Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Ransomware is Increasing & Evolving – How Do We Keep Up? current page
Link copied

Ransomware is Increasing & Evolving – How Do We Keep Up?

Apr 27, 2021
Author:
Dan Stern 200X200
Dan Stern
Vice President of IT, Infrastructure and Services at AirMethods
Blog banner default
Ransomware is Increasing & Evolving – How Do We Keep Up?
Dan Stern 200X200
Dan Stern
Vice President of IT, Infrastructure and Services at AirMethods

On the coattails of some major vulnerabilities, we have seen ransomware attacks surge 150% in 2020, and they show no signs of relenting. The new attacks are hitting large businesses, school districts, and local governments. Interviews with security professionals have turned downright pessimistic as some pros report they are seeing attacks “faster than we can count”.

As an industry, we are failing to keep up with attackers. While vulnerabilities are being published and organizations know the price if they fail to patch, recent vulnerabilities have been at the highest end of criticality and require immediate—sometimes business-impacting—patching to avoid standing out as a prominent target.

Today, ransomware as a service proliferates and ransomware kits are easily bought online. These growing ransomware business models and markets now make it easy to develop and acquire ransomware. And it was already easy to deploy ransomware through email and other common attacks, in addition to using the newer and pervasive vulnerabilities for direct injection of malware.

Many modern threat actors are looking to achieve something different than in years past. The target and attack types are not what we saw a few years ago, when encrypting individual user computers netted attackers a few hundred dollars per victim. While the payout rates have stayed relatively constant with close to half of victims paying the ransom, the ransom amounts and the targets have become much larger and we are now seeing negotiations in the tens of millions of dollars. In fact, the average ransomware payout amounts almost tripled from 2019 to 2020.

Attackers know they have leverage, and they are even targeting insured organizations to specifically seek ransom payments within insurance policy coverage. While relatively new, this adjustment puts organizations - even large, mature, stable, insured companies - in an almost unwinnable position.

Ransomware can be introduced into our environments through many different attack vectors, so no one technology or solution can provide complete ransomware protection. Law enforcement isn’t identifying, prosecuting, and sentencing, enough attackers in this space to deter future attempts. And organizations with mature backup programs still aren’t recovering quickly enough to offset the impact of ransomware attacks.

We need to think differently about the threat and how we prepare and respond. We must know and understand our own systems, have a ransomware specific incident response plan, and continue being creative in designing robust and multi-tiered backups.

Additionally, organizations should assume they will be victimized by ransomware -- not if, but when. We should all have a “kill switch” to shut down all systems and aid in containment when it happens. Because today, we are not containing and we are certainly not succeeding.

For a deeper dive on this topic, please check out my on-demand webinar: The Brutal Wave of Ransomware & How Attacks are Evolving


Learn how BeyondTrust Privileged Access Management (PAM) platform provides powerful, blended ransomware threat protection by securing remote access, enforcing least privilege, and protecting privileged credentials:

https://www.beyondtrust.com/solutions/ransomware


Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • Cloud Integration: Okta + PowerBroker for Unix & Linux for Authorization and Command Control
    Aug 2, 2018 Cloud Integration: Okta + PowerBroker for Unix & Linux for Authorization and Command Control
    Blog
    1m
  • Effectively Administer Windows  - Without Domain Admin Privileges
    Sep 3, 2019 Effectively Administer Windows - Without Domain Admin Privileges
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.