Skip to content

What is the EU Digital Operational Resilience Act (DORA)?

The Digital Operational Resilience Act (DORA) is a regulatory framework enacted by the European Union aimed at increasing the cyber resilience of financial services institutions. Effective from January 17, 2025, DORA (EU regulation 2022/2554) mandates that financial organizations within the EU enhance their operational resilience against disruptions such as cyberattacks, emphasizing recovery and continuity over traditional detect-and-protect methods.

By mandating stringent standards for information and communication technology (ICT) risk management, incident reporting, resilience testing, and third-party service provider oversight, DORA will ensure that the financial sector in Europe can maintain business continuity during and after serious operational disruptions. 

Who must comply with DORA standards? 

Under DORA, a wide range of financial entities — including banks, insurance firms, investment companies, cryptocurrency exchanges, trading platforms, and other critical service providers — must comply with rigorous standards to ensure operational stability. This comprehensive regulation spans organizational, technical, operational, and people-related aspects.

This regulation necessitates comprehensive changes in how financial institutions approach ICT risk management, incident reporting, resilience testing, third-party risk management, and information sharing. By integrating these elements into their operational strategies, organizations can better prepare for and mitigate the impacts of potential cyber threats, thereby maintaining the stability and integrity of the financial system across the EU.

DORA represents a significant shift towards a more resilient and secure financial sector, encouraging proactive measures and collaborative efforts to combat cyber threats effectively.

5 key DORA regulation requirements, with relevant chapters and articles 

  • ICT risk management: Chapter II, Articles 5 to 16 
  • Incident reporting: Chapter III, Articles 17 to 23 
  • Resilience testing: Chapter IV, Articles 24 to 27 
  • Third-party risk management: Chapter V, Articles 28 to 44 
  • Information sharing: Chapter VI, Article 45 

  

The DORA framework is structured around five primary pillars spanning articles and chapters of the regulation in the Official Journal of the EU. Reference this resource to read more about the specific articles.

The regulation’s objectives for strengthening EU financial entities are achieved through:

1. ICT risk management: This pillar emphasizes the development of a comprehensive ICT risk management framework. This framework should encompass strategies, policies, procedures, protocols, and tools necessary, including backup and restore procedures, for safeguarding ICT systems. The management body, typically the board of directors, holds the responsibility for this framework. Although the bulk of DORA requirements falls under IT teams, the risk management function must integrate these requirements into the overall risk management strategies of the company. 

2. ICT-related incident management and reporting: This component requires firms to classify and report all significant ICT-related incidents to the appropriate supervisory authorities. A “major” incident is defined as one that significantly impacts the network and information systems supporting critical or important functions of the entity. Firms must provide an initial notification, an interim progress report, and a final report analyzing the incident’s root causes. This standardization aims to improve incident response and management processes.

3. Operational resilience testing: Annual testing of ICT systems is mandated to evaluate the effectiveness of a firm’s digital operational resilience. These tests should include gap analyses and vulnerability assessments. Larger organizations must conduct threat-led penetration testing (TLPT) every three years. While many companies already perform some level of resilience testing, DORA sets specific requirements that may necessitate changes to existing practices.

4. Third-party risk management: Integrating third-party risk management into the company’s ICT risk framework is essential. Financial entities must thoroughly assess potential ICT service providers before entering into contractual agreements. This involves ensuring that contracts address the use of ICT systems or processes critical to important functions, comply with supervisory requirements, and identify and mitigate associated risks. Additionally, firms must maintain a detailed register of all contractual agreements related to ICT services.

5. Information sharing: DORA encourages, but does not mandate, the sharing of cyberthreat information and intelligence among financial entities. This sharing should occur within trusted communities and be formalized through structured arrangements. Any shared information must be reported to the relevant supervisory authorities, promoting a collaborative approach to enhancing digital operational resilience.

