Prevention is Better Than Cure: The Ransomware Evolution – ISBuzz News
Posted: August 10, 2021 at 1:53 am
Ransomware tactics have continued to evolve over the years, and remain a prominent threat to both SMBs and larger organisations. Particularly during the peak of COVID-19,research by IBMfound that ransomware incidents exploded in June 2020, which saw twice as many ransomware attacks as the month prior, taking advantage of remote workers being away from the help of IT teams. The same research found that demands by cyber attackers are also increasing to as much as 31 million, which for businesses of any size, is detrimental for survival.
In recent months, ransomware attacks have not left the mainstream media headlines. And with the number and frequency of ransomware attacks increasing, not to mention the innovation in distribution methods, this should be a wakeup call for organisations to strengthen their defences.Jack Garnsey, Product Manager Security Awareness Training and SafeSend, VIPREexplains that by taking a preventative approach, businesses can take the necessary steps to strengthen their cybersecurity posture. This includes a combination of education, processes, hardware and software to detect, combat and recover from such attacks if they were to arise.
Ransomware in the 21st Century
Ransomware is not a new phenomenon, but its use has grownexponentially, and has led to the development of the term Ransomware as a Service (RaaS), which is a subscription-based model that enables affiliates to use already-developed ransomware tools to execute attacks.
As ransomware incidents become more sophisticated and frequent, such as the increase in fileless attacks which exploit tools and features that are already available in the victims environment, the level of potential damage to a business is heightened. These types of attacks can be used in combination with social engineering targeting, such as phishing emails, without having to rely on file-based payloads. And unfortunately, ransomware is extremely difficult to prevent all it takes is one employee clicking on the wrong link in an email or downloading a malicious attachment.
No matter the size of an organisation, the effects of ransomware can be devastating financially, as well as inflicting longer-term damage to business reputation. The Irish Department of Health and Health Service Executive (HSE)were recently attacked by The Conti ransomware group, who reportedly asked the Health Service for $20 million (14 million) to restore access. This attack caused substantial cancellations to outpatient services, part of a system already stretched to the max due to COVID-19. Some ransomware gangs operate by aflimsy code of ethics, stating they dont intend to endanger lives, but even if a minority of ransomware organisations are developing a sense of conscience, businesses are not exemptfrom the damage that can be done from such attacks.
Additionally, in the US, Colonial Pipeline paid the cyber-criminal group DarkSide nearly $5m (3.6m) in ransom,following a cyber-attack which took its service down for five days, causing supplies to tighten across the US.Unfortunately when under attack, a majority of businesses, such as the major pipeline, often pay the ransom. Luckily for Colonial Pipeline,some of the money was later recovered by the American Department Of Justices Ransomware and Digital Extortion Task Force.But if they pay once they will pay multiple times. A successful ransomware attack can be used various times against many organisations, turning an attack into a cash cow for criminal organisations offering Ransomware as a Service. So much so, that there is now anongoing debatearound whether it should be illegal for businesses or an individual to pay a ransom in order to try and deter the attackers, or at the minimum, to at least report it to the necessary regulators.
Contain and Report It
If a ransomware attack were to take place, it is important that the organisation works with local authorities to try to rectify the issue and follow the guidance. Often, many ransomware attacks go unreported and this is where a lot of criminal power lies.
Prevention is always better than cure, and damage limitation and containment are important right from the outset. As the United States President, Joe Biden, highlighted in hisrecent letterto business leaders around ransomware: The most important takeaway from the recent spate of ransomware attacks on U.S., Irish, German and other organizations around the world is that companies that view ransomware as a threat to their core business operations, rather than a simple risk of data theft will react and recover more effectively.
Most organisations should have a detailed disaster recovery plan in place and if they dont, they should rectify this immediately. The key to every disaster recovery plan is backups. Once the breach has been contained, businesses can get back up and running quickly and relatively easily, allowing for maximum business continuity.
As soon as the main threat has passed, it is recommended that all organisations conduct a full retrospective audit, ideally without blame or scapegoats, and share their findings and steps taken with the world. Full disclosure is helpful not only for customer, client or patient reassurances, but also for other organisations to understand how they can prevent an attack of this type being successful again.
The Support of Digital Tools
When it comes to ransomware, the importance of getting security foundations right must be emphasised. These attacks are not likely to stop or slow any time soon, but their success can be prevented with the right security armoury.
Particularly to mitigate the threat of ransomware, it is crucial to have secure endpoint protection in place which protects at the file, application and network layer across a number of devices, and respond to security alerts in real-time. This has never been more important than during the ongoing pandemic, where employees are dispersed and working from home in order to ensure all devices are protected and comply to the same standards.
Additionally, solutions such as email attachment and URL sandboxing are also vital, as these digital tools provide vital protection against malicious emails. They can help prevent dangerous links, attachments or forms of malware from entering the users inbox by examining and quarantining them. By filtering out this traffic and automatically restricting dangerous content, businesses can maintain greater control over email and the access points to the network.
The Human Layer
The users themselves are a key part of any security strategy. Those who are educated about the types of threats they could be vulnerable to, how to spot them and the steps to take in the event of a suspected breach, are a valuable and critical asset to any organisation.
Employees need to be trained to be vigilant, cautious, suspicious and assume their role as the last line of defence when all else fails. The final decision to click send on an email or a link lies with the human, but this one click could mean the entire organisation falls prey to a ransomware attack. The key is to change the mindset from full reliance on IT, to one where everyone is responsible.In order to strengthen a business human layer protection, security awareness training and education must be implemented across the board.
These programmes are designed to support users in understanding the role they play in helping to combat attacks and malware. Using phishing simulations, for example, as part of the wider security strategy, will help to give employees insight into real life situations they may face at any point. The importance of testing your human firewall was also outlinedin Joe Bidens ransomwareletter: Use a 3rd party pen tester to test the security of your systems and your ability to defend against a sophisticated attack. Many ransomware criminals are aggressive and sophisticated and will find the equivalent of unlocked doors.
Conclusion
Cyber security is a multi-faceted, complicated area, and one which must receive investment in each layer, from the technology to the people, to the tools we give to the users. Nevertheless, businesses of all sizes can safeguard their data and themselves from these types of ransomware attacks by investing in their cybersecurity and ensuring their workforces are conscious and informed of the threats they face.
Both detection and prevention play a key role in stopping ransomware, but it shouldnt be one or the other. The essence of a solid cybersecurity strategy is a layered defence that includes endpoint detection and response, email security, advanced threat protection, web security and a business-grade firewall for the security of your network at its most basic. But even with the most sophisticated software in place, hackers make it their mission to stay one step ahead of IT defences. That is why regular training, in addition to complementary security tools which reinforce security best practice, can provide a fortified strategy for users to mitigate the threat of a cyberattack.
Jack Garnsey, Product Manager Security Awareness Training and SafeSend, VIP
Expert Comments : 0
Security Articles : 1
Jack Garnsey, Product Manager Security Awareness Training and SafeSend at VIPRE
Read more:
Prevention is Better Than Cure: The Ransomware Evolution - ISBuzz News
- The Golden Voyage Music for Inspiration [Last Updated On: June 19th, 2011] [Originally Added On: June 19th, 2011]
- Master Keys to Success Video [Last Updated On: June 20th, 2011] [Originally Added On: June 20th, 2011]
- Barbara Marx Hubbard, Conscious Evolution [Last Updated On: August 10th, 2011] [Originally Added On: August 10th, 2011]
- 2012 Shift of Consciousness [Last Updated On: August 10th, 2011] [Originally Added On: August 10th, 2011]
- Synchronicties, coincidences, and noticing the little things [Last Updated On: June 30th, 2013] [Originally Added On: June 30th, 2013]
