Stronger Cyber Controls Are Needed to Counter Ransomware Pandemic, According to New Allianz Risk Report
- AGCS report highlights cyber risk trends driving the surge in ransomware incidents such as double and triple extortion and supply chain attacks.
- Business interruption and recovery are the main causes of financial loss for companies.
- Many attacks could be prevented if companies strengthen their cyber security and controls – often with simple measures.
During the Covid-19 crisis, another outbreak took place in the cyber space: a digital pandemic driven by ransomware. In a new report, cyber insurer
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20211013005112/en/
Allianz: Cyber-related claims per year 2016-2021 (Graphic: Business Wire)
The increasing frequency and severity of ransomware incidents is driven by several factors:
- Growing number of different attack patterns such as double and triple extortion campaigns;
- Criminal business model around ‘ransomware as a service’ and cryptocurrencies;
- Recent skyrocketing of ransom demands;
- Rise of supply chain attacks.
“The number of ransomware attacks may even increase before the situation gets better,” says
Cyber intrusion activity globally jumped 125% in the first half of 2021 compared to the previous year, according to Accenture, with ransomware and extortion operations one of the major contributors behind this increase. According to the
These cyber risk trends are mirrored in AGCS’ own claims experience. AGCS was involved in more than a thousand cyber claims overall in 2020, up from about 80 in 2016. Specifically, the number of ransomware claims (90) rose by 50% compared to 2019 (60). Losses resulting from external cyber incidents such as ransomware or Distributed Denial of Service (DDoS) attacks account for most of the value of all cyber claims analyzed by AGCS over the past six years.
Increasing reliance on digitalization, the surge in remote working during Covid-19, and IT budget constraints are just some of the reasons why IT vulnerabilities have intensified, offering countless access points for criminals to exploit. The wider adoption of cryptocurrencies, such as Bitcoin, which enable anonymous payments, is another key factor in the rise of ransomware incidents.
“We often hear about high profile sophisticated attacks in the media, but as a whole the majority of ransomware attacks are not targeted, nor are they technically sophisticated,” says
Five Ransomware Trends
In the report, AGCS identifies five trends in the ransomware space, although these are constantly evolving and can quickly change in the ‘cat and mouse’ race between cyber criminals and companies:
- Ransomware as a service: Run like a commercial business, hacker groups such as REvil and Darkside sell or rent their hacking tools to others. They also provide a range of support services. As a result, many more malicious threat actors are operating.
- From single to double to triple extortion: Criminals combine the initial encryption of data or systems, or increasingly even their back-ups, with a secondary form of extortion, such as the threat to release sensitive or personal data. In such a scenario, affected companies have to manage the possibility of both a major business interruption and a data breach event, which can significantly increase the final cost of the incident. ‘Triple extortion’ incidents can combine DDoS attacks, file encryption and data theft – and don’t just target one company but potentially customers and business partners.
-
Supply chain attacks the next big thing: There are two main types – those that target software/IT services providers and use them to spread the malware (for example, the Kaseya or SolarWinds attacks). Or those that target physical supply chains or critical infrastructure such as the one that impacted
Colonial Pipeline . Service providers are likely to become prime targets as they often supply hundreds or thousands of businesses with software solutions and therefore offer criminals the chance of a higher payout. -
Ransom dynamics: Ransom demands have rocketed over the past 18 months. According to Palo Alto Networks, the average extortion demand in the US was
$5.3mn in the first half of 2021, a 518% increase on the 2020 average. The highest demand was$50mn , up from$30mn the previous year. The average amount paid to hackers is around 10 times lower than the average demand, but this general upward trend is alarming. - To pay or not to pay: Ransom payment is a controversial topic. Law enforcement agencies typically advise against paying extortion demands to not further incentivize attacks. Even when a company decides to pay a ransom, the damage may have already been done. Restoring systems and enabling the recovery of the business is a huge undertaking, even when a company has the decryption key.
Business Interruption and Recovery Cost Main Drivers of Losses
Business interruption and restoration costs are the biggest drivers behind cyber losses such as ransomware attacks, according to AGCS claims analysis. They account for over 50% of the value of close to 3,000 insurance industry cyber claims worth around €750mn (
The average total cost of recovery and downtime – on average 23 days – from a ransomware attack more than doubled over the past year, increasing from
The surge in ransomware attacks in recent years has triggered a major shift in the cyber insurance market. Cyber insurance rates have been rising, according to broker Marsh, while capacity has tightened. Underwriters are placing increasing scrutiny on the cyber security controls employed by companies.
“Three out of four companies do not meet AGCS’ requirements for cyber security,” explains
IT Security Best Practices
AGCS has published a checklist with recommendations for effective cyber risk management. “In around 80% of ransomware incidents losses could have been avoided if the organizations had followed best practices. Regular patching, multi-factor authentication, as well as information security and awareness training and incident response planning are essential to avoiding ransomware attacks and also constitute good cyber hygiene,” says
In the event of an attack, cyber insurance coverage has evolved to provide emergency incident response services that typically include access to a professional crisis manager, IT forensic support and legal advisory. Further offerings include IT security training for employees and assistance with the development of a cyber crisis management plan.
About
Our customers are as diverse as business can be, ranging from Fortune Global 500 companies to small businesses, and private individuals. Among them are not only the world’s largest consumer brands, tech companies and the global aviation and shipping industry, but also wineries, satellite operators or
Worldwide, AGCS operates with its own teams in 31 countries and through the
For more information please visit http://www.agcs.allianz.com/ or follow us on Twitter @AGCS_Insurance and LinkedIn.
Cautionary Note Regarding Forward-Looking Statements
src="https://cts.businesswire.com/ct/CT?id=bwnewssty=20211013005112r1sid=acqr8distro=nxlang=en" style="width:0;height:0" />
View source version on businesswire.com: https://www.businesswire.com/news/home/20211013005112/en/
973-876-3902
sabrina.glavan@agcs.allianz.com
Stanton
631-681-8770
eburke@stantonprm.com
Source:


Wellteq Digital Health Inc. Extends Private Health Insurer Partnership For 3-Years
Enact Releases Monthly Operating Statistics
Advisor News
- A rising retirement challenge: The license to spend
- Financial stress leaves less room for retirement saving
- Giving while you’re living: 3 frequently asked questions about gifting
- Helping clients prepare for one of their biggest retirement expenses
- Important year-end financial conversations every advisor must have
More Advisor NewsAnnuity News
- A rising retirement challenge: The license to spend
- What lower interest rates mean to annuity payouts
- AM Best downgrades A-Cap insurers amid financial and regulatory troubles
- Lawsuit claims Delaware Life hid billions in insurer-linked investments
- AM Best to Deliver Presentation at 2026 ACLI Annual Conference
More Annuity NewsHealth/Employee Benefits News
Life Insurance News