Sophos, a global provider of cybersecurity as a service, published a new sectoral survey report, “The State of Ransomware in Manufacturing and Production,” which discovered that the sector had the highest average ransom payment across all sectors—$2,036,189 versus $812,360, respectively. Furthermore, when compared to the previous year’s survey, 66% of manufacturing and production organizations surveyed reported an increase in the complexity of cyber attacks, and 61% reported an increase in the volume of cyber attacks. The increase in complexity and volume is also 7% and 4% higher, respectively, than the cross-sector average.
“Manufacturing is an attractive sector to target for cybercriminals due to the privileged position it occupies in the supply chain. Outdated infrastructure and lack of visibility into the OT environment provides attackers with an easy way in and a launching pad for attacks inside a breached network. The convergence of IT and OT is increasing the attack surface and exacerbating an already complex threat environment,” said John Shier, senior security advisor, Sophos.
“While having reliable backups is an important part of recovery, today’s ransomware threat requires a detailed response plan that includes human-led threat hunting capabilities. Complex attacks require comprehensive protection, which, for many organizations, will include the addition of managed detection and response (MDR) teams who are trained to look for and neutralize active attackers.”
While manufacturing and production had the highest average ransom payment, the percentage of organizations that paid the ransom was among the lowest across industries (33% versus 46% for the cross-sector average).
Additional findings include:
In light of the survey findings, Sophos experts recommend the following best practices for all organizations across all sectors:
To learn more about the State of Ransomware in Manufacturing and Production, download the full report from Sophos.com.
The State of Ransomware 2022 survey polled 5,600 IT professionals in mid-sized organizations.