app communicators like Box, threat actors can connect a personal Box application to a victim's corporate Box account and use that connection to input malicious content or exfiltrate data from the company.

Targeting Browsers

Guntrip also expects an increase of targeted browser attacks like highly evasive adaptive threat (HEAT) attacks, which are built to bypass traditional detection methods and use the browser to enter a network, rendering them "especially dangerous," he explained.

"Couple this with the fact that the use of SaaS [software-as-a-service] applications has been growing rapidly since the pandemic and today with the work from anywhere and hybrid work models. That makes the browser even more of a target," Guntrip said.