How DORA impacts the financial sector of the European Union 

 

DORA significantly reshapes cybersecurity for the European financial sector, introducing strict measures to enhance operational resilience and ensure robust protection against cyberthreats:

  • Enhanced cybersecurity and resilience: DORA mandates that financial entities implement robust cybersecurity measures to ensure their systems can withstand and recover from cyber threats and incidents. This includes regular testing, incident reporting, and continuous monitoring to identify vulnerabilities and mitigate risks promptly.
  • Standardization across member states: By establishing uniform requirements for digital operational resilience, DORA eliminates discrepancies between national regulations. This harmonization ensures a level playing field for financial institutions operating across different EU countries, facilitating smoother cross-border operations and compliance.
  • Third-party risk management: DORA emphasizes the need for financial entities to manage risks associated with third-party ICT service providers. This includes rigorous due diligence, contractual arrangements, and continuous oversight of third-party services to ensure they meet the required resilience standards.
  • Regulatory oversight and reporting: The regulation introduces stringent reporting requirements for significant ICT-related incidents. Financial entities must report such incidents to the relevant authorities within a specific timeframe. This improves transparency and allows regulators to monitor and respond to systemic risks more effectively.
  • Operational resilience testing: Financial institutions are required to conduct regular operational resilience testing, including advanced threat-led penetration testing (TLPT). This helps in identifying and addressing weaknesses in their ICT infrastructure before they can be exploited by malicious actors.
  • Governance and control: DORA places a strong emphasis on governance, requiring financial entities to establish comprehensive ICT risk management frameworks. This involves the appointment of senior-level responsibility for overseeing digital operational resilience and ensuring that ICT risk management is integrated into the overall risk management framework of the institution.
  • Increased accountability: The regulation increases the accountability of financial institutions and their management. By stipulating clear roles and responsibilities for managing digital operational resilience, DORA ensures that senior management and boards of directors are directly accountable for their organization’s cybersecurity posture.
  • Consumer protection: By enhancing the resilience of financial institutions, DORA indirectly protects consumers from the fallout of cyber incidents, such as data breaches and service disruptions. This fosters greater trust in the financial system and ensures the stability and integrity of financial services.
  • Innovation and competition: While DORA imposes stringent requirements, it also encourages innovation by fostering a secure environment where financial technology (fintech) firms and traditional financial institutions can thrive. By providing clear guidelines, DORA helps fintech firms navigate the regulatory landscape, thus promoting healthy competition and innovation in the financial sector.
  • Compliance and penalties: Non-compliance with DORA can lead to significant penalties, potentially reaching up to 2% of an entity’s total annual global turnover. The severity of the fine will correlate with the seriousness of the breach and the institution’s level of cooperation with regulatory authorities. Financial entities must therefore invest in compliance programs, which may involve substantial initial costs but ultimately lead to a more secure and resilient operational environment.

DORA represents a comprehensive approach to enhancing the digital operational resilience of the financial sector in the EU. It ensures that financial institutions are better prepared to tackle cyberthreats and operational disruptions, thereby maintaining the stability and integrity of the financial system. By harmonizing regulations across member states and emphasizing robust risk management practices, DORA not only safeguards financial entities but also bolsters consumer confidence and fosters innovation in the financial sector.

Additional DORA regulation resources, such as the status of DORA implementation, can be found via the European Banking Authority. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Can your cloud provider accidentally delete your data?

In May 2024, UniSuper, an Australian superannuation fund managing $135 billion for 647,000 members, faced an unprecedented crisis when their entire Google Cloud account — including backups — was suddenly gone. Surprisingly, the culprit wasn’t ransomware or a cyberattack.

What happened to an entire company’s Google Cloud account?

Rather, a misconfiguration within Google Cloud’s system led to the deletion of UniSuper’s entire account. This “one-of-a-kind event,” as described by Google, wiped out UniSuper’s cloud subscription and its backups stored across multiple geographic locations.

