ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Ransomware 101: What Banks Can Do To Mitigate Risk

July 20, 2018
Reading Time: 3 mins read

Ransomware Concept with Hooded Hacker - On-Line Security

By Israel Barak

Ransomware has become one of the most—if not the most—prevalent, effective and successful forms of cybercrime. Ransomware is simple to create and distribute and offers cybercriminals an extremely low-risk, high-reward business model for monetizing malware. Combine this with the fact that most companies and people are unprepared to deal with ransomware, and it’s clear why it has become the fastest growing cyber threat to date.

Simple code, sophisticated e-marketing
Ransomware propagates through the same channels as regular malware—mainly email, but also through compromised or malicious websites and pirated software. Ransomware code is often not sophisticated, but it doesn’t need to be. This is because unlike many types of traditional malware, in most cases ransomware does not need to remain undetected for long to achieve its goal. What is more sophisticated about ransomware is the e-marketing effort that drives its distribution.

Ransomware purveyors are often savvy e-marketers who know their targets. It is not uncommon for a ransomware gang to run multiple campaigns at the same time, with tiered pricing based on a variety of parameters such as vertical industry, region, age, etc. While ransoms have exceeded hundreds of thousands of dollars in some cases, the goal is to set a price that makes it either cheaper or easier for the victim to pay the ransom than to recreate or restore the compromised systems, especially when the victim has a sense of urgency.

Exploiting risk management gaps in cyber insurance, operations
The end result of ransomware is a whole new economy for cybercrime, one with risk management gaps that allow it to thrive. One significant gap is that the cyber insurance industry is often useless when it comes to ransomware. Most policies have an “extortion” clause, but the deductibles are cost prohibitive: often times, hundreds of thousands of dollars need to be extorted before the insurance will kick in. Plus, if the company publicly discloses that it has a cyber-extortion clause in its policy—in a press release or a public report, for example—then it could invalidate the policy.

Another key factor is that it can take a medium-sized business days to restore from backup, which makes it cheaper and easier for victims to pay the ransom. Think about Hollywood Presbyterian Medical Center in Southern California, which in 2016 had its computer systems crippled for more than a week as it worked to recover from a ransomware attack. When their labs and prescription systems were down, those orders had to be handled manually. Think about the cost involved in that!

Some believe paying the ransom will mark them as an easy target and invite future attacks. However, generic ransomware is rarely individually targeted—it’s usually a “shotgun” approach: attackers acquire email lists, compromise websites and blast out ransomware. Given the amount of attackers out there, if you do get hit again, it will likely be by a different attacker.

So what can you do to mitigate ransomware risk?
Here are some tips banks can follow to mitigate ransomware risk at their institutions and limit the fallout of a ransomware attack:

  1. Maintain regular and constant backups of important files and consistently verify that the backups can be restored. Be aware of and filter potentially malicious websites and emails.
  2. Avoid common malware delivery tactics. Ransomware is often delivered through the exact same channels as other types of malware—sometimes it’s even bundled and downloaded together with other types of malware. Refrain from downloading pirated software or paid software offered for “free.” (Remember: when a paid product is offered for free, you are the actual product.)
  3. Don’t download software from any non-trusted sources or websites or any key-gen, password cracking or license check removal software. In addition, don’t open email attachments from unknown or unexpected senders, and ensure that your staff is well trained on what to do in the event they receive a suspicious message.
  4. Review your company’s cyber insurance plans. Ensure your cyber insurance plans are in line with the level of risk you want from ransomware. Consider requesting a “ransomware clause” for cyber extortion that would eliminate the inability to publicly disclose and adjust the unrealistic high deductible to be more in line with current ransom demands.
  5. In the event of a ransomware attack, assume all sensitive data on the machine was compromised. Whether you pay or not, keep in mind that attackers will always try and extract useful data off a compromised machine. This potentially includes usernames and passwords for internal or web resources, payment information, email addresses of contacts, etc.
  6. Consider deployment of advanced anti-ransomware technology to prevent execution of ransomware. These technologies can be adopted either as standalone tools or incorporated into the organizational anti-malware platform.

If you have not taken precautions in advance and your organization falls victim to a ransomware attack, then it might be easiest to pay, and better prepare for the next attack.

Israel Barak is CISO at Boston-based Cybereason, a cybersecurity company specializing in endpoint protection, detection and response.

Tags: Cyber crimeCybersecurity
ShareTweetPin

Author

Monica C. Meinert

Monica C. Meinert

Monica C. Meinert is a senior editor at the ABA Banking Journal and VP for executive communications at the American Bankers Association.

Related Posts

ABA urges ‘same risk, same regulation’ for digital assets

ABA, associations: Updated crypto market structure bill still puts local lending at risk

Newsbytes
July 22, 2026

The latest version of a proposed market structure bill for digital assets still puts at risk the local lending that drives economic activity in the U.S, ABA and five other banking sector associations said in a joint statement.

Federal agencies warn of scams following hurricanes

House Republicans propose whole-of-ecosystem approach to combat fraud, scams

Compliance and Risk
July 22, 2026

Republicans on the House Financial Services Committee published a report calling for a coordinated national strategy to combat financial fraud and scams, saying that scams begin long before a customer contacts their bank and require stronger collaboration across...

Survey: Banks boosting cybersecurity due to AI while also investing in technology

ABA offers improvements for FSB’s ‘sound practices’ in AI adoption

Compliance and Risk
July 22, 2026

The Financial Stability Board’s draft list of 12 recommendations to guide the adoption of artificial intelligence by financial institutions is useful, but the document could use some further tweaks to make the recommendations even more effective, ABA said.

Nichols: ABA seeks ‘surgical’ changes to crypto market structure bill

Nichols: ABA seeks ‘surgical’ changes to crypto market structure bill

Newsbytes
July 21, 2026

ABA isn’t opposed to market structure legislation for digital assets but is seeking “tiny, surgical” changes to ensure the Genius Act’s prohibition on interest and yield on payment stablecoin is upheld, ABA President and CEO Rob Nichols told...

The Genius Act in 2026

The Genius Act in 2026

Compliance and Risk
July 20, 2026

Institutions that choose to lead will shape the architecture of the next payments era. Those that partner will need to move with precision and speed.

ABA, 52 state bankers associations urge Congress to close stablecoin interest loophole

ABA, associations seek agency alignment on Genius Act implementation

Compliance and Risk
July 17, 2026

The National Credit Union Administration should coordinate with the banking agencies to ensure that Genius Act implementation is substantially similar among all federal payment stablecoin regulators, the American Bankers Association and three other banking sector associations said.

NEWSBYTES

ABA, associations: Updated crypto market structure bill still puts local lending at risk

July 22, 2026

Main Street Capital Access Act would extend CDFI bond guarantee program

July 22, 2026

House Republicans propose whole-of-ecosystem approach to combat fraud, scams

July 22, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Understanding the 2025 Home Mortgage Disclosure Act data

July 8, 2026

Podcast: Financing America’s independence

June 29, 2026

Podcast: Talent and innovation in community banking

June 18, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.