As many as 57,571 ransomware attacks were detected between January and June 2024 in Southeast Asia (SEA), according to cyber security solutions provider Kaspersky.
Due to growing digital economy and its position as a regional hub for finance and technology, the SEA region remains a hotspot for ransomware attacks, made worse by the regional countries’ varying degrees of cybersecurity priority and infrastructure.
“In general, cybercriminals, including ransomware groups are eyeing critical infrastructure and vulnerable sectors such as financial, public services, manufacturing and healthcare. Essentially, they are opportunists that are after targets big on cash,” says Adrian Hia, Managing Director for Asia Pacific at Kaspersky.
Recent high-profile cases involved attacks on national data centre (Indonesia), public transport operator (Malaysia), health insurance provider (the Philippines), restaurant group (Singapore), and brokerage firm (Vietnam).
The impact of a ransomware attack can be very devastating financially and can often tarnish reputation. Organisations under attacks are forced to allocate additional monetary resources and personnel to address the aftermath of the attacks, and must face the consequences of disrupted operation and downtime, followed by a recovery period.
There are growing global efforts to combat ransomware such as No More Ransom initiative, and regional governments have enacted cybersecurity laws to curb cyber attacks. However, businesses and organisations still need to play their parts in bolstering IT1 Security.
For added protection from ransomware attacks, cybersecurity experts at Kaspersky have recommended the following measures:
- Always keep software updated on all the devices to prevent attackers from exploiting vulnerabilities and infiltrating organisation’s network.
- Promptly install available security patches for commercial Virtual Private Network (VPN) solutions providing access for remote employees and acting as gateways in your network.
- Back up your data regularly and ensuring that such data can be accessed quickly when needed or in an emergency.
- Avoid downloading and installing pirated software or software from unknown/unverified sources.
- Assess and audit your supply chain and manage services access to your environment. Outsource assessment services where necessary.
- Do not expose remote services login information such as RDP2 and MSSQL3 to public networks unless absolutely necessary and always use strong passwords, two-factor authentication and firewall rules for them.
- Monitor access and activity over the network to spot any unusual activity, and controlling user access to as-needed, and as-required basis to minimise risk of unauthorised access and data leak.
- Set up a security operation centre (SOC) using a unified console for monitoring and analysing data related to security breach incidenets as well as deploying strategic cyber defence solutions to ward off attacks.
- Use the latest Threat Intelligence information to have an in-depth understanding of cyberthreats targeting your organisation and provide your information security offiers with the most comprehensive and up-to-date information regarding potential malicious actors.
- Educate employees and improve their cybersecurity literacy as employees should be aware of the risk of cybersecurity threats and how to protect themselves and the organisation they work for.
- Engage an external cybersecurity consultancy service provider to assess the current state of your IT security in order to optimise the IT function that is often heavily burdened.
- If your company does not have a dedicated IT security function and only have generalist IT administrator, consider subscribing to an MDR service that normally offers around-the-clock monitoring that proactively seek out anomalies within your IT environment, while you focus on building in-house expertise for the long term.
- For micro businesses, use solutions intended for the automated management of cybersecurity without having an IT administrator on board especially when the cybersecurity budget is limited, particularly in the early stages of business development.





