Ransomware victims fail to fix flaws that exposed them, according to new research from Black Kite. Their annual ransomware report highlights a persistent problem: many organisations do not fully address the weaknesses that allowed cybercriminals in, even after suffering a ransomware attack. This ongoing risk is leaving businesses open to repeat incidents and further losses.
Black Kite’s Findings: Ongoing Vulnerabilities After Attacks
The 2024 Black Kite ransomware report provides an in-depth look at the aftermath of ransomware incidents. Released in June 2024, the report analysed hundreds of organisations that had previously fallen victim to ransomware. Its findings are stark: a significant proportion of these organisations still operate with unpatched critical vulnerabilities and misconfigured email security settings, even after completing their initial incident response and recovery processes.
Key statistics from the report include:
- 43% of ransomware victims still have at least one unpatched critical vulnerability in their systems.
- 31% continue to have at least one vulnerability currently listed by the US Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited.
- 59% of victims have not properly configured their Domain-based Message Authentication, Reporting & Conformance (DMARC) email authentication.
- 32% have misconfigured DomainKeys Identified Mail (DKIM) records, leaving their email domains vulnerable to spoofing and impersonation attacks.
How Attackers Exploit Lingering Weaknesses
The report makes clear that ransomware is a profit-driven business. Cybercriminals systematically scan for the easiest and most profitable targets. When organisations fail to remediate the entry points used in a previous attack, they remain on the radar for further exploitation. Attackers do not require a single, perfect vulnerability. Instead, they seek evidence that access may still be available, identity controls may be weak or trust controls are incomplete.
These visible signals matter because they are used by attackers to prioritise targets for repeat attacks. The unpatched vulnerabilities and misconfigured email authentication systems are easily discoverable from outside the organisation, making it simple for attackers to identify which victims have not fully recovered or secured their environments.
CISA KEV and Actively Exploited Vulnerabilities
Of particular concern is the continued presence of vulnerabilities listed in CISA’s Known Exploited Vulnerabilities (KEV) catalogue. These are security flaws for which attacks are already occurring in the wild. When 31% of ransomware victims continue to operate with at least one of these vulnerabilities unpatched, it dramatically increases their risk of being targeted again by the same or different cybercriminal groups.
Email Authentication Weaknesses
Email-based attacks, such as phishing and business email compromise, remain a common precursor to ransomware. The report found that 59% of victim organisations have not properly configured DMARC, a technology designed to prevent unauthorised use of an organisation’s email domain. Additionally, 32% have misconfigured DKIM records, which are essential for authenticating legitimate email communications. These weaknesses allow attackers to spoof email addresses and trick employees into opening malicious attachments or links, restarting the ransomware infection cycle.
Who Is Affected: Sectors, Organisations and Products
The Black Kite research covers a wide range of sectors and organisation sizes, but small and medium businesses are particularly at risk. They often lack the resources or expertise to thoroughly remediate after an attack. The report does not single out specific software products or vendors, but notes that the vulnerabilities most often left unpatched include those affecting widely used operating systems and business applications.
- All sectors are affected, with professional services, healthcare and education among the top targets.
- Victim organisations span from small businesses to large enterprises.
- Commonly unpatched products include Microsoft Windows, Microsoft Exchange, and various web application frameworks.
Timeline and Current Exploitation Status
The Black Kite report was published in June 2024, but the data reflects trends seen throughout 2023 and into early 2024. The persistence of critical vulnerabilities and email misconfigurations is an ongoing issue. CISA continues to update its KEV catalogue with new vulnerabilities as they are discovered and exploited, and ransomware groups are quick to capitalise on unpatched systems.
There is no evidence that exploitation has waned. In fact, attackers are increasingly leveraging automation and AI tools to identify and exploit these lingering weaknesses. Organisations that have already suffered a ransomware attack remain at heightened risk of repeat incidents if they have not addressed the root causes.
Why It Matters: The Cost of Incomplete Recovery
Fixing the technical flaws that enabled a ransomware incident is not just good practice, it is essential to prevent further attacks. Failing to address these issues can result in additional breaches, reputational damage and financial losses. Attackers routinely revisit previous victims, looking for signs that vulnerabilities remain unpatched or email defences are still weak. Incomplete remediation increases the likelihood of being targeted for another ransom demand.
What Organisations Should Do Next
Organisations that have been affected by ransomware should:
- Prioritise patching all critical vulnerabilities, especially those listed in the CISA KEV catalogue.
- Ensure DMARC and DKIM are properly configured and regularly tested.
- Conduct a thorough post-incident review to identify and address all entry points used by attackers.
Remediation should be treated as a vital part of recovery, not an optional afterthought. This approach reduces the risk of repeat incidents and demonstrates to attackers that the organisation is no longer an easy target.
Originally reported by cybersecuritydive.com.






