No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Allianz Report Finds Companies Need Stronger Controls to Stem Ransomware Tide

No Reason to Hope Ransomware Will Simply Fade Away in the Future, Cyber Insurer Predicts

by Corporate Compliance Insights
October 19, 2021
in Cybersecurity
Allianz Report Finds Companies Need Stronger Controls to Stem Ransomware Tide

Multiple factors are pushing ransomware, including growing attack patterns that include double and triple extortion, criminal business models taking advantage of ransomware, cryptocurrencies and wave of supply chain attacks

During the COVID-19 crisis, another outbreak took place in the cyber space: a digital pandemic driven by ransomware. In a new report, cyber insurer Allianz Global Corporate & Specialty (AGCS) has analyzed the latest risk developments around ransomware to put the scale of the crisis into scope.

The increasing frequency and severity of ransomware incidents is driven by several factors, the Allianz report determines:

  • Growing number of different attack patterns such as double and triple extortion campaigns
  • Criminal business model around ‘ransomware as a service’ and cryptocurrencies
  • Recent skyrocketing of ransom demands
  • Rise of supply chain attacks

“The number of ransomware attacks may even increase before the situation gets better,” said Scott Sayce, global head of cyber at AGCS. “Not all attacks are targeted. Criminals also adopt a scattergun approach to exploit those businesses that aren’t addressing or understanding the vulnerabilities they may have. As insurers we must continue to work with our clients to help businesses understand the need to strengthen their controls. At the same time, in today’s rapidly evolving cyber insurance market, providing emergency response services, as well as financial compensation, is now the standard.”

Government and private data indicate that ransomware and other attacks have surged, and these cyber risk trends are mirrored in AGCS’ claims experience. AGCS was involved in more than 1,000 cyber claims overall in 2020, up from about 80 in 2016, the company said. Specifically, the number of ransomware claims (90) rose by 50 percent compared to 2019 (60). Losses resulting from external cyber incidents such as ransomware or distributed denial of service (DDoS) attacks account for most of the value of all cyber claims analyzed by AGCS over the past six years.

Five Ransomware Trends

In the report, AGCS identifies five trends in the ransomware space, although the company points out that cyber criminals are clever and highly adaptable, which means conditions are constantly evolving.

  • Ransomware as a service: Run like a commercial business, hacker groups such as REvil and Darkside sell or rent their hacking tools to others. They also provide a range of support services. As a result, many more malicious threat actors are operating.
  • From single to double to triple extortion: Criminals combine the initial encryption of data or systems, or increasingly even their backups, with a secondary form of extortion, such as the threat to release sensitive or personal data. In such a scenario, affected companies have to manage the possibility of both a major business interruption and a data breach event, which can significantly increase the final cost of the incident. “Triple extortion” incidents can combine DDoS attacks, file encryption and data theft — and don’t just target one company but potentially customers and business partners.
  • Supply chain attacks the next big thing: There are two main types — those that target software/IT services providers and use them to spread the malware (for example, the Kaseya or SolarWinds attacks) — and those that target physical supply chains or critical infrastructure such as the one that impacted Colonial Pipeline. Service providers are likely to become prime targets as they often supply hundreds or thousands of businesses with software solutions and therefore offer criminals the chance of a higher payout.
  • Ransom dynamics: Ransom demands have rocketed over the past 18 months, which could make these attacks more enticing.
  • To pay or not to pay: Ransom payment is a controversial topic. Law enforcement agencies typically advise against paying extortion demands to avoid incentivizing attacks. Even when a company decides to pay a ransom, the damage may have already been done. Restoring systems and enabling the recovery of the business is a huge undertaking, even when a company has the decryption key.

Business Interruption and Recovery Cost Main Drivers of Losses

Business interruption and restoration costs are the biggest drivers behind cyber losses such as ransomware attacks, according to AGCS claims analysis. They account for over 50 percent of the value of close to 3,000 insurance industry cyber claims worth around $885 million the company has been involved in over six years.

The average total cost of recovery and downtime — on average 23 days — from a ransomware attack more than doubled over the past year, increasing from $761,106 to $1.9 million in 2021.

The surge in ransomware attacks in recent years has triggered a major shift in the cyber insurance market. Cyber insurance rates have been rising, according to broker Marsh, while capacity has tightened. Underwriters are placing increasing scrutiny on the cyber security controls employed by companies.

Tags: Cyber RiskCybercrimeRisk AssessmentTechnology
Previous Post

Allianz Cyber Insights Ransomware Trends: Risk and Resilience

Next Post

Proposed Inter-Agency Guidance Would Rewrite the Book on Third-Party Risk Management and Raise the Bar for SOC 2 Compliance

Corporate Compliance Insights

Corporate Compliance Insights

Corporate Compliance Insights

Related Posts

website opt out banner

New CIPA Claims Expand Privacy Litigation Risk Over Website Consent Banners

by Andrew Chase
July 17, 2026

A lawsuit against Ace Hardware demonstrates the claims that can be brought against organizations under new California laws

hand checking off checklist

10 Questions Every Organization Should Ask a Potential AI Vendor

by Angela Juneau
July 15, 2026

Adopting AI without understanding how it was built and how it handles data can expose an organization to risks that...

manchester uk terrorist attack flowers

Martyn’s Law: What New Anti-Terrorism Guidance Means for Event Organizers

by Liam Lane and Constance Strasser
July 14, 2026

Ahead of the act's expected entry into force next year, the guidance signals a cultural shift: counterterrorism preparedness embedded into...

nist sign building

NIST Database Change Rebalances Burden of Risk

by Nichole Windholz
July 13, 2026

Register of common vulnerabilities and exposures will have less federal context, leaving organizations to decide if a vulnerability warrants quick...

Next Post
close up shot of a dollar bill

Proposed Inter-Agency Guidance Would Rewrite the Book on Third-Party Risk Management and Raise the Bar for SOC 2 Compliance

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights