Ransomware is at the forefront of every CISO's mind, with 83% of surveyed security leaders admitting to paying ransoms directly or indirectly, often hefty ones, according to the latest Splunk report. However, researchers noted when making ransom payment decisions, CISOs might be the least important person in the room as it’s a business decision.
Splunk’s the CISO Report surveyed about 370 CISOs, CSOs and other executive security leaders and found a vast majority (90%) of them reported their organization suffered at least one disruptive attack last year.
Notably, in the wake of these events, 18% of the respondents said they paid the ransom directly to the attackers, 37% paid through cyber insurance and 28% used third-party negotiators. The retail sector stands out with a staggering 95% paying the ransom.
Mick Baccio, global security advisor of the SURGe security research team at Splunk, told SDxCentral the actual figures might be even higher, given that many transactions remain “behind the scenes.”
“Ransomware is such a big deal and has been going on so long,” he said. “Whether you want to deal with ransomware or not, you're going to have a contingency plan in place.”
The ubiquity of crimeware — including ransomware and extortion attacks — and the need for a disaster plan was echoed by Ryan Kovar, distinguished security strategist and leader of Splunk SURGe.
The financial toll of ransomware attacksNotably, of those who paid, more than half reported the amount was over $100,000, with 44% paying somewhere between $25,000 to $99,000 and an alarming 9% paying more than a million dollars for ransom, according to Splunk’s report.
On the other hand, recent cyberattacks on casino giants MGM and Caesars underscore the potential fiscal devastation. MGM estimated a staggering loss exceeding $100 million due to the ransomware attack, while Caesars reportedly paid a ransom of $15 million. Such disparities beg the question: How will these incidents impact the future considerations of CISOs and organizations regarding ransom payments?
Kovar noted victims like MGM have to deal with massive financial losses from operation disruptions and their security leaders will have to answer some hard questions from their stakeholders including: Did you prepare enough? Did you allocate funding?
“If that CISO was three people down, does that really show a prioritization by that board of directors or that corporate governance of the company to actually care about security? But when you have a CISO who's reporting directly to the CEO, his words are unvarnished,” he said. “I think that's kind of why CISOs are in the C-suite now, which wasn't always there.”
Baccio highlighted the shifting paradigm surrounding ransomware as its public perception is evolving due to changing regulations and reporting requirements like the new SEC cybersecurity disclosure rules.
“Paying ransomware is not as forbidden to a lot of entities because even to a board, if I am a board of directors, I have the responsibility to keep operations moving, period, and any impact to that,” he said. “I think it is becoming more public.”
MGM's incident dominated headlines while the Caesars attack was relatively underreported until their 8-K form filing, “But it shows you that ecosystem is very plausible,” Baccio said.
To pay or not to pay the ransom?Should organizations pay a ransom? Kovar has been asked this question many times. “I always say it's a very personal question. It really depends on your business and if you have disaster recovery plans.”
Baccio underscores CISOs’ role in cyber and organizational resilience. “The role of a CISO honestly is in those tabletop exercises. We keep saying those scenarios: when that ransomware event doesn't happen, or that extortion event does happen, do I have all the people I need in place to have to answer that question: Do we pay the ransom?”
“As a security professional, the role of CISOs years ago was 100% secure all the time. And that has really shifted to hey, look, we have a responsibility to keep this business running, and we are a facet of operations, not the entirety of operations,” he added.
Baccio pointed out that it's not up to CISOs to decide whether or not to pay the ransom, but they will be involved in the conversation and present what’s available. “The people involved in making that decision whether to pay the ransom, so it's not a singular person. But I really think the value is planning for that scenario, and CISOs now know that if I don't have a plan in place if an event happens, my tenure is even shorter than that 18 to 24 months.”
Surprisingly, when the decision arises, the CISO, despite their cybersecurity expertise, is not the loudest voice. “When it’s down to do we pay the ransom or not. They're the least important person there. Now it's a business decision,” Kovar said. “At that point, sadly, the CISOs are in the room, but they're no longer important people.”
“You're on the back bench,” Baccio concurred.
After the incident, their role becomes secondary to lawyers, public relations teams and other business stakeholders, Kovar said.
He also reiterated that even after the ransom is paid, data recovery is never guaranteed. “The reality is that most organizations never get their data back completely, even when they pay. You can't trust a ransomware operator to give you a decryption key that works. They're not financially motivated to do so.”
Comments