The result was a nearly two-week outage that left members without access to their accounts.

Timeline and response

The ordeal began on May 2, when UniSuper’s online systems went offline. Members were unable to check their superannuation accounts, leading to concerns and frustration. On May 8, UniSuper CEO Peter Chun and Google Cloud CEO Thomas Kurian issued a joint statement explaining the situation. They clarified that the outage wasn’t due to a cyberattack and that no personal data had been exposed. Instead, an internal error within Google Cloud’s provisioning system caused the deletion.

On May 15, full restoration of services was achieved, and UniSuper members could access their accounts once again.

Apology and assurance

Chun and Kurian apologized for the “extremely frustrating and disappointing” disruption, emphasizing that it was an isolated incident with no precedent among Google Cloud’s clients globally. They assured stakeholders that Google Cloud had identified the sequence of events leading to the deletion and had implemented measures to prevent such occurrences in the future.

Restoration efforts

Restoring services was a monumental task. Despite having duplication measures to protect against data loss and outages, the deletion affected all backups across both geographic locations where UniSuper’s data was stored.

Typically, such duplication ensures that if one service goes down, it can be restored from another location. However, in this case, all duplicated data was lost simultaneously because it was stored within the same logical infrastructure (i.e., same cloud) rather than being protected via a multi-cloud setup.

Backup and recovery

Fortunately, UniSuper had maintained additional backups with an independent third-party provider, which proved to be the saving grace and played a crucial role in the recovery process.

These external backups minimized data loss and significantly aided UniSuper and Google Cloud in restoring core systems.

Per UniSuper’s official statement, ‘UniSuper had backups in place with an additional service provider. These backups have minimised data loss and significantly improved the ability of UniSuper and Google Cloud to complete the restoration.’

Lessons learned

This incident highlights the critical importance of having a robust, multi-layered backup strategy in line with the 3-2-1 backup principle, particularly for organizations handling sensitive and substantial financial data. Relying solely on a single cloud provider for backup, even one as reputable as Google Cloud, can pose significant risk.

The adage of “don’t keep all your eggs in one basket” applies: Don’t keep all your data and backups in the same logical infrastructure. Backups must be kept in a separate cloud. Implementing a third-party, independent cloud backup solution provides an essential safety net — also known as air gapping. Read why air gapping is your best defense.

How do you ensure business continuity?

Following data protection best practices (such as data immutability) and leveraging multi-cloud data protection solutions ensures access to business-critical data. One such solution is Keepit, which offers comprehensive and easy, guaranteed access to backups.

Keepit’s platform ensures that all data is readily available online, allowing administrators to provide employees with direct links to their data, enabling rapid restoration of the most business-critical information.

This means employees can continue working seamlessly without waiting for a full system restore, prioritizing critical tasks such as email access and other essential functions.

 

Conclusion

UniSuper’s experience is a stark reminder of the potential data protection gaps when relying on one single cloud service for SaaS backup. A robust disaster recovery plan must include independent cloud backups to ensure data can be restored quickly and efficiently from multiple sources, thereby providing the ability to recover no matter what happens, be it ransomware or misconfiguration.

The UniSuper incident underscores the need for comprehensive data protection strategies.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Greener backup services with efficient code

The following is an abridged version of my recent article, “Tapping the potential of code for greener backup services,” which is published, in full, with Computer Weekly.

The language of sustainability 

Sustainability goes beyond green energy; it includes building efficient, reliable, and adaptable systems. Using C++ as the primary programming language enables the development of storage systems that minimize resource usage while maximizing performance and reliability.

Efficient architecture and programming 

Sustainability is about optimizing efficiency at every operational level to minimize resource consumption while maximizing performance and profitability. C++ helps create sustainable, scalable architectures, reducing environmental impact and avoiding legacy inefficiencies.

Purpose-built architecture 

The key to sustainable data management is purpose-built architecture, tailored to address storage challenges efficiently. Deduplication, eliminating redundant data, is crucial. This approach streamlines operations, reduces complexity, and lowers resource consumption compared to virtual machines provided by third-party platforms.

Choosing efficient programming languages 

Efficiency extends to programming languages. C++, known for its performance and low resource utilization, can yield significant energy savings compared to resource-intensive languages. Its versatility, low-level access to system resources, and support for high-level abstractions make it ideal for developing efficient and scalable software.

Avoiding legacy inefficiencies 

Legacy systems introduce complexity and inefficiencies, increasing costs and energy consumption. By maintaining full ownership and control of the technology stack, companies can streamline operations and minimize resource overhead, prioritizing lean, purpose-built architectures that deliver long-term benefits.

Performance as a priority 

Optimizing resource usage is essential for long-term sustainability, especially with the increasing volume of data. Meticulous design of storage architecture and code optimization are necessary. Off-the-shelf solutions may offer quick fixes, but efficient code is crucial for addressing core issues sustainably.

The impact of code on sustainability and cost 

Adopting sustainable practices in architecture design and programming languages reduces energy consumption, predicts costs, and simplifies compliance. Techniques like incremental backup and deduplication enhance efficiency, sustainability, and profitability. C++ enables the creation of resource-efficient, fast, and environmentally sustainable storage systems.

Conclusion 

Prioritizing responsible resource consumption and operational efficiency allows technology companies to lead in environmental stewardship without compromising profitability. By integrating sustainable practices, we can foster a more environmentally conscious tech industry for future generations. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

What’s keeping CISOs up at night?

Introduction 

Cybersecurity is no longer a siloed concern relegated to IT departments; it’s a fundamental component of business strategy. Chief information security officers (CISOs) face mounting pressures to not only protect their organizations but also to integrate cybersecurity into the broader business framework.

This is the focus of our recent webinar, “The CISO balancing act: How to tackle rising cybersecurity pressures in 2024,” where industry experts share insights and strategies. Read further for a summary highlighting the key takeaways.

Watch the on-demand webinar

Strategies for CISOs navigating cybersecurity challenges

As the digital landscape expands, so do the complexities of managing cybersecurity. We’re seeing a mix of longstanding challenges and new, emerging threats that are putting unprecedented pressure on security professionals worldwide.

Our on-demand webinar provides strategic and operational insights based on extensive research and interviews with over 30 top security professionals from organizations around the globe. Whether you’re a CISO, a security analyst, or a business leader, these compiled insights will help you navigate the obstacles ahead.

Join Mark Renouf, former BBC journalist and contributor, as he engages with industry experts Tim Rhodes, managing director at Apprize360, and Kim Larsen, CISO at Keepit, to discuss key takeaways from the study, such as:

  • Decisions to consider as you prepare for both known and unknown threats. 
  • Key components of a resilient security framework that adapts to both current needs and future technologies. 
  • How to identify solid best practices to embrace. 

 

 

The importance of a data governance framework

One of the most pressing challenges identified in the webinar is the need for a robust data governance framework. This is highlighted as a top priority by nearly all the CISOs and IT leaders interviewed.

Key points:

  • Customization and scalability: Organizations need data governance frameworks tailored to their specific needs, which can grow and evolve with them.
  • Deployment challenges: Many leaders struggle with effectively deploying and maintaining these frameworks. 
  • Foundational role: Data governance is foundational to overall cybersecurity strategy, impacting compliance, risk management, and operational efficiency. 

 

Data classification: The bedrock of data governance

Hand in hand with data governance is the need for an effective data classification strategy. This is emphasized as a critical step before any governance framework can be successfully implemented.

Key points:

  • Foundation first: Proper data classification is seen as the cornerstone of an effective data governance framework. 
  • AI and automation: While AI and machine learning hold promise for automated data classification, there’s caution about relying too heavily on these technologies without thorough vetting. 
  • Simplification: Effective data classification frameworks should avoid complexity, making them easy to understand and use across the organization. 

