-

New Axio Research Report Illustrates Glaring Deficiencies in Cybersecurity Hygiene Leaving Organizations Exposed to Ransomware

Axio’s 2021 State of Ransomware Preparedness Report illustrates companies lack basic cybersecurity practices to combat the growing tide of ransomware

NEW YORK--(BUSINESS WIRE)--Axio, the leader in cyber risk management software, today released its 2021 State of Ransomware Preparedness research report. The report reveals that organizations are not equipped to defend against ransomware due to deficiencies in implementing and sustaining basic cybersecurity practices, including managing privileged administrator credentials and ensuring visibility of supply chain risk.

“Ransomware is everywhere, dominating headlines, corporate board meetings and even the Biden administration’s agenda,” remarked the report’s co-author David White, President and Co-Founder of Axio. “And with high-visibility attacks continuing to unfold, companies more than ever require ransomware readiness measures in place to protect against a cyber catastrophe. As we learned from the much-publicized Colonial Pipeline attack—which raised national awareness about critical infrastructure susceptibility to ransomware—these attacks can cause widespread societal disruption and economic damage.”

The report identifies several emerging patterns that yield insights into why organizations are increasingly susceptible to ransomware attacks. The data pinpoints seven key areas where organizations are deficient in implementing and sustaining basic cybersecurity practices:

  • Management of privileged access
  • Basic cyber hygiene
  • Exposure to supply chain risk
  • Network monitoring
  • Incident management
  • Vulnerability management
  • Training and awareness

Overall, most organizations surveyed are not adequately prepared to manage the risk associated with a ransomware attack. Key data findings include:

  • Nearly 80% of organizations responded that they have not implemented or have only partially implemented a privileged access management solution.
  • Only 36% of respondents indicated that they audit the use of service accounts, a type of privileged account, on a regular basis.
  • Only 26% of respondents deny the use of command-line scripting tools (such as PowerShell) by default.
  • 69% of organizations indicated that they do not limit access to the internet for their Windows domain controller hosts.
  • Only 29% of respondents evaluate the cybersecurity posture of external parties prior to allowing them access to the organization’s network.
  • Only 50% of respondents conduct user awareness training for employees on email and web-based threats, such as spear-phishing and watering hole attacks, on an annual basis.

“As ransomware techniques continue to become more sophisticated and readily available, the threat to organizations, regardless of size or industry, increases,” stated Scott Kannry, CEO and Co-Founder of Axio. “Companies need to take a proactive approach to ransomware by evaluating and identifying gaps in their cybersecurity posture. Our research clearly illustrates that some improvements in ransomware defense may be directly attainable by re-committing to improving basic cyber hygiene. Axio is committed to helping organizations take a proactive approach by identifying and quantifying cybersecurity risks, including growing threats like ransomware. The key is to be ready.”

To learn more, please download a complimentary copy of the report.

About Axio

Axio is the leader in SaaS-based risk management software, which empowers security leaders to build and optimize security programs and quantify risk for better investment prioritization and decision-making. Since 2013, Axio has been a trusted partner of the world’s leading critical infrastructure, manufacturing, and financial services organizations. Axio360 is the only risk management platform designed to align security leaders, business leaders, executives, and Boards of Directors around a common set of benchmarks, performance metrics, and shared understanding of the most critical corporate risks.

Contacts

Media
Alexandra Pony
Silver Jacket Communications for Axio
alexandra@silverjacket.net

Axio


Release Summary
New Axio Research Report illustrates glaring deficiencies in cybersecurity hygiene leaving organizations exposed to ransomware.
Release Versions

Contacts

Media
Alexandra Pony
Silver Jacket Communications for Axio
alexandra@silverjacket.net

More News From Axio

BlueVoyant Partners with Axio to Modernize Cybersecurity Vendor Selection

NEW YORK--(BUSINESS WIRE)--BlueVoyant, the market leader in integrated security, today announced a new partnership with Axio, a leading SaaS provider of cyber risk quantification solutions. The partnership will enable BlueVoyant customers to receive customized ROI reports evidencing how much cyber risk, in financial terms, BlueVoyant products have helped to reduce or eliminate. This collaboration aims to solve some of the cybersecurity market’s most pressing challenges, centered on the difficul...

Axio Named a Leader in Industry Cyber Risk Quantification Report

NEW YORK--(BUSINESS WIRE)--Axio, the SaaS platform that empowers organizations to quantify, manage, and communicate cyber risk, has been recognized as a Leader in The Forrester Wave™: Cyber Risk Quantification Solutions, Q2 2025. Founded in 2016, Axio has redefined how enterprises approach cyber risk by making Cyber Risk Quantification (CRQ) a core element of cybersecurity program evaluation and strategic decision-making. Axio’s designation as a Leader in the Forrester Wave reflects the platfor...

Axio Unveils Quantification Wizard for Quick Time to Value with CRQ

NEW YORK--(BUSINESS WIRE)--Axio, a leader in cyber risk management software, today unveiled its Quantification Wizard, a powerful tool designed to simplify and accelerate cyber risk quantification. Available now on Axio's platform, the Wizard allows organizations to quickly assess and quantify the financial impact of cybersecurity risks, helping them make well-informed, prioritized decisions. Cyber risk quantification has traditionally been a resource-intensive task, demanding time, expertise,...
Back to Newsroom