How companies can deal with the rising threat of ransomware
A strange text file appears on your desktop, and you open it to discover a ransom demand.
You’ve become the latest victim of a ransomware attack, and all your data and sensitive information will only be released once you’ve paid the ransom to the hackers.
Such attacks are becoming more common, with the frequency of ransomware incidents having increased by 93% in the first half of 2021 compared to the same period the year before. Worse still, organizations in Asia Pacific have been hit hard with 1,338 attacks each week, the highest of any region in the world.
Amid their rapid digitalization efforts, companies will have to be prepared to tackle this rising threat head-on.
Illicitly lucrative
One major reason why ransomware is on the rise is due to being an increasingly lucrative income source for malicious actors.
“In the past, if I built a really cool app, there’s a chance I could get recognized. But technology and app development are so common nowadays,” explains John Hodges, senior vice president of product strategy at SaaS platform provider AvePoint.
“I think that [ransomware] was the easier route for a lot of tech-savvy people to grasp on,” he adds. “Being able to hold data for ransom is something that creates an exponential opportunity to bring more income in, as data became the thing that companies were willing to pay money for.”
This is made apparent by how ransomware demands have been shooting up in value. According to a report from Palo Alto Networks, the average ransom demand in these cyber attacks jumped by 171% from US$115,123 in 2019 to US$312,493 in 2020.
In worse scenarios, these figures could reach into the tens of millions. Just last year, US-based insurance firm CNA Financial paid hackers US$40 million following a ransomware attack, making it one of the largest recorded ransoms paid to date.
The costs of ransomware
With ransomware attacks becoming more prevalent, businesses face a litany of issues beyond the cost of the ransom itself.
In some cases, such incidents could also force business production to stop, leading to further damages to operations and revenue. Earlier this year, a ransomware attack led Toyota to shut down for a day, and the company fell behind its production schedule for roughly 13,000 vehicles.

Photo credit: phanuwatnandee / 123RF
In other scenarios, falling prey to ransomware attacks could also cause customer information to be leaked. In turn, companies face additional financial risk as they may be fined for flouting data privacy laws, such as the Personal Data Protection Act in Singapore.
“The larger and more in touch with consumers you are, the more likely it is that you have many systems that are in play. Being able to safeguard each and every one of those touchpoints with your customers can be challenging for any company,” Hodges points out.
Worse still, it’s going to get more difficult to implement such safeguards. According to Hodges, older versions of ransomware attacks would usually be immediately noticeable to companies. However, ransomware viruses today are getting increasingly harder to detect and may not be evident to IT security systems before an attack is actually triggered on a system. This allows the virus to continue infecting more systems and may lead to more widespread damage further down the line.
“The one that we’ve personally witnessed is a slowed playout [of the attack] where there wasn’t a key event where we see the exact moment that the ransomware hit,” he says. “They may play out over time.”
Ransomware’s insurance policy
With the methods of ransomware getting increasingly sophisticated and harder to spot, Hodges emphasizes that companies will have to be proactive in their cybersecurity policies to not only detect attacks better, but also to ensure that business operations can continue running smoothly even if they do fall victim.
“Having a call with your account team for Microsoft, Google, or Salesforce to ask about zero trust or ransomware protections gives you an eye-opening first line of defense there,” he suggests.
Companies should also consider the use of backup services, he adds. Such services allow firms to have a safety net should any attacks occur as well as a reliable way to quickly restore business operations.

Photo credit: gorodenkoff / 123RF
“If you have a backup, full stop you’re covered,” Hodges says. “Backup is the fundamental thing because regardless of any defenses failing, this is your insurance policy that allows you to come back to an earlier and safer point in time.”
Such was the case with Irish building contractor Walls Construction, which fell victim to a ransomware attack. Following the incident, it realized the need for a backup service to future-proof against further attacks and engaged AvePoint for its Cloud Backup solution.
Since then, the Irish firm has been able to alleviate the impact of subsequent ransomware attacks by relying on prior backups of its databases and other IT infrastructure, which cut down on its restore times by roughly 90%. This, in turn, allowed it to make another four to five recoveries since the initial incident and quickly get back to business as usual.
Continuous proactiveness
With ransomware attacks continuing to evolve, Hodges urges that being proactive is the key to continued security for companies.
“You will be learning all your life, same as your ransomware attackers,” says the senior vice president. “It’s an education war of who’s going to be savvy enough to stay safe.”
In this regard, he likens the practice of proactively getting a backup service to save points in video games.
“Save early, save often,” he says. “When you encounter someone who has been better educated than you, if you didn’t take the proactive steps of setting up safe restore points, you’re in trouble on the other end at the end of the day.”
AvePoint helps companies secure collaboration data, sustain the connections between people, and ensure business continuity. More than 9 million cloud users today rely on AvePoint’s Confidence platform, an advanced SaaS and data management solution to optimize operations and secure collaboration.
To find out more about AvePoint, visit its website.
This content was produced by Tech in Asia Studios, which connects brands with Asia’s tech community. Learn more about partnering with Tech in Asia Studios.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.
Recommended reads
Life’s a game, and AI agents are Animoca’s new play
Indonesian AI startup goes global
Forrest Li on scaling Sea, building smarter bots, and founder grit
An AI assistant that joins sales calls and scores team skills
Beyond the check: Why VCs need more than capital
SGX’s CEO says it doesn’t need a unicorn to win
SMEs want AI too, but not the kind Big Tech is selling
Oatside’s alt-milk rise hits a profitable gear
Alibaba’s financial health in 12 charts
Asia’s telcos bundle AI into mobile plans. Will it pay off?
Editing by Nathaniel Fetalvero and Lorenzo Kyle Subido
(And yes, we’re serious about ethics and transparency. More information here.)