 

Board involvement in cybersecurity

Another major theme is the crucial role of board involvement in cybersecurity strategy. Despite its importance, many organizations still lack adequate board engagement in this area.

Key points:

  • Risk integration: Boards need to integrate cybersecurity risks into their overall risk management strategies. 
  • Education and engagement: CISOs often need to educate board members about cybersecurity threats and the importance of proactive strategies. 
  • Strategic role: Cybersecurity should be a regular item on board agendas, influencing broader business decisions. 

 

Defensible security strategies

CISOs are increasingly focusing on creating defensible security strategies rooted in zero trust principles. This involves continuous threat modeling and analysis, ensuring that security measures can withstand scrutiny and adapt to evolving threats.

Key points:

  • Lifecycle approach: Viewing cybersecurity through a lifecycle lens rather than isolated solutions. 
  • Zero trust: Implementing zero trust principles to create a more resilient security posture. 
  • Continuous improvement: Regularly updating and refining security strategies to address new threats. 

 

Vendor partnerships: beyond products to solutions

Effective cybersecurity often depends on strong vendor partnerships. CISOs are looking for vendors who can provide not just products but comprehensive solutions and strategic advice.

Key points:

  • Consultative partnerships: CISOs value vendors who act as partners, offering strategic guidance and support. 
  • Integration and collaboration: Vendors should work seamlessly with internal teams and other third-party solutions to provide cohesive security coverage. 
  • Service and support: High levels of service and support from vendors are crucial for maintaining effective security postures. 

 

Addressing CISO experience and maturity 

The webinar highlights the varying levels of experience and maturity among CISOs, which can significantly impact an organization’s cybersecurity effectiveness.

Key points:

  • Diverse backgrounds: CISOs come from various professional backgrounds, affecting their approach to cybersecurity. 
  • Rapid impact: With an average tenure of 24-36 months, especially in the U.S., CISOs need to make quick, impactful changes. 
  • Training and development: Continuous education and professional development are essential for CISOs to stay ahead of emerging threats. 

 

Conclusion 

As we navigate the complexities of cybersecurity in 2024, the role of the CISO is more critical than ever. Effective data governance, board involvement, strategic vendor partnerships, and continuous improvement in security strategies are vital. Organizations that prioritize these areas will be better equipped to handle the rising pressures and evolving threats in the cybersecurity landscape.

By integrating these insights into their operations, businesses can enhance their cybersecurity posture, ensuring not only protection but also resilience and strategic advantage in the digital age. 

Watch the on-demand webinar

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

Ransomware as a service: A growing cyberthreat for data protection

And 7 ways to mitigate the impact of RaaS 

 

Ransomware has evolved from being a nuisance to a full-blown industry, with sophisticated networks of cybercriminals operating on a global scale. Among the various iterations of ransomware, one of the most concerning developments is the rise of ransomware as a service (RaaS). RaaS has emerged as a lucrative cybercrime business model, facilitating the proliferation of ransomware attacks across the globe through a much more extensive network of cybercriminals than ever before.

Let’s get into the intricacies of RaaS, exploring its workings, implications, cybersecurity challenges, and preventive measures.

First off, what is ransomware as a service? 

Ransomware as a service, as the name suggests, is a model where cybercriminals develop and offer ransomware kits and services to other individuals or groups, allowing them to execute ransomware attacks with minimal technical expertise. Essentially, it’s a turnkey solution for anyone looking to extort money through malicious means. With this cybercrime business model, one party creates ransomware software and then a second party pays to use said ransomware software to launch attacks.

According to IBM’s X-Force Threat Intelligence Index, ransomware ranked as the second most common type of cyberattack in 2022, with RaaS playing a significant role in its prevalence. Many experts believe the rise of RaaS has contributed to making ransomware so prevalent. The “2022 ThreatLabz State of Ransomware” report from Zscaler found that 73% of the most active ransomware variants were RaaS variants.

