Skip to content

10 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

  • Comment
      • View all
    • create value

      4 ways to help your CFO create value

      The chief financial officer has a vital contribution to make to the board’s strategy on...

      leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

      growth

      Governance Guide: How boards drive growth

      The strategic role of the board is changing rapidly, in line with a shifting world....

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

The new reality of ransomware attacks: better targeted, more damaging

by Kamal Bechkoum

Boards should be clear on how their organisation’s data and IT infrastructure is being protected against a ransomware attack.

Alert from a ransomware attack

Image: JMiks/Shutterstock

Favorite

The Sophos State of Ransomware 2021 report, an independent survey of 5,400 IT managers in mid-sized companies in 30 countries, has revealed that 37% of organisations have experienced a ransomware attack over the past 12 months, down from 51% in 2020. In addition, fewer businesses have suffered data encryption as the result of an attack, dropping from 73% in 2020, to 54% in 2021.

However, this positive reduction doesn’t tell the full story. The average financial impact of a ransomware attack over the same period has more than doubled, from $761,106 in 2020, to $1.85m in 2021. The most likely reason behind this is that attackers are launching more complex and targeted attacks that are much harder to recover from.

One such example is the recent DarkSide ransomware assault against the Colonial Pipeline operator, the largest fuel pipeline in the US, resulting in a six cents per gallon price hike and forcing the American government to temporarily relax regulations on how long truck drivers are able to remain behind the wheel to improve fuel supply chain flexibility.

Worryingly the number of organisations paying a ransom has grown to 32% in 2021, compared with 26% last year. Despite this only 8% of companies that paid got all of their data back. Nearly a third, 29%, were unable to recover more than half of their encrypted data.

Targeted objectives

The new reality of ransom attack behaviour appears to be a switch from large-scale, automated attacks to more targeted and specific objectives involving expert criminals getting hands-on-keyboards in their attempts to penetrate an organisation.

This means that the potential damage being done is far higher and often includes data-exfiltration followed by a threat to sell or publish that stolen information.

Covid-19 has made firms increasingly reliant upon their online networks and remote-working capabilities

Many of the existing methods of resisting this state of affairs still apply: a culture of security should be fostered throughout the workplace; staff need to be educated and trained to keep software applications and systems updated; files must be backed-up regularly; and networks require segmenting to ensure sensitive data is only accessible to those who need it when necessary.

Covid-19 has made firms increasingly reliant upon their online networks and remote-working capabilities. Given that 95% of internal breaches continue to be caused by human error the default approach to all Internet of Things (IOT) systems should always be one of suspicion.

The pressures of the pandemic and lockdown has left many workers tired, often putting them in a position where they might fail to fully check the veracity of texts and emails before reacting to them. This is when it becomes very easy to overlook crucial details and allow threats to slip through.

Everyone should be reminded to avoid the mistake of acting in haste. Staff at all levels should be encouraged to breathe, regroup and take their time before reacting. Asking the right questions, double-checking procedures and ensuring that colleagues are alert to cybersecurity issues will make the difference between a secure operating environment, or crushing failure.

Professor Kamal Bechkoum is head of business and technology at the University of Gloucestershire.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Business concern over cyber attacks rises in wake of Ukraine conflict
    February 28, 2022
    Ukraine flag with coding

    Geopolitical uncertainty is leading firms to boost their defences against cyber attacks. But true digital resilience is a continuous process.

  • FBI warns ransomware gangs are targeting M&A transactions
    November 18, 2021
    ransomware threat

    US crime agency says the hard deadlines involved in M&A transactions pressures victims to pay up for fear of affecting stock values.

  • Technology, cyber risk and ESG top list of business leaders' concerns
    June 8, 2022
    Digital code on skycrapers

    Mazars survey reveals 82% of executives plan to increase investment in IT systems, while 75% plan to boost spending on sustainability.

  • Identity crisis: the threat of malicious credential abuse
    September 1, 2021
    Employee credentials login screen

    The security risks posed by malicious credential abuse is fast becoming every chief information security officer’s worst nightmare.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy