Ransomware victims fail to fix flaws that exposed them

A new report reveals that many organizations fail to patch critical vulnerabilities or configure email security protocols even after suffering a ransomware attack. This negligence leaves them highly susceptible to repeat attacks from cybercriminals who exploit these known weaknesses.
Why it matters
It highlights a systemic failure in corporate cybersecurity hygiene that allows ransomware to remain a highly profitable and recurring threat.
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found.
Because ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets, and if an organization fails to fix the problems that opened the door for hackers in the first place, they are likely to return. That fact makes it imperative for hacked businesses to fix digital liabilities as soon as possible after an incident, lest hackers revictimize them seeking another payout.
But many organizations haven’t learned that lesson and continue to operate with serious cybersecurity weaknesses.
Forty-three percent of victimized organizations still have at least one unpatched critical vulnerability, and 31% still have at least one vulnerability that the Cybersecurity and Infrastructure Security Agency says hackers are currently exploiting .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in