{"id":8149,"date":"2024-08-27T11:40:11","date_gmt":"2024-08-27T09:40:11","guid":{"rendered":"https:\/\/testing.eight25sites.com\/en-us\/?p=8149"},"modified":"2024-08-27T11:40:11","modified_gmt":"2024-08-27T09:40:11","slug":"the-state-of-ransomware-in-state-and-local-government-2024","status":"publish","type":"post","link":"https:\/\/testing.eight25sites.com\/en-us\/2024\/08\/resources\/the-state-of-ransomware-in-state-and-local-government-2024\/","title":{"rendered":"The State of Ransomware in State and Local Government 2024"},"content":{"rendered":"<p>The latest annual Sophos study of the real-world ransomware experiences of state and local government organizations explores the full victim journey, from attack rate and root cause to operational impact and business outcomes.<\/p>\n<p>This year\u2019s report sheds light on new areas of study for the sector, including an exploration of ransom demands vs. ransom payments and how often state and local government organizations receive support from law enforcement bodies to remediate the attack.<\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-government\" target=\"_blank\" rel=\"noopener\">Download the report<\/a>\u00a0to get the full findings.<\/p>\n<h2><strong>Attack rates have gone down, but recovery is more expensive<\/strong><\/h2>\n<p>State and local government organizations reported the lowest rate of attacks of all sectors surveyed in 2024. 34% of state and local government organizations were hit by ransomware in 2024, a 51% reduction in the attack rate reported in 2023 (69%).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956796 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image1.png\" sizes=\"auto, (max-width: 728px) 100vw, 728px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image1.png 728w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image1.png?resize=300,84 300w\" alt=\"Attack Rate\" width=\"728\" height=\"203\" \/><\/p>\n<p>Almost all (99%) state and local government organizations hit by ransomware in the past year said that cybercriminals attempted to compromise their backups during the attack. Of the attempts, just over half (51%) were successful \u2013 one of the lowest rates of backup compromise across sectors.<\/p>\n<p>98% of ransomware attacks on state and local government organizations resulted in data encryption, a considerable increase from the 76% encryption rate reported in 2023. This is the highest rate of data encryption of all sectors studied in 2024.<\/p>\n<p>The mean cost in state and local government organizations to recover from a ransomware attack was $2.83M in 2024, more than double the $1.21M reported in 2023.<\/p>\n<h2><strong>Devices impacted in a ransomware attack<\/strong><\/h2>\n<p>On average, 56% of computers in state and local government organizations were impacted by a ransomware attack, above the cross-sector average of 49%. Having the full environment encrypted is extremely rare, with only 8% of organizations reporting that 81% or more of their devices were impacted.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956797 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image2.png\" sizes=\"auto, (max-width: 856px) 100vw, 856px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image2.png 856w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image2.png?resize=300,149 300w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image2.png?resize=768,381 768w\" alt=\"Device Impact\" width=\"856\" height=\"425\" \/><\/p>\n<h2><strong>The propensity to pay the ransom has increased<\/strong><\/h2>\n<p>78% of state and local government organizations restored encrypted data using backups, the second highest rate of backup use reported (tied with\u00a0<em>higher education<\/em>). 54% paid the ransom to get data back. In comparison, globally, 68% used backups and 56% paid the ransom.<\/p>\n<p>The three-year view of state and local government organizations reveals a steady rise in both the use of backups and the sector\u2019s propensity to pay the ransom.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956798 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image3.png\" sizes=\"auto, (max-width: 603px) 100vw, 603px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image3.png 603w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image3.png?resize=300,200 300w\" alt=\"Ransom Payments\" width=\"603\" height=\"402\" \/><\/p>\n<p>A notable change over the last year is the increase in the propensity for victims to use multiple approaches to recover encrypted data (e.g., paying the ransom and using backups). In this year\u2019s study, 44% of state and local government organizations that had data encrypted reported using more than one method, four times the rate reported in 2023 (11%).<\/p>\n<h2><strong>Victims rarely pay the initial ransom sum demanded<\/strong><\/h2>\n<p>49 state and local government respondents whose organizations paid the ransom shared the actual sum paid, revealing that the average (median) payment was $2.2M in 2024.<\/p>\n<p>Only 20% paid the initial ransom demand. 35% paid less than the original demand, while 45% paid more. On average, across all state and local government respondents, organizations paid 104% of the initial ransom demanded by adversaries.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-956799 size-full\" src=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image4.png\" sizes=\"auto, (max-width: 572px) 100vw, 572px\" srcset=\"https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image4.png 572w, https:\/\/news.sophos.com\/wp-content\/uploads\/2024\/08\/image4.png?resize=300,191 300w\" alt=\"Ransom Demand\" width=\"572\" height=\"364\" \/><\/p>\n<p><a href=\"https:\/\/www.sophos.com\/en-us\/whitepaper\/state-of-ransomware-in-government\" target=\"_blank\" rel=\"noopener\">Download the full report<\/a>\u00a0for more insights into ransom payments and many other areas.<\/p>\n<h2><strong>Generate demand for your business<\/strong><\/h2>\n<p>Make the most of Sophos partner marketing resources to run a successful partner marketing campaign to educate your audiences and generate demand for your business. The ready-to-run campaign kit includes the pdf report, a complete PowerPoint deck, and co-brandable email templates.<\/p>\n<p><a href=\"https:\/\/partners.sophos.com\/prm\/English\/c\/the-state-of-ransomware-campaign\" target=\"_blank\" rel=\"noopener\">Access partner marketing campaign assets<\/a><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<p><strong>About the survey<\/strong><\/p>\n<p>The report is based on the findings of an independent, vendor-agnostic survey commissioned by Sophos of 5,000 IT\/cybersecurity leaders across 14 countries in the Americas, EMEA, and Asia Pacific, including 270 from the state and local government sector. All respondents represent organizations with between 100 and 5,000 employees. The survey was conducted by research specialist Vanson Bourne between January and February 2024, and participants were asked to respond based on their experiences over the previous year.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>270 IT\/cybersecurity leaders share their ransomware experiences from the last year.<\/p>\n","protected":false},"author":59,"featured_media":8150,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[12,21],"coauthors":[98],"class_list":["post-8149","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-resources","tag-campaigns","tag-threats-malware"],"_links":{"self":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/8149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/users\/59"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/comments?post=8149"}],"version-history":[{"count":1,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/8149\/revisions"}],"predecessor-version":[{"id":8151,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/posts\/8149\/revisions\/8151"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/media\/8150"}],"wp:attachment":[{"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/media?parent=8149"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/categories?post=8149"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/tags?post=8149"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/testing.eight25sites.com\/en-us\/wp-json\/wp\/v2\/coauthors?post=8149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}