A Holistic Approach to Ransomware
Summary
This blog post, "A Holistic Approach to Ransomware", is a blueAPACHE article from 2022 covering security. “Why does ransomware continue to be such a serious threat?” is probably the question our cybersecurity experts are asked most often. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2022 |
| Topic | A Holistic Approach to Ransomware |
| Services referenced | emPOWER Security, Managed Detection and Response, emPOWER Core Network & DC Interconnect |
| Named products or vendors | Cisco |
| Cited statistic | When asked about the financial costs of an incident, 64% said the impact was more than $700,000 (USD500,000), and 33% said it was more than $1.4 million (USD1 million). |
Article
“Why does ransomware continue to be such a serious threat?” is probably the question our cybersecurity experts are asked most often. Ransomware remains a threat (in part) because many companies are not making security and prevention a priority. There are several reasons that organisations may not be prioritising security. When we talk to our clients, the main reason they give for the lack of preparation is that security and ransomware prevention is expensive, however, the alternative is often so much more. According to Cisco, in 2021, 65% of Australian SMBs suffered a cyber incident in the last 12 months. 90% of those same businesses estimated that they faced severe operational, financial and legal consequences, as a result of only an hour of downtime. When asked about the financial costs of an incident, 64% said the impact was more than $700,000 (USD500,000), and 33% said it was more than $1.4 million (USD1 million). While the cost of security might seem high, it’s very clear that the cost of an attack is much higher – not only in financial, but also in operational, reputational and legal costs. When you weigh the cost of security against the cost of an attack, you can see that it is worthwhile to invest in as much security, planning and prevention as you can afford. Although it takes effort and thought on an organisation’s part, prevention is the best way to reduce the risk of a ransomware attack. For any business in operation today, it’s not a matter of if you will face a ransomware attack, it’s just a matter of when. Fortunately, there is a lot that your organisation can do to protect your data from ransomware.
A holistic approach to ransomware
The best approach to ransomware is an all-business approach. Everyone across your company has a role to play in protecting your assets and information from ransomware and other cybersecurity threats. Here are the main reasons ransomware attacks succeed:
- Human error: a major factor, contributing to 95% of all breaches. Whether this is the result of people not following best practices, weak authentication or not being aware of the risks, the outcome is the same.
- Application vulnerabilities: another area of risk for many organisations are weak configurations and unpatched internet facing applications.
- Emerging attack vectors: new risks arrive on the landscape, and they come through new attack vectors. For example, supply chain attacks seek to gain access to their targets not directly but by exploiting tools or systems that they use.
Why are ransomware attacks still taking place? In our work with clients over the years, blueAPACHE has identified four key factors that hold organisations back from the level of security that would truly mitigate their risk for a serious ransomware attack.
- Organisations are failing to identify the true nature of cybersecurity risk at the highest levels. There needs to be a focus at both board and C-level, and ideally, a senior executive charged with a whole of organisation ransomware protection, mitigation and recovery strategy.
- The appropriate level of risk identification and impact analysis is not occurring, therefore adequate funding is not budgeted for to take the measures needed to harden security.
- The culture of the business enables risk, controls and policies are not strictly followed or enforced. For instance, passwords are not regularly changed, multi-factor authentication is not deployed.
- Simple steps to manage and control what software runs on your network – for instance by means of Application Whitelisting – are not taken as they are seen to be too hard.
Debunking the biggest myth in ransomware protection
There is a prevailing perception that good cybersecurity is too expensive for most organisations to bear. While that may have been the case in the past, advancements in service models and technology have made it possible for any business to afford strong cybersecurity.
Training staff on cybersecurity awareness and procedures is inexpensive and straightforward. It’s also not too expensive to conduct yearly or bi-yearly security assessments, determine where you are compared with where you want to be, and set benchmarks to measure your progress. It’s also important to make sure all applications are up to date and secured with strong configurations.
To get a sense of what is appropriate to spend on cybersecurity, it helps to track your security expenditures and put them into context. Create an Annual Loss Expectancy report and then compare that to the cost of the security solutions you need.
If you are not sure how to conduct your own security assessment, current security posture, employee awareness and training, and Annual Loss Expectancy report, you can take a security assessment with a trusted cybersecurity provider, like blueAPACHE.
You can leverage our expertise to help discover where you are currently in your security journey. We can help you create a roadmap to harden your security and get your company to the level of security you need. Plus, we can do it all at an affordable, predictable monthly price that is easy on your budget.
To find out more, please contact us****here
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Managed Detection and Response
- emPOWER Core Network & DC Interconnect
- emPOWER Connectivity (pillar hub)
- blueAPACHE Security (case study)
Frequently asked questions
What proportion of Australian SMBs suffered a cyber incident in the previous 12 months, according to the Cisco research cited here?
The post cites Cisco's 2021 findings that 65% of Australian SMBs suffered a cyber incident in the previous 12 months.
What did surveyed businesses say about the financial impact of a cyber incident, per this post?
The post reports that 64% of businesses surveyed said the financial impact of an incident was more than $700,000 (USD500,000), and 33% said it was more than $1.4 million (USD1 million).