- Tracking your every purchase, watching our every move [Last Updated On: May 8th, 2014] [Originally Added On: May 8th, 2014]
- Self-Compassion: Why it's Important and How you Can Practice It [Last Updated On: November 5th, 2014] [Originally Added On: October 16th, 2014]
- The Transhuman Cosmic Conscious Evolution Website ... [Last Updated On: September 14th, 2015] [Originally Added On: September 14th, 2015]
- Conscious Evolution Defined - Foundation for Conscious ... [Last Updated On: September 14th, 2015] [Originally Added On: September 14th, 2015]
- Conscious evolution - Wikipedia, the free encyclopedia [Last Updated On: September 14th, 2015] [Originally Added On: September 14th, 2015]
- Amazon.com: Conscious Evolution: Awakening Our Social ... [Last Updated On: September 15th, 2015] [Originally Added On: September 15th, 2015]
- Consciousness and the Universe: Quantum Physics, Evolution ... [Last Updated On: September 15th, 2015] [Originally Added On: September 15th, 2015]
- Consciousness Evolution [Last Updated On: September 15th, 2015] [Originally Added On: September 15th, 2015]
- Conscious Evolution | CONSTRUCTING A MEMOIR [Last Updated On: September 22nd, 2015] [Originally Added On: September 22nd, 2015]
- Conscious Evolution - FREE Tarot Card Reading [Last Updated On: September 25th, 2015] [Originally Added On: September 25th, 2015]
- Evolution - Conscious Evolution - Co-Intelligence [Last Updated On: October 16th, 2015] [Originally Added On: October 16th, 2015]
- About Conscious Evolution - Linda Goodman Forums [Last Updated On: October 20th, 2015] [Originally Added On: October 20th, 2015]
- Conscious Evolution [Last Updated On: January 22nd, 2016] [Originally Added On: January 22nd, 2016]
- Conscious Evolution - Home [Last Updated On: January 25th, 2016] [Originally Added On: January 25th, 2016]
- Back to the Future: LCWR nuns and Conscious Evolution ... [Last Updated On: May 1st, 2016] [Originally Added On: May 1st, 2016]
- Carruthers - The Evolution of Consciousness [Last Updated On: August 17th, 2016] [Originally Added On: August 17th, 2016]
- The Conscious Evolutionary 2.0 | The Shift Network [Last Updated On: August 17th, 2016] [Originally Added On: August 17th, 2016]
- Conscious Evolution (Kansas City, MO) - Meetup [Last Updated On: August 17th, 2016] [Originally Added On: August 17th, 2016]
- 'Focusing Within' Using Tai Chi - Nisqually Valley News [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Tai Chi, Free Massages on Tap for Farmers Market Saturday - The Local Ne.ws (registration) [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Fly-fishing plus tai chi for adults and writing event for tweens - Pagosa Springs Sun [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Tai chi class set to begin Tuesday - The Mountain Press [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Tucson Tai Chi, Yoga, Martial arts and more July 13-21 - Arizona Daily Star [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- How to Do Tai Chi (with Pictures) - wikiHow [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- Pierre Teilhard De Chardin Information [Last Updated On: May 31st, 2020] [Originally Added On: July 23rd, 2017]
- Fighting for the Tasmanian devil: photos, video - Ararat Advertiser [Last Updated On: July 30th, 2017] [Originally Added On: July 30th, 2017]
- What's New In The World Of Robot Sex? - NPR [Last Updated On: July 30th, 2017] [Originally Added On: July 30th, 2017]
- Girl Scouts step up with badges tied to STEM, cybersecurity - NewHampshire.com [Last Updated On: July 30th, 2017] [Originally Added On: July 30th, 2017]
- Art Awakening Humanity Alexander de Cadenet Interviewed By Revd Jonathan Evens - ArtLyst [Last Updated On: July 30th, 2017] [Originally Added On: July 30th, 2017]
- 'Nature Boy' Ric Flair on the Hard Knocks, Hard Partying and Hard Lessons of a Pro Wrestling Life - Channel Guide Magazine [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- The evolution of network security strategies being adopted by the financial services sector. - Finextra (blog) [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Finland in the Stall Out zone for digital evolution? - Helsinki Times [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Sheila Gautreaux Highlights Importance of Forgiveness - Benzinga [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Nights Of Fire: A Conscious Evolution Festival Preview - NYSMusic [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Conscious TV - Homepage [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Consciousness - Wikipedia [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- The 8 Stages of Conscious Evolution - Waking Times [Last Updated On: August 17th, 2017] [Originally Added On: August 17th, 2017]
