{"id":17356,"date":"2025-08-05T09:48:50","date_gmt":"2025-08-05T13:48:50","guid":{"rendered":"https:\/\/gtm.com\/business\/?p=17356"},"modified":"2025-08-05T09:48:50","modified_gmt":"2025-08-05T13:48:50","slug":"reduce-risk-ransomware","status":"publish","type":"post","link":"https:\/\/gtm.com\/business\/reduce-risk-ransomware\/","title":{"rendered":"How to Reduce the Risk of a Ransomware Attack"},"content":{"rendered":"<p><em><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-17357\" src=\"https:\/\/gtm.com\/business\/wp-content\/uploads\/2025\/08\/pexels-shkrabaanthony-5475752-1.jpg\" alt=\"reduce risk ransomware\" width=\"1024\" height=\"682\" srcset=\"https:\/\/gtm.com\/business\/wp-content\/uploads\/2025\/08\/pexels-shkrabaanthony-5475752-1.jpg 1024w, https:\/\/gtm.com\/business\/wp-content\/uploads\/2025\/08\/pexels-shkrabaanthony-5475752-1-980x653.jpg 980w, https:\/\/gtm.com\/business\/wp-content\/uploads\/2025\/08\/pexels-shkrabaanthony-5475752-1-480x320.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) 1024px, 100vw\" \/><\/em><\/p>\n<p><em>Ransomware is a type of malicious software (malware) that threatens to publish the victim&#8217;s data or perpetually block access to it unless a ransom is paid.\u00a0It encrypts files or locks computer systems, demanding payment, often in cryptocurrency, for decryption or access.<span class=\"pjBG2e\" data-cid=\"db355e8e-8645-4b0b-bf0d-a3e0d0aebade\"><span class=\"UV3uM\"> Our cybersecurity partner, <a href=\"https:\/\/orbitalfire.com\/2025\/07\/15\/ransomware-payouts-down-but-dont-celebrate\/?utm_campaign=Monthly%20Newsletter&amp;utm_medium=email&amp;_hsenc=p2ANqtz--3nvLVlriY5CYN36hxy_TvdbGQ40f6_E1zf7BIfsHMFtwBOoSj6uLUcFSpBilgVb-NU7OuX4yi4aYiD2tnr0fGZr4wGQ&amp;_hsmi=373744110&amp;utm_content=373744110&amp;utm_source=hs_email\" target=\"_blank\" rel=\"noopener\">Orbitalfire<\/a>, says that while ransomware payouts have been on the decline, businesses shouldn\u2019t mistake lower payouts for lower risk, and they provide some proactive tips to reduce the risk of an attack.<\/span><\/span><\/em><\/p>\n<h2>Ransomware Payouts Are Down, But Don\u2019t Celebrate Just Yet<\/h2>\n<p class=\"\">If you\u2019ve skimmed recent headlines, you might have seen something surprising: ransomware payouts are on the decline. According to\u00a0<a href=\"https:\/\/www.aon.com\/cyber-risk-report\/ransomware-payouts-decline-despite-growing-cyber-claims-frequency\">Aon\u2019s 2024 Cyber Resilience Report<\/a>, the average ransom paid by companies fell to just 28% of the initial demand in 2023, down from 43% in 2022. On the surface, that sounds like good news. Less money to the bad guys? We\u2019ll take it.<\/p>\n<p class=\"\">But here\u2019s the catch: ransomware attacks themselves haven\u2019t slowed down. They\u2019re evolving. And for small businesses, the risks remain high, even if the ransom number doesn\u2019t.<\/p>\n<h3>The Cost Is Still Coming from Somewhere<\/h3>\n<p class=\"\">Lower payouts don\u2019t mean fewer claims. In fact, cyber claims are\u00a0<em>up<\/em>, especially among small and midsized businesses. Aon\u2019s report shows a significant uptick in cyber insurance claims from this group, driven by business email compromise, data theft, and of course, ransomware.<\/p>\n<p class=\"\">Why the disconnect? In many cases, organizations are refusing to pay ransoms or negotiating them down, often due to better preparedness, stronger backups, or legal\/regulatory pressure. But that doesn\u2019t eliminate the cost. Downtime, data recovery, incident response, and customer notification costs can easily stack up, regardless of whether a ransom is paid.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/orbitalfire.com\/wp-content\/uploads\/2025\/07\/Ransomware-Payments-are-Down-Article-Image-v1-07-25-300x278.jpg\" alt=\"Ransomware Payouts are Down but the Risk Isn't\" width=\"365\" height=\"338\" \/><\/p>\n<h3>The Ransom Isn\u2019t the Only Threat<\/h3>\n<p class=\"\">Cybercriminals are getting creative. More are using \u201cdouble extortion\u201d: stealing data and threatening to leak it if the ransom isn\u2019t paid. Others are exploiting vulnerabilities faster and more quietly, often sitting in networks for weeks before triggering an attack. Small businesses without the tools or visibility to detect this kind of activity are at higher risk, regardless of how low the final ransom demand is.<\/p>\n<h3>So What Should Small Businesses Do?<\/h3>\n<p class=\"\">Here\u2019s the real takeaway: lower average ransomware payouts are a sign that resilience is possible, but only with the right preparation.<\/p>\n<p class=\"\">At OrbitalFire, we\u2019ve seen firsthand how smaller businesses can punch above their weight by focusing on practical, proactive cybersecurity. Here are some of the things making the biggest difference:<\/p>\n<ul class=\"\">\n<li><strong>Backups that Actually Work<\/strong>\u00a0\u2013 Offline, tested, and restorable.<\/li>\n<li><strong>24\/7\u00a0<a class=\"internal-link\" title=\"Intrusion and Threat Detection\" href=\"https:\/\/orbitalfire.com\/pages\/intrusion_and_threat_detection\/\">Intrusion and Threat Detection<\/a><\/strong>\u00a0\u2013 Complete visibility to and detection of intrusions, anomalies, compromise, and other potential threats.<\/li>\n<li><strong><a class=\"internal-link\" title=\"Cybersecurity Incident Response Tabletop\" href=\"https:\/\/orbitalfire.com\/pages\/incident_response_tabletop\/\">Incident Response Planning\u00a0<\/a><\/strong>\u2013 So your team knows what to do\u00a0<em>before<\/em>\u00a0things go sideways.<\/li>\n<li><strong><a class=\"internal-link\" title=\"Phishing Testing\" href=\"https:\/\/orbitalfire.com\/pages\/phishing_testing_services\/\">Phishing Testing<\/a>\u00a0<\/strong>\u2013 Improved cybersecurity behaviors to reduced phishing risk.<\/li>\n<li><strong><a class=\"internal-link\" title=\"Awareness Training\" href=\"https:\/\/orbitalfire.com\/pages\/awareness_training_services\/\">Awareness Training<\/a><\/strong>\u00a0\u2013 Because phishing is still the #1 way attackers get in.<\/li>\n<li><strong><a class=\"internal-link\" title=\"Vulnerability Management\" href=\"https:\/\/orbitalfire.com\/pages\/vulnerability_management_service\/\">Vulnerability Management<\/a><\/strong>\u00a0\u2013 Identify and patch before attackers exploit known weaknesses.<\/li>\n<\/ul>\n<h3>Bottom Line: Hope Is Not a Strategy<\/h3>\n<p class=\"\">The decline in ransom payouts is encouraging, but it\u2019s not a green light to relax. If anything, it\u2019s a sign that businesses who prepare\u00a0<em>can<\/em>\u00a0avoid the worst outcomes. But for those who haven\u2019t? The costs are just hiding elsewhere.<\/p>\n<p class=\"\">Cybercriminals don\u2019t care about your size, they care about your gaps. Let\u2019s close them.<\/p>\n<p class=\"\">Need help building a more resilient cybersecurity program?<\/p>\n<p class=\"\"><a class=\"internal-link\" title=\"Contact Us #2\" href=\"https:\/\/orbitalfire.com\/pages\/contact\/\">Contact OrbitalFire<\/a>\u00a0to learn how we help small businesses prepare for (and prevent) ransomware and other attacks.<\/p>\n<h2>GTM\u2019s Cybersecurity Practices<\/h2>\n<p>Security is integral to our operations. It\u2019s at the core of what we do with multiple layers of protection embedded into our products, processes, and infrastructure.<\/p>\n<p>Our\u00a0<a href=\"https:\/\/gtm.com\/business\/why-gtm\/data-security\/\">state-of-the-art security measures<\/a>\u00a0are designed to safeguard your data from unauthorized access and cyber threats. We employ a robust combination of physical, administrative, and technical controls, including advanced encryption technologies, continuous network monitoring, and strict access controls, ensuring your data is protected around the clock.<\/p>\n<p>GTM undergoes annual security assessments from the New York State Department of Financial Services and adheres to the National Institute of Standards and Technology (NIST) for cybersecurity standards. GTM also submits to several third-party audits, including SOC 1 audits, Nacha audits, and financial statement audits.<\/p>\n<h3>Cyber and Data Breach Liability Insurance<\/h3>\n<p>As an additional method of security, cyber and data breach liability insurance is available in case of a cyberattack or data breach. A cyber liability and data breach insurance policy can help if your business computers get hit with a virus that exposes private or sensitive information, your business is sued for losing customers\u2019 sensitive data, or your business takes on public relations costs to protect its reputation after a data breach.<\/p>\n<p>If you are interested in cyber and data breach insurance, the\u00a0<a href=\"https:\/\/gtminsurance.com\/business-insurance\/cyber-data-breach-liability\/\">GTM Insurance Agency<\/a>\u00a0can discuss your options.\u00a0<a href=\"https:\/\/gtminsurance.com\/contact-us\/\">Contact them<\/a>\u00a0for a free quote or more information.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn how you can reduce the risk of a ransomware attack on your business, but only with the right preparation.<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[232],"tags":[221,287,425,42,10],"post_folder":[],"class_list":["post-17356","post","type-post","status-publish","format-standard","hentry","category-gtm-biz-blog-isolved","tag-cyberattack","tag-cybersecurity","tag-ransomware","tag-safety","tag-small-business"],"_links":{"self":[{"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/posts\/17356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/comments?post=17356"}],"version-history":[{"count":1,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/posts\/17356\/revisions"}],"predecessor-version":[{"id":17358,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/posts\/17356\/revisions\/17358"}],"wp:attachment":[{"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/media?parent=17356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/categories?post=17356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/tags?post=17356"},{"taxonomy":"post_folder","embeddable":true,"href":"https:\/\/gtm.com\/business\/wp-json\/wp\/v2\/post_folder?post=17356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}