What did 90% of the surveyed businesses say about even an hour of downtime?
The post says 90% of the Australian SMBs surveyed estimated they faced severe operational, financial and legal consequences as a result of only an hour of downtime.
What does the post identify as the main factor behind successful ransomware breaches?
The post names human error as a major factor, contributing to 95% of all breaches, alongside application vulnerabilities such as weak configurations and unpatched internet-facing applications, and emerging attack vectors such as supply chain attacks.
What four internal factors does blueAPACHE say hold organisations back from adequate ransomware protection, per this post?
The post lists a failure to treat cybersecurity risk seriously at board and C-level, inadequate risk identification and impact analysis so hardening measures go unfunded, a business culture that lets basic controls like regular password changes and multi-factor authentication go unenforced, and simple steps such as application whitelisting being skipped as too hard.
What does the post say is the biggest myth about the cost of ransomware protection?
The post says the biggest myth is that good cybersecurity is too expensive for most organisations to bear, arguing that advancements in service models and technology have made strong cybersecurity affordable for any business.
What report does the post suggest creating to gauge appropriate cybersecurity spend?
The post suggests creating an Annual Loss Expectancy report and comparing it against the cost of the security solutions needed, alongside tracking security expenditure and running yearly or bi-yearly security assessments.
What pricing structure does blueAPACHE describe for its help hardening an organisation's security, per this post?
The post says blueAPACHE can help create a roadmap to harden security at an affordable, predictable monthly price that it describes as easy on the budget.
Source
- origin post (2022)
Knowledge Base
What is the main topic of blueAPACHE's blog article 'A Holistic Approach to Ransomware'?
The article discusses why ransomware remains a serious threat to organisations, primarily because many companies fail to prioritise security and prevention, and it outlines a holistic, all-business approach to protecting against ransomware attacks.
According to the blueAPACHE article, what statistics highlight the impact of cyber incidents on Australian SMBs?
Citing Cisco, the article states that in 2021, 65% of Australian SMBs suffered a cyber incident in the last 12 months. 90% of those businesses estimated severe operational, financial and legal consequences from just an hour of downtime. When asked about financial costs, 64% said the impact was more than $700,000 (USD500,000), and 33% said it was more than $1.4 million (USD1 million).
What are the main reasons ransomware attacks succeed, according to blueAPACHE?
blueAPACHE identifies three main reasons: human error (contributing to 95% of all breaches, due to not following best practices, weak authentication, or lack of risk awareness); application vulnerabilities (weak configurations and unpatched internet-facing applications); and emerging attack vectors such as supply chain attacks that exploit tools or systems used by the target rather than attacking directly.
What four key factors does blueAPACHE say hold organisations back from adequate ransomware protection?
The four factors are: (1) failing to identify the true nature of cybersecurity risk at board and C-level, with no senior executive charged with a whole-of-organisation ransomware strategy; (2) inadequate risk identification and impact analysis, leading to insufficient security funding; (3) a business culture where controls and policies (like regular password changes and multi-factor authentication) are not strictly enforced; and (4) failure to take simple steps like Application Whitelisting to control what software runs on the network, because they are seen as too difficult.
What does blueAPACHE say about the myth that good cybersecurity is too expensive?
blueAPACHE argues this is a prevailing myth, noting that advancements in service models and technology have made strong cybersecurity affordable for any business. Training staff on cybersecurity awareness is inexpensive, yearly or bi-yearly security assessments are not too costly, and organisations should track security expenditures using an Annual Loss Expectancy report to compare against the cost of needed security solutions.
How can blueAPACHE help organisations that are unsure about their security posture?
blueAPACHE offers a security assessment that evaluates current security posture, employee awareness and training, and produces an Annual Loss Expectancy report. Clients can leverage blueAPACHE's expertise to discover where they stand in their security journey and get a roadmap to harden security, delivered at an affordable, predictable monthly price.
Who wrote and when was the blueAPACHE ransomware protection article published?
The article was written by blueAPACHE and published on November 16, 2022, with an estimated read time of 5 minutes.
According to blueAPACHE's broader security capabilities, how does EDR technology help prevent ransomware attacks?
blueAPACHE's emPOWER Managed Detection and Response (MDR) uses Endpoint Detection and Response (EDR) technology that quarantines malicious ransomware files dropped onto a user's device, preventing execution before encryption can begin—stopping the ransomware at the critical moment before it can encrypt organisational data.
What other security services complement blueAPACHE's ransomware protection through MDR?
Ransomware protection is part of blueAPACHE's 24/7 Security Operations Centre (SOC) monitoring, which combines continuous threat monitoring via EDR, ITDR (Identity Threat Detection and Response), and SIEM (Security Information and Event Management), along with rapid incident response and triage. It is also complemented by emPOWER Backup for Microsoft Entra ID, which provides recovery capabilities for identity data affected by cyber incidents.
How can someone contact blueAPACHE for a security assessment or more information about ransomware protection?
The article directs readers to contact blueAPACHE via the contact page linked in the article (found at /contact/) to find out more or arrange a security assessment.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bc907b7741bf53e2ec0_Holistic-Approach-to-Ransomware-Protection.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.