Ransomware attacks on critical infrastructure are on the rise. Late last week, Colonial Pipeline was hit with a ransomware attack that shut down over 5,000 miles of U.S. pipeline. This section transports around 2.5 million barrels of diesel and gasoline a day, and accounts for almost half of the East Coast’s fuel supply. A few days earlier, attackers targeted Volue, a Norwegian company that provides technology to water and wastewater facilities in 44 countries. Colonial Pipeline reportedly paid a $5 million ransom – using cryptocurrency.
Ransomware attacks are usually focused on data exfiltration, followed with a threat to encrypt the data, and/or release it to the public unless payment is made – often in the form of cryptocurrency. Ransomware attacks are skyrocketing – up by more than 300 percent in the past year in the U.S. alone, according to the U.S. Department of Homeland Security.
Neither of these most recent attacks appear to be worst-case scenarios like what happened to a U.S. water utility last year when attackers took control of an industrial control system. But the implications are still enormous. In the case of Colonial Pipeline, panic-buying is leading to fuel shortages across the U.S. Eastern Seaboard. And, in the case of Volue, 200 Norwegian water municipalities were impacted.
While ransomware attacks can come from a number of vectors, the most frequent is phishing. Someone clicks a link, which infects their device and gives extortionists a pathway to do their work. This is why demand for security services is exploding and why enterprise dollars are flowing in this direction. As we discussed a couple weeks ago, enterprise security spending per employee increased by over 40 percent from 2019 to 2020. Security spend as a percentage of overall IT spend is increasing as well (see Data Watch).
Managed security services focused on SOC/SIEM operations are seeing steady demand. While these engagements tend to be smaller – between $2 and $3 million in ACV – we are seeing them grow to upwards of $5 million as enterprise buyers increasingly broaden the scope to include things like data loss prevention and identity governance.