Sophos, a global pioneer in innovating and delivering cybersecurity as a service, released a new sectoral survey report, “The State of Ransomware in Education 2023,” which found that education reported the highest rate of ransomware attacks in 2022.

Over the past year, 79% of higher educational organizations surveyed reported being hit by ransomware, while 80% of lower educational organizations surveyed were targeted, an increase from 64% and 56% in 2021, respectively.

Rates of ransom payment

Additionally, the sector reported one of the highest rates of ransom payment with more than half (56%) of higher educational organizations paying and nearly half (47%) of lower educational organizations paying the ransom.

However, paying the ransom significantly increased recovery costs for both higher and lower educational organizations.

Recovery costs

For lower educational organizations, the average recovery costs were $2.18 million

Recovery costs (excluding any ransoms paid) for higher educational organizations that paid the ransom were $1.31 million when paying the ransom versus $980,000 when using backups.

For lower educational organizations, the average recovery costs were $2.18 million when paying the ransom versus $1.37 million when not paying.

Backup for recovery

Paying the ransom also lengthened recovery times for victims. For higher educational organizations, 79% of those that used backups recovered within a month, while only 63% of those that paid the ransom recovered within the same timeframe.

For lower educational organizations, 63% of those that used backups recovered within a month versus just 59% of those that paid the ransom.

Factor in victim selection

Unfortunately, the data doesn’t support that paying ransoms resolves these attacks more quickly"

While most schools are not cash-rich, they are very highly visible targets with immediate widespread impact in their communities. The pressure to keep the doors open and respond to calls from parents to ‘do something’ likely leads to pressure to solve the problem as quickly as possible without regard for cost."

"Unfortunately, the data doesn’t support that paying ransoms resolves these attacks more quickly, but it is likely a factor in victim selection for the criminals,” said Chester Wisniewski, field CTO, of Sophos.

Root causes of ransomware attacks

For the education sector, the root causes of ransomware attacks were similar to those across all sectors.

There was a significantly greater number of ransomware attacks involving compromised credentials for both higher and lower educational organizations (37% and 36% respectively versus 29% for the cross-sector average).

Additional findings

Additional key findings from the report include:

  • Exploits and compromised credentials accounted for more than three-fourths (77%) of ransomware attacks against higher educational organizations; these root causes accounted for more than two-thirds (65%) of attacks against lower educational organizations.
  • The rate of encryption stayed about the same for higher educational organizations (74% in 2021 versus 73% in 2022) but increased from 72% to 81% across lower educational organizations during the past year.
  • Higher educational organizations reported a lower rate of using backups than the cross-sector average (63% versus 70%). This is the third lowest rate of backup use across all sectors. Lower educational organizations, on the other hand, had a slightly higher rate of using backups than the global average (73%).

Lack of MFA use

MFA sets a good example and is a simple way to avoid many of these attacks from getting in the door"

Abuse of stolen credentials is common across sectors for ransomware criminals, but the lack of adoption of multifactor authentication (MFA) technology in the education sector makes them even more at risk of this method of compromise."

"Like the U.S. federal government’s initiative to mandate all agencies use MFA, it is time for schools of all sizes to employ MFA for faculty, staff, and students. It sets a good example and is a simple way to avoid many of these attacks from getting in the door,” said Wisniewski.

Best practice recommendation

Sophos recommends the following best practices to help defend against ransomware and other cyberattacks:

1) Strengthen defensive shields with:

  • Security tools that defend against the most common attack vectors, including endpoint protection with strong anti-exploit capabilities to prevent exploitation of vulnerabilities, and Zero Trust Network Access (ZTNA) to thwart the abuse of compromised credentials.
  • Adaptive technologies that respond automatically to attacks, disrupt adversaries and buy defenders time to respond.
  • 24/7 threat detection, investigation, and response, whether delivered in-house or by a specialist Managed Detection and Response (MDR) provider.

2) Optimize attack preparation, including making regular backups, practicing recovering data from backups, and maintaining an up-to-date incident response plan.

3) Maintain good security hygiene, including timely patching and regularly reviewing security tool configurations.

Survey details

The State of Ransomware 2023 survey polled 3,000 IT/cybersecurity pioneers in organizations with between 100 and 5,000 employees, including 400 from the education sector, across 14 countries in the Americas, EMEA, and Asia Pacific.

This includes 200 from lower education (up to 18 years) and 200 from higher education (above 18 years) and both public and private sector education providers.

Download PDF version Download PDF version

In case you missed it

Choosing The Right Fingerprint Capture Technology
Choosing The Right Fingerprint Capture Technology

Choosing the appropriate fingerprint technology for a given application is dependent on factors including the required level of security and matching accuracy, the desired capabili...

Morse Watchmans: Texas State University Boosts Security To Keep Pace With Rapid Growth And Expansion
Morse Watchmans: Texas State University Boosts Security To Keep Pace With Rapid Growth And Expansion

In 1899, the Texas Legislature authorized the formation of the Southwest Texas State Normal School, which opened in San Marcos four years later. At the time, the school’s mis...

Koning Willem College Implements ASSA ABLOY Wireless Aperio Access Control
Koning Willem College Implements ASSA ABLOY Wireless Aperio Access Control

Koning Willem I College in north-east Brabant, The Netherlands offers various educational and integration programs. In total, around 18,000 students take 250 courses at its 16 loca...