Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceCybersecurity News

The fight against ransomware

By Christian Have
ransomware freepik
October 5, 2021

A new ransomware attack occurs every 11 seconds, and today the attacks are more financially debilitating than ever before, with the average incident resulting in more than $700,000 in damages. In fact, JBS recently paid 11 million dollars following an attack on their U.S. beef plants, and one of the largest U.S. insurance companies, CNA Financial, paid nearly 40 million dollars to regain access to files and restore operations. Not to mention the major impact ransomware attacks have on company operations and customer and investor relationships, like the gas shortage caused by the Colonial Pipeline attack. The need to fight back, and fight back hard, is obvious. But to be successful, companies need to understand the threat at hand first.


Most ransomware groups are similar to corporate structures, with roles and responsibilities that mirror regular software development organizations, making it difficult to identify the responsible parties and hold them accountable. What makes these criminal organizations even more dangerous is their ability to generate different revenue streams, aside from company payouts from:


  • Selling access to ransomware platforms that deliver end-to-end ransomware-as-a-service for other groups to use
  • Brokers that recruit teams to build and deploy malware
  • Selling corporate data access to victims for other networks to capitalize on


The sophisticated framework of ransomware groups enables hackers to meticulously target organizations with ease, especially when organizations don’t prioritize cybersecurity programs that proactively detect and prevent attacks, let alone address the cybersecurity basics. Understanding the threats at hand and the best practices for combatting them can help organizations better navigate today’s cybersecurity landscape.   


Keeping the Basics Top Of Mind

Chief information security officers (CISOs), security operations teams, and security vendors have focused on complex attacks and staying on top of the cutting edge of what adversaries can do. For example, the malicious hacking conglomerate Stuxnet is notorious for extremely innovative campaigns. The complexity of their campaigns scared organizations into investing in advanced technologies, which are expensive and difficult to integrate with surrounding security systems. But advanced technologies aren’t meant to cover basic mistakes. The Colonial Pipeline security setup consists of advanced detection tools, but the tools could not protect against the lack of multi-factor authentication and shared passwords which caused the recent breach. Failing to cover cybersecurity basics like patching, having secure configurations, or following password best practices makes it easy for hackers to gain access. While they are “basic,” they are effective and necessary for a company’s overall security posture. 


Diving Deeper Into Security Solutions

Influential security research/analysis firms, such as Forrester, Gartner, and IDC, are hearing from vendors and customers about the growing need to link incident detection with incident management and response in a unified platform that can autonomously increase threat detection and reaction speed. One way to do this is by integrating SIEM, or Security Information and Event Management, with SOAR (Security Operation Automation and Response).


Most IT departments already have SIEM systems in place. These systems work as threat protection 

by ingesting and aggregating data from the entire IT infrastructure to identify incidents and alert security professionals, allowing them to respond appropriately. The future of cyber protection will minimize the need for human intervention by unifying threat detection with threat response through SOAR. By combining vulnerability data with natural language processing and machine learning, organizations can couple indicators of ransomware with threat intelligence and malware research to identify documented adversarial techniques. From there, systems can conclude the type of threat and automate and orchestrate the response. Not only can these systems respond to active threats in real-time, they can also utilize situational awareness to predict the next phase of an attack. Newer vendors even have small agents on customers’ machines that can rapidly disconnect machines from networks and otherwise act based on how security operators want to approach a potential issue.


Opening the Lines of Communication

However, when an organization’s infrastructure is under attack, technology alone will not solve the issue. There needs to be increased internal communication between the security operations team, IT operations team and enterprise risk management team. A lack of communication across departments, whether human error or not, has been a point of contention within many organizations. Aligning objectives and goals across different departments is critical in preparing for these inevitable attacks. 


Collaboration is particularly important when it comes to law enforcement cooperation and legislation. Law enforcement agencies need to cooperate to target ransomware groups, track payments and ultimately, make it more difficult to do illicit business. Lawmakers need to be held accountable as well. Legislation and regulations will incentivize companies to prioritize cyber security protection. With organizations facing fines by failing to prevent or protect their infrastructure adequately, boardrooms will begin to take the threat seriously. 


While ransomware attacks are inevitable, organizations can better equip themselves to mitigate attacks. It is just the start to cover basic security requirements like multi-user authentication, eliminating shared passwords, and increasing communication across IT teams. The real difference will be integrating SIEM and SOAR to automate threat detection and threat response. 

KEYWORDS: automation cyber security ransomware risk management security operations

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Christian Have, CTO, brings years of cybersecurity expertise to his product strategy role at LogPoint. He owns the whole product process from vision, strategy, design, development to marketing. He brings to market products that fulfil the needs of today’s businesses. Have also oversees all aspects of the product journey from conceptualization, launch and post-launch performance. Prior to joining the company, he was the head of network security for the Danish National Police. He is also a guest lecturer on cybersecurity at leading Danish universities. He has a Bachelor of IT from the IT University of Copenhagen.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

Cybersecurity trends of 2025

3 Top Cybersecurity Trends from 2025

Red laptop

Security Leaders Discuss SitusAMC Cyberattack

Green code

Logitech Confirms Data Breach, Security Leaders Respond

Neon human and android hands

65% of the Forbes AI 50 List Leaked Sensitive Information

The Louvre

After the Theft: Why Camera Upgrades Should Begin With a Risk Assessment

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

December 11, 2025

Responding to Evolving Threats in Retail Environments

Retail security professionals are facing an increasingly complex array of security challenges — everything from organized retail crime to evolving cyber-physical threats and public safety concerns.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • data-protection-freepik1170x658v504.jpg

    How a more unified approach to data protection will help in the fight against ransomware

    See More
  • covid-19

    The critical role security technology plays in the fight against COVID-19

    See More
  • cyber security freepik

    The fight against cyber threats requires a public-private partnership. Here’s how to get it done.

    See More

Related Products

See More Products
  • Risk Analysis and the Security Survey, 4th Edition

  • The Database Hacker's Handboo

  • 9780367030407.jpg

    National Security, Personal Privacy and the Law

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing