Skip to main content
Guidance

NCSC Annual Review 2021

Making the UK the safest place to live and work online

Page 13 of 44

Ransomware: Ever evolving threat

In the last Annual Review, the NCSC set out how the ransomware model had shifted from not only withholding data but threatening to publish it as well. This year the model has developed further into what is termed Ransomware as a Service, (RaaS) where off-the-shelf malware variants and online credentials are available to other criminals for a one-off payment or a share of profits.

As the business model has become more and more successful, with these groups securing significant ransom payments from large businesses who cannot afford to lose their data to encryption or to suffer the down time while their services are offline, the market for ransomware has become increasingly ‘professional’.

The NCSC has observed that some victims have been offered the services (from the attackers) of a 24/7 help centre to quickly pay the ransom and get back online. Everything is geared to make it as easy as possible to simply pay the ransom and move on.

Organised crime groups spend time conducting in-depth reconnaissance on their targeted victims. They will identify exploitable cyber security weaknesses. They will use spoofing and spearphishing to masquerade as employees to get access to the networks they need. They will look for the business-critical files to encrypt and hold hostage. They may identify embarrassing or sensitive material that they can threaten to leak or sell to others. And they may even research to see if a potential victim’s insurance covers the payment of ransoms.

This process can be painstaking and lengthy, but it means that, when they are ready to deploy, the effect of ransomware on an unprepared business is brutal. Files are encrypted. Servers go down. Digital phone lines no longer function. Everything comes to a halt and business is stopped in its tracks.

But it’s not all bad news. There are many services that organisations can use to protect themselves against ransomware or mitigate the impact of an attack. As well as implementing practical cyber security measures and following advice, an important defence against ransomware is to understand the ever-evolving threat picture and working with others to share information and good practice.

The NCSC’s Cyber Security Information Sharing Partnership (CISP) service provides a secure forum where companies and government can collaborate on threat information. CISP, which also gives access to regular sensitive threat reports, is one of many tools available, as can be seen in the next chapter.





Published

Reviewed

Version

1.0

Written for