Summary is AI-generated, newsdesk-reviewed
  • 58% of cybersecurity leaders consider paying ransomware to prevent business downtime.
  • 83% of CISOs confident in recovery, but 57% take up to six days to recover.
  • Legacy patching and employee awareness are top challenges in ransomware mitigation.

The latest findings reveal that over half of cybersecurity leaders are open to the idea of paying ransoms to cybercriminals to mitigate the impacts of ransomware attacks.

A significant 58 percent would consider such payments to prevent operational downtime, which 46 percent of respondents identified as the most severe consequence of ransomware intrusions.

Report Insights

The report, titled The Ransomware Reality: Zero Days to Recover, was published by Absolute Security. It draws insights from a survey conducted by Censuswide, involving 750 Chief Information Security Officers (CISOs) from enterprises based in the United States and United Kingdom.

"It is not surprising to learn that despite regulatory pressure, security and risk leaders remain open to paying a ransom to recover their systems and protect data when considering that prolonged downtime can lead to unsustainable losses," commented Christy Wyatt, President and CEO of Absolute Security. Wyatt emphasized that systems designed for rapid recovery from attacks could prevent enterprises from becoming ensnared in a cycle of increasing cyber threats.

Ransomware: A Chief Concern

Ransomware remains a top CISO concern, especially due to vulnerable endpoint infrastructuresRansomware remains a predominant threat on the agendas of CISOs, with a focus on the vulnerability of endpoint device infrastructures. Over the past 12 to 18 months, 57 percent of the surveyed leaders indicated that their organizations encountered attacks originating from remote, mobile, or hybrid devices, while 58 percent reported that these incidents left endpoints non-functional.

This aligns with telemetry research showing a failure in critical endpoint security controls 20 percent of the time.

Cyber Resilience Challenges

This report, the second in the State of Enterprise Cyber Resilience series, highlights additional challenges posed by ransomware. Notably, 83 percent of CISOs expressed confidence in their company's recovery capabilities; however, 57 percent said the recovery took up to six days, and 20 percent up to two weeks.

None reported being able to restore operations within a day. Furthermore, 59 percent of organizations stated the need for physical access to an endpoint for remediation and recovery, despite available remote recovery solutions, which only 53 percent employ.

Legacy System Patching Difficulties

Patching legacy systems emerged as the second most challenging method for mitigating ransomware attacks, cited by 42 percent of CISOs, surpassed only by Employee Awareness Training at 43 percent. With advancements like advanced language models accelerating vulnerability discovery, companies are challenged to address unpatched software risks efficiently.

Consequently, while patching is crucial, expediting recovery from evolving vulnerabilities should become a primary focus for maintaining security resilience.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence
How AI-Enabled Cameras Are Becoming Operational Sensors That Power Safety, Automation, And Business Intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organizations are increasingly discovering that the same cameras installed to pro...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...