Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Executives' ransomware concerns are high, yet few are prepared for attacks

Questions leaders can use to measure organization's ransomware preparedness

cyber-security-ransom-freepik25w58.jpg
September 14, 2021

The vast majority (86.7%) of C-suite and other executives say they expect the number of cyberattacks targeting their organizations to increase over the next 12 months, according to a recent Deloitte poll.  And while 64.8% of polled executives say that ransomware is a cyber threat posing major concern to their organizations over the next 12 months, only 33.3% say that their organizations have simulated ransomware attacks to prepare for such an incident.

More than 50 C-suite and other executives were polled online during a webcast held on June 24, 2021 about cyber threat detection and response. Participating executives held leadership roles in areas including corporate boards (36.7%), IT (34.4%), risk management (12.2%) and security and privacy (6.7%).

According to Deloitte, questions leaders can ask to gauge their organizations' ransomware preparedness include:

  • Does our organization's cyber incident response plan address ransomware attacks specifically?  Leading organizations have developed and tested cyber incident response plans, but not every organization has one and not all directly address the nuances of ransomware attacks. 
  • Has our organization considered adopting Zero Trust to help bolster cybersecurity against ransomware and other threats?  Removing automatic or inherited trust given to users, workloads, networks, and devices can help organizations shore-up security gaps created by digital transformation, M&A activity, rapid cloud adoption and continued remote work that ransomware actors frequently take advantage of. 
  • Does our organization fully appreciate how ransomware attackers could exploit our use of emerging technologies to propagate attacks?  Are we leveraging emerging technologies to better protect our organization from those threats? Certain technologies that companies are implementing as part of their digital transformations appear to benefit attackers in a number of ways, but defenders can use them to their organization's advantage as well. It's important for companies to understand how these technologies may increase their cyber risk exposure and how defenders could use them to improve security.
  • How does our organization test for ransomware vulnerabilities?  Frequent penetration testing can help identify attack surface vulnerabilities and paths to critical systems and assets, while business continuity/disaster recovery testing can confirm that redundant backups are ready to support business resiliency if needed. As ransomware can propagate throughout a technology infrastructure, traditional backup and recovery plans may not be sufficient. Further, testing ransomware incident response plans via simulations or other approaches can help leaders across an organization build "muscle memory" around roles, responsibilities and protocols in the event of an attack.
  • Does our organization conduct threat hunting to help manage ransomware risk?  Leading organizations are starting to take the offensive in cyber risk management by proactively working to identify new attack patterns and new attackers before they can potentially cause damage.  By uncovering undetected ransomware, malware or other cyber threats, potential effects can be investigated and remediated in a timely manner. 

Tim Wade, Technical Director, CTO Team at Vectra, says, "Awareness of security issues by the C-Level has increased in recent times if for no other reason than the impossibility of ignoring ransomware attacks – security programs that routinely failed to detect adversaries whose modius operandi was simply data exfiltration without environmental disruption could continue their ineffectiveness without cause for course correction. Ransomware changed that. C-Level support is essential to prepare an organization to withstand a ransomware attack because it involves the will to fundamentally change the way legacy IT is conducted – shifting from a set-and-forget preventative security posture, to one that emphasizes resilience by detection and responding to an attack before material damage is done. Without top-cover, this paradigm shift in how an organization manages cyber risk will almost certainly die on the vine."

However, getting security buy-in no easy task. It is always challenging for executives who may only see the problem in terms of costs for new tools or personnel, explains Sean Nikkel, Senior Cyber Threat Intel Analyst at Digital Shadows. Nikkel says, "It may be a case of spelling out the threat regarding potential losses in a ransomware attack. No one thinks they will be a target until they become a target, and it is at that point that building a response plan is too late."

Today's ransomware payouts far outweigh the cost of developing incident response capabilities, having playbooks planned and practiced, or developing security policies to combat the problem, Nikkel adds. "Security teams may have to show the potential return on investment for a security tool or procedure, compared to the possible repercussions —  essentially that a "stitch in time saves nine." Once you consider the thousands to millions of dollars required to respond to an incident and the potential public fallout, a small early investment can have some actual savings that the C-level should consider."


 

KEYWORDS: c-suite cyber security information security ransomware risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cyber threat

    Are you Ready for These 26 Different Types of DDoS Attacks?

    See More
  • Study says 75% of U.S. Organizations are not Prepared to Respond to Cyber Attacks

    See More
  • Vertical green code on black screen

    87% of executives are concerned about bot attacks and AI fraud

    See More

Related Products

See More Products
  • High-Rise Security and Fire Life Safety, 3rd edition

  • 150 things.jpg

    The Handbook for School Safety and Security

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing