ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Ransomware 101: What Banks Can Do To Mitigate Risk

July 20, 2018
Reading Time: 3 mins read

Ransomware Concept with Hooded Hacker - On-Line Security

By Israel Barak

Ransomware has become one of the most—if not the most—prevalent, effective and successful forms of cybercrime. Ransomware is simple to create and distribute and offers cybercriminals an extremely low-risk, high-reward business model for monetizing malware. Combine this with the fact that most companies and people are unprepared to deal with ransomware, and it’s clear why it has become the fastest growing cyber threat to date.

Simple code, sophisticated e-marketing
Ransomware propagates through the same channels as regular malware—mainly email, but also through compromised or malicious websites and pirated software. Ransomware code is often not sophisticated, but it doesn’t need to be. This is because unlike many types of traditional malware, in most cases ransomware does not need to remain undetected for long to achieve its goal. What is more sophisticated about ransomware is the e-marketing effort that drives its distribution.

Ransomware purveyors are often savvy e-marketers who know their targets. It is not uncommon for a ransomware gang to run multiple campaigns at the same time, with tiered pricing based on a variety of parameters such as vertical industry, region, age, etc. While ransoms have exceeded hundreds of thousands of dollars in some cases, the goal is to set a price that makes it either cheaper or easier for the victim to pay the ransom than to recreate or restore the compromised systems, especially when the victim has a sense of urgency.

Exploiting risk management gaps in cyber insurance, operations
The end result of ransomware is a whole new economy for cybercrime, one with risk management gaps that allow it to thrive. One significant gap is that the cyber insurance industry is often useless when it comes to ransomware. Most policies have an “extortion” clause, but the deductibles are cost prohibitive: often times, hundreds of thousands of dollars need to be extorted before the insurance will kick in. Plus, if the company publicly discloses that it has a cyber-extortion clause in its policy—in a press release or a public report, for example—then it could invalidate the policy.

Another key factor is that it can take a medium-sized business days to restore from backup, which makes it cheaper and easier for victims to pay the ransom. Think about Hollywood Presbyterian Medical Center in Southern California, which in 2016 had its computer systems crippled for more than a week as it worked to recover from a ransomware attack. When their labs and prescription systems were down, those orders had to be handled manually. Think about the cost involved in that!

Some believe paying the ransom will mark them as an easy target and invite future attacks. However, generic ransomware is rarely individually targeted—it’s usually a “shotgun” approach: attackers acquire email lists, compromise websites and blast out ransomware. Given the amount of attackers out there, if you do get hit again, it will likely be by a different attacker.

So what can you do to mitigate ransomware risk?
Here are some tips banks can follow to mitigate ransomware risk at their institutions and limit the fallout of a ransomware attack:

  1. Maintain regular and constant backups of important files and consistently verify that the backups can be restored. Be aware of and filter potentially malicious websites and emails.
  2. Avoid common malware delivery tactics. Ransomware is often delivered through the exact same channels as other types of malware—sometimes it’s even bundled and downloaded together with other types of malware. Refrain from downloading pirated software or paid software offered for “free.” (Remember: when a paid product is offered for free, you are the actual product.)
  3. Don’t download software from any non-trusted sources or websites or any key-gen, password cracking or license check removal software. In addition, don’t open email attachments from unknown or unexpected senders, and ensure that your staff is well trained on what to do in the event they receive a suspicious message.
  4. Review your company’s cyber insurance plans. Ensure your cyber insurance plans are in line with the level of risk you want from ransomware. Consider requesting a “ransomware clause” for cyber extortion that would eliminate the inability to publicly disclose and adjust the unrealistic high deductible to be more in line with current ransom demands.
  5. In the event of a ransomware attack, assume all sensitive data on the machine was compromised. Whether you pay or not, keep in mind that attackers will always try and extract useful data off a compromised machine. This potentially includes usernames and passwords for internal or web resources, payment information, email addresses of contacts, etc.
  6. Consider deployment of advanced anti-ransomware technology to prevent execution of ransomware. These technologies can be adopted either as standalone tools or incorporated into the organizational anti-malware platform.

If you have not taken precautions in advance and your organization falls victim to a ransomware attack, then it might be easiest to pay, and better prepare for the next attack.

Israel Barak is CISO at Boston-based Cybereason, a cybersecurity company specializing in endpoint protection, detection and response.

Tags: Cyber crimeCybersecurity
ShareTweetPin

Author

Monica C. Meinert

Monica C. Meinert

Monica C. Meinert is a senior editor at the ABA Banking Journal and VP for executive communications at the American Bankers Association.

Related Posts

ABA: Proposed customer identification standards for stablecoin issuers need strengthening

ABA: Proposed customer identification standards for stablecoin issuers need strengthening

Compliance and Risk
August 21, 2026

A proposed rule to require payment stablecoin issuers to maintain customer identification programs must go further if it is to reflect those firms’ business models and ensure equal treatment for all financial institutions, ABA said.

ABA suggests splitting proposal to expand Fedwire, NSS operating hours

ABA: International payment transparency standards need more work

Compliance and Risk
August 21, 2026

A recent effort by the Financial Action Task Force to improve cross-border payment transparency is commendable, but there are additional steps the task force should take to reduce operational challenges and preserve a true risk-based approach, ABA said.

COVID-19 Scams and the Elderly: Inspiring Savvy Seniors

The voice fraud threat to banking

Compliance and Risk
August 21, 2026

How AI-generated impersonation is reshaping the risk landscape as the voice channel remains an important customer-contact method for the banking industry.

FDIC’s Hill: Standards-setting organization could spur bank-fintech partnerships

U.S. Bank executive to head FSSCC

Compliance and Risk
August 20, 2026

Ann Barron-DiCamillo, EVP and CISO at U.S. Bank, has been selected as the next chair of the Financial Services Sector Coordinating Council. She succeeds Debbie Guild, EVP and head of technology at PNC Financial Services Group, who recently...

OCC’s Gould defends charter approvals for crypto activity

OCC’s Gould defends charter approvals for crypto activity

Compliance and Risk
August 19, 2026

Noting more than half of recent bank charter applications received by his agency involve digital assets, Comptroller of the Currency Jonathan Gould said his job isn’t about “incumbent protection” but rather preserving the integrity of the banking system.

ABA, 52 state bankers associations urge Congress to close stablecoin interest loophole

Treasury proposes rulemaking for licensing payment stablecoin issuers

Newsbytes
August 17, 2026

The Treasury Department released proposed rulemaking to require digital asset providers to obtain a federal or state license before issuing payment stablecoins, as required by the Genius Act.

NEWSBYTES

Tioga-Franklin Savings Bank in Philadelphia closed by regulators

August 21, 2026

ABA: Proposed customer identification standards for stablecoin issuers need strengthening

August 21, 2026

ABA: International payment transparency standards need more work

August 21, 2026

SPONSORED CONTENT

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

The exam question a backup can’t answer

August 18, 2026
Beyond Surveillance: Rethinking Security for Modern Financial Institutions

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

August 12, 2026
Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

August 1, 2026

PODCASTS

Could Your Bank Absorb the Hidden Cost of Running Legacy Systems?

August 20, 2026

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.