What makes RaaS different is that, unlike ransomware of the past, attackers don’t need to have the traditional high-level IT technical skills because they can rely on the technical skills of the RaaS developers. And because of this, criminals that were previously limited by their lack of specialized skills can now carry out sophisticated and successful ransomware attacks. Essentially, RaaS has democratized ransomware. 

 

How ransomware as a service works 

RaaS operates similarly to legitimate SaaS business models. Ransomware developers, known as RaaS operators, develop and maintain ransomware tools and infrastructure, packaging them into RaaS kits sold to other hackers, referred to as RaaS affiliates. These affiliates purchase the kits through various revenue models, including monthly subscriptions, affiliate programs, one-time license fees, and pure profit sharing and then use them to extort money from their victims.

Read a case about Conti leaks cybercrime commercialization, with a real example of a ransom note: Center for Internet Security.

The availability of RaaS platforms has led to a surge in ransomware attacks globally. As more cybercriminals gain access to these tools, the frequency and scale of attacks are expected to increase further.

An increasing number of new players were attracted by the potential for high profits and lower barriers to entry.

Reuters

Impact of ransomware as a service on industries and organizations 

Ransomware attacks have a widespread impact on basically all industries and organizations, causing disruption to critical services, loss of sensitive data, and financial damage. The healthcare sector has been heavily targeted, with ransom attacks on hospitals and medical facilities posing a threat to patient safety. Read about why healthcare organizations need Microsoft 365 backup for regulatory compliance and business continuity.

Legal implications of ransomware as a service 

Businesses that fall victim to ransomware attacks may face legal consequences for failing to maintain adequate business continuity and data protection measures. Non-compliance with regulations such as NIS2 (Network and Information Systems Directive) and GDPR (General Data Protection Regulation) can result in significant fines, loss of reputation, and other penalties. These regulations require organizations to implement robust cybersecurity measures, including regular data backups, disaster recovery, and incident response plans, to protect sensitive information and ensure business continuity. Learn why air gapping is your best defense.

The economics of RaaS cyberattacks 

Ransomware attacks can have severe economic repercussions, particularly for small businesses and organizations. The costs associated with ransom payments, data recovery, and downtime can be crippling, leading to financial losses and reputational damage.

In 2023, a new record was set for ransomware attack payments: A staggering $1.1 billion USD in payments for ransomware attacks was sent, according to Reuters. nearly doubling the total from 2022.

RaaS operators engage in competitive marketing strategies, often creating websites that mimic legitimate businesses. The global damages (total impact) from ransomware attacks were approximately $20 billion USD in 2020, and predictions are that ransomware will cost $265 billion USD annually by 2031 (Cybersecurity Ventures), highlighting the significant financial impact of RaaS. This forecast takes into consideration the impact of the increased market of cyberattacks due to accessibility and ease of use of RaaS, enabling threat actors to execute cyberattacks with minimal technical skills.

 

Extortion methods in ransomware attacks 

Ransomware threat actors employ various techniques to extort money from victims. These include double extortion, multiple extortion, and pure extortion.

  • Double extortion involves encrypting stolen data and then also threatening to release stolen data should the ransom not be paid, putting more pressure on the victim to pay. 
  • Multiple extortion combines data encryption with DDoS attacks against victim infrastructure.  
  • Pure extortion entails threatening to publish stolen data without encryption. (Read more about ransomware from the Cybersecurity & Infrastructure Security Agency’s #StopRansomware Guide.)

Main threat actors and notable ransomware as a service variants 

Several well-known cybercriminal groups developing RaaS include Hive, DarkSide, PINCHY SPIDER, ALPHV BlackCat, and LockBit. These operators continually evolve their ransomware to maximize impact and profit. Notable incidents involving RaaS operators include Hive’s targeting of Microsoft’s Exchange Server customers and DarkSide’s involvement in the Colonial Pipeline incident.

