Navanta Insights 2026 Digital - Flipbook - Page 3
SPONSORED
CONTENT
Staggering Losses
Annual payments made to ransomware actors over the blockchain, in U.S. dollars.
Source: The 2026 Crypto Crime Report, Chainalysis
$1.5B
$1.2B
$997M
$1.23B
$1.09B
$892M $820M
$900M
$637M
The Best Defense
The threat of ransomware underscores
the need to routinely patch and update
security software across the bank, as well
$600M
as regular employee education to ensure
that all bank staff understand what a
ransomware attack could look like.
$300M
Every bank should assume that it may
eventually be targeted by a ransomware
0
2020
2021
2022
2023
2024
2025
attack, so the board and management
team ought to prepare accordingly. This
means that senior leadership and at least
some directors should participate in
regular tabletop exercises of the bank’s
a link to read or download the ransom
response plan, says Matt Saidel, manag-
recently begun attacking victims in a
note, and by clicking on that message, the
ing director with FTI Consulting. Usually
“smash and grab” style, meaning they get
victim actually allows the ransomware in.
facilitated by a third party such as an
Some ransomware attackers have
a little bit of their target’s data and try
Instead, banks can work with third-par-
attorney or technical adviser, the exercise
to convince their victim they’ve actually
ty cybersecurity experts who are skilled at
walks key leaders through a realistic
captured much more of it. In some cases,
negotiating with these types of criminals,
scenario.
the criminal will use a screenshot or cre-
if they absolutely need to. If the bank has
ate an image using generative AI to act as
the proper security system measures, then
scenario, the facilitator will inject new
proof that they’ve taken the data hostage.
bank staff or a third party may be able to
twists into the situation. What if the threat
As with any type of fraud, the perpetra-
detect early evidence of a breach, like an
actor goes public, for example? “Ransom-
tor is hoping the victim will panic and
unusual outbound connection, and then
ware response is similar to a team sport,”
react before pausing to think about their
determine what specific data has actually
Saidel says. “Like any sport, it requires
next steps.
been stolen.
practice, and it requires having the differ-
As the participants move through that
“If I can’t find evidence that it’s been
If cybersecurity staff determine the
done, maybe it was fabricated outright,”
compromised data is not especially sensi-
Bank leadership might also discuss,
Moss says. “In the age of AI, so many
tive, then they may just erase the exposed
for example, whether the bank would be
things can be faked and forged.”
workstation and move on, Moss says.
willing to pay the ransom in the event of
ent players be able to coordinate together.”
But a bank needs to have a data loss
an attack. There’s a lot of debate about
prevention program in place to be able to
whether victims should ever pay, and
do this. A data loss prevention program
walking through the plan in a tabletop
bank has been breached in a ransomware
refers to a set of tools or processes by
exercise gives everybody a chance to get
attack, it’s not wise to try to negotiate
which the organization identifies its most
on the same page.
directly with the perpetrator, says Moss.
sensitive data and focuses on protecting
It’s possible the attacker may not have
that data. “If you don’t have [a pro-
when you prepare that way, in knowing
actually breached the bank’s defenses and
gram] in place, then you may not know
that your peers, your board, etc., know
is trying to gain access another way. In
whether the data is worth something or
what the plan is and are following the
one method, the attacker sends the target
not,” Moss says.
plan,” Ringsred says.
Responding (or Not) in the Moment
Should you receive a message that your
“There’s confidence in the organization
3