Close Menu

    Subscribe to Updates

    Get the latest tech news

    Facebook X (Twitter) Instagram
    TechArenaTechArena
    • Home
    • News
    • Reviews
    • Features
      • Top 5
    • Startups
    • Contact
    Facebook X (Twitter) Instagram
    TechArenaTechArena
    Home»News»Sophos Survey Reveals the Median Recovery Costs for Critical Infrastructure Sectors Quadruples to $3 Million in 1 Year
    News

    Sophos Survey Reveals the Median Recovery Costs for Critical Infrastructure Sectors Quadruples to $3 Million in 1 Year

    Kaluka wanjalaBy Kaluka wanjalaJuly 19, 2024Updated:August 25, 20254 Mins Read
    Facebook Twitter Telegram LinkedIn WhatsApp Email Pinterest
    Sophos
    Share
    Facebook Twitter LinkedIn WhatsApp Telegram

    Sophos has released a sector survey report, “The State of Ransomware in Critical Infrastructure 2024,” which revealed that the median recovery costs for two critical infrastructure sectors, Energy and Water, quadrupled to $3 million over the past year. This is four times higher than the global cross-sector median. In addition, 49% of ransomware attacks against these two critical infrastructure sectors started with an exploited vulnerability.

    Data for the State of Ransomware in Critical Infrastructure 2024 report comes from 275 respondents at energy, oil and gas, and utilities organizations, which fall under the Energy and Water sectors of CISA’s 16 defined critical infrastructure sectors. The results for this sector survey report are part of a broader, vendor-agnostic survey of 5,000 cybersecurity/IT leaders conducted between January and February 2024 across 14 countries and 15 industry sectors.

    “Criminals focus where they can cause the most pain and disruption so the public will demand quick resolutions, and they hope, ransom payments to restore services more quickly. This makes utilities prime targets for ransomware attacks. Because of the essential functions they provide, modern society demands they recover quickly and with minimal disruption,” said Chester Wisniewski, global Field CTO.

    “Unfortunately, public utilities are not only attractive targets but vulnerable to attacks on many fronts, including the requirement for high availability and safety, as well as an engineering mindset focused on physical security. There’s a preponderance of older technologies configured to enable remote management without modern security controls like encryption and multifactor authentication. Like hospitals and schools these utilities are frequently operating with minimal staffing and without the IT staffing required to stay on top of patching, the latest security vulnerabilities and the monitoring required for early detection and response.”

    On top of growing recovery costs, the median ransom payment for organizations in these two sectors jumped to more than $2.5 million in 2024 $500,0000 higher than the global cross-sector median. The Energy and Water sectors also reported the second highest rate of ransomware attacks. Overall, 67% of the organizations in these sectors reported being hit by ransomware in 2024, in comparison to the global, cross-sector average of 59%.

    Other findings from the report include:

    • The energy and water sectors reported increasingly longer recovery times. Only 20% of organizations hit by ransomware were able to recover within a week or less in 2024, compared to 41% in 2023 and 50% in 2022. Fifty-five percent took more than a month to recover, up from 36% in 2023. In comparison, across all sectors, only 35% of companies took more than a month to recover 
    • These two critical infrastructure sectors reported the highest rate of backup compromise (79%) and the third highest rate of successful encryption (80%) when compared to the other industries surveyed

    “This once again shows that paying ransom payments almost always works against our best interests. An increasing number (61%) paid the ransom as part of their recovery, yet the amount time it took to recover was extended. Not only do these high rates and amounts of ransoms encourage more attacks on the sector, but they are not achieving the claimed goal of shorter recovery times,” said Wisniewski.

    “These utilities must recognize they are being targeted and take proactive action to monitor their exposure of remote access and network devices for vulnerabilities and ensure they have 24/7 monitoring and response capabilities to minimize outages and shorten recovery times. Incident response plans should be planned in advance, the same as for fires, floods, hurricanes and earthquakes, and be rehearsed on a regular schedule.”

    Read: 76% of Companies Improved Their Cyber Defenses to Qualify for Cyber Insurance, Sophos Survey Finds

    sophos
    Kaluka wanjala
    • Website
    • Facebook
    • X (Twitter)
    • LinkedIn

    Editor at TechArena. I cover all things technology and review new gadgets as I get them. You can reach me on email: [email protected]

    Related Posts

    Absa, Microsoft and Women in Tech Expand ElevateHer AI Programme Across Nine African Markets

    February 6, 2026

    LG Positions Africa as Key Growth Frontier for AI-Powered Smart Home Expansion at InnoFest 2026 MEA

    February 6, 2026

    Cellulant Appoints Michael Muriuki as Chief Product & Technology Officer

    February 6, 2026

    Comments are closed.

    Latest Posts

    Absa, Microsoft and Women in Tech Expand ElevateHer AI Programme Across Nine African Markets

    February 6, 2026

    LG Positions Africa as Key Growth Frontier for AI-Powered Smart Home Expansion at InnoFest 2026 MEA

    February 6, 2026

    Cellulant Appoints Michael Muriuki as Chief Product & Technology Officer

    February 6, 2026

    Pin Up how to play and win instructions for experienced players

    February 6, 2026
    Advertisement
    Editor's Pick

    Deepfake Scams and AI-Generated Malware Are Now Top Cyber Risks for Kenya, ESET Warns

    February 5, 2026

    The Smartphone as an AI Platform: What On-Device AI Really Means for Africa

    February 4, 2026

    What You Need to Know About Kenya’s National Electric Mobility Policy (e-Mobility Policy)

    February 4, 2026

    How Data Centers Are Reshaping Africa’s Power Market

    February 2, 2026
    © 2026 TechArena.. All rights reserved.
    • Home
    • Startups
    • Reviews

    Type above and press Enter to search. Press Esc to cancel.