Hive garnered attention in April 2022 when they targeted Microsoft’s Exchange Server customers. The US Department of Justice seized two servers belonging to Hive, disrupting their operations.

DarkSide primarily targeted Windows machines but has expanded to Linux systems. They gained notoriety in the Colonial Pipeline incident, where the organization paid nearly $5 million to a DarkSide affiliate. TechTarget explains the Colonial Pipeline incident in depth. REvil is known for receiving one of the largest ransoms on record: $11 million USD. 

 

7 ways to mitigate the impact of RaaS attacks 

Mitigating the impact of ransomware as a service (RaaS) attacks is crucial. While it may be challenging (or even impossible) to entirely prevent ransomware incidents, organizations can take proactive steps to minimize the effects and impact of RaaS, thereby ensuring business continuity and data compliance. The following seven steps outline strategies to mitigate the impact of RaaS attacks:

  • Maintain rigorous patch management: Vigilantly applying security patches and updates is essential to mitigate known and unknown vulnerabilities. By promptly addressing vulnerabilities, organizations can reduce the likelihood of exploitation by threat actors seeking to deploy ransomware. 
  • Deploy robust endpoint protection: Implementing reliable and modern endpoint protection solutions is key to detecting and mitigating threats. These solutions should leverage advanced algorithms to provide continuous threat detection and mitigation, reducing the risk of ransomware infiltration. 
  • Frequent and air-gapped backups: Conducting regular and frequent backups of critical data is crucial for minimizing the impact of ransomware attacks. Storing multiple backups on separate devices in different physical locations ensures data availability and resilience in the event of an attack. Look for backup services that store backup data independent from production data. 
  • Test backups regularly: Regularly testing backups is vital to ensure their reliability and effectiveness in restoring data. By verifying the integrity of backups, organizations can minimize downtime and data loss in the event of a ransomware attack. 
  • Implement advanced anti-phishing measures: Deploying robust email security solutions with advanced threat detection capabilities helps mitigate the risk of ransomware attacks initiated through phishing emails. By blocking malicious emails before they reach end-users, organizations can reduce the likelihood of ransomware infiltration. 
  • Immutability by default: Deploying a solution with immutability baked into the design greatly enhances resilience against ransomware attacks. Immutable data storage ensures that once data is written, it cannot be altered or deleted, effectively preventing unauthorized modifications by ransomware. Immutable data storage allows organizations to safeguard critical data from encryption or tampering attempts by threat actors. 
  • Invest in user training and security culture: Educating users about the risks associated with ransomware attacks and fostering a culture of security awareness is critical. By training employees to recognize and report suspicious activities, organizations can strengthen their overall security posture and mitigate the impact of ransomware incidents.

By implementing these proactive measures, organizations can significantly mitigate the effects and impact of RaaS attacks, enhancing their resilience in the face of evolving cyberthreats.

Conclusion 

Ransomware as a service poses a significant (and growing) threat to cybersecurity globally, contributing to the proliferation of ransomware attacks across various industries. Understanding the workings of RaaS, its implications, and the associated cybersecurity challenges is essential for organizations to effectively combat this evolving threat.

By implementing proactive measures, such as maintaining cybersecurity hygiene, deploying robust defense mechanisms like backup management, and fostering a culture of security awareness, organizations can significantly mitigate the impact of RaaS attacks. Additionally, investing in an immutable, air-gapped backup and recovery solution is paramount to ensure data resilience and continuity of operations in the event of a ransomware incident. 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Keepit
At Keepit, we believe in a digital future where all software is delivered as a service. Keepit’s mission is to protect data in the cloud Keepit is a software company specializing in Cloud-to-Cloud data backup and recovery. Deriving from +20 year experience in building best-in-class data protection and hosting services, Keepit is pioneering the way to secure and protect cloud data at scale.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×