- Urban Intellect fashion designer Bernard Tucker has classic views on race - Rolling Out [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- Dear Younger Me: Michael Granville - MileSplit [Last Updated On: August 23rd, 2017] [Originally Added On: August 23rd, 2017]
- The Fascinating Evolution of Taylor Swift's Sound, from 2006 to Now - MarieClaire.com [Last Updated On: August 27th, 2017] [Originally Added On: August 27th, 2017]
- Conscious Life News | News and Articles About Conscious ... [Last Updated On: August 27th, 2017] [Originally Added On: August 27th, 2017]
- Archer (2009) Art of the Title [Last Updated On: August 27th, 2017] [Originally Added On: August 27th, 2017]
- If The Big Bang Started The Universe, What, or Who, Started the Big Bang? What About The Multi-Verse? - Collective Evolution [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- How I Induced An Out Of Body Experience Without Substances - Collective Evolution [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- Cliff's Edge - Science and Progress Toward the Truth - Adventist Review [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- Is Information the Basis for the Universe? - Discovery Institute [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- Evolution and social justice, nature itself - Global Sisters Report (blog) [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- India working on developing roadmap for NDC implementation: Harsh Vardhan - Daily Excelsior [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- Mainstream Science Finally Recognizes The Consciousness of ... [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- An Answer Existential Questions: Science & Spirituality ... [Last Updated On: August 31st, 2017] [Originally Added On: August 31st, 2017]
- Environment Minister's inaugural address at Business and Climate change Summit 2017 - India Education Diary [Last Updated On: September 1st, 2017] [Originally Added On: September 1st, 2017]
- Into the Grey Zone: can one really be conscious while in a coma? - New Statesman [Last Updated On: September 1st, 2017] [Originally Added On: September 1st, 2017]
- See Zendaya's Hair Evolution, From Mullet to Locs and More - Allure Magazine [Last Updated On: September 1st, 2017] [Originally Added On: September 1st, 2017]
- Programme directory - Conscious TV - Homepage [Last Updated On: October 11th, 2017] [Originally Added On: October 11th, 2017]
- Superbrain Yoga: 3 Minutes That Maximize Brain Power ... [Last Updated On: October 14th, 2017] [Originally Added On: October 14th, 2017]
- What is Ascension | Sandra Walter - Creative Evolution [Last Updated On: October 14th, 2017] [Originally Added On: October 14th, 2017]
- If Consciousness is a Door, Kundalini Yoga is the Key [Last Updated On: October 30th, 2017] [Originally Added On: October 30th, 2017]
- The Importance of Conscious Awareness Collective Evolution [Last Updated On: November 29th, 2017] [Originally Added On: November 29th, 2017]
- Conscious evolution - Wikipedia [Last Updated On: December 8th, 2017] [Originally Added On: December 8th, 2017]
- One Buddha Teaching That Will Tell ... - Collective Evolution [Last Updated On: December 13th, 2017] [Originally Added On: December 13th, 2017]
- Initiation through 52 Codes of Conscious Evolution [Last Updated On: December 28th, 2017] [Originally Added On: December 28th, 2017]
- Events with Sandra Walter | Sandra Walter - Creative Evolution [Last Updated On: December 28th, 2017] [Originally Added On: December 28th, 2017]
- Awake vs. Conscious: How They Differ & Why it Matters ... [Last Updated On: January 9th, 2018] [Originally Added On: January 9th, 2018]
- Sacred Centers - Tools for Conscious Evolution [Last Updated On: January 14th, 2018] [Originally Added On: January 14th, 2018]
- Conscious Entities [Last Updated On: February 1st, 2018] [Originally Added On: February 1st, 2018]
- Neocortex - Wikipedia [Last Updated On: February 13th, 2018] [Originally Added On: February 13th, 2018]
- Physical exercise - Wikipedia [Last Updated On: March 2nd, 2018] [Originally Added On: March 2nd, 2018]
- COTF and Conscious Evolution : Communities of the Future [Last Updated On: March 12th, 2018] [Originally Added On: March 12th, 2018]
- Kids and Exercise [Last Updated On: March 22nd, 2018] [Originally Added On: March 22nd, 2018]
- Leo Gura - Building a Passionate Life [Last Updated On: October 9th, 2019] [Originally Added On: March 24th, 2018]
- Events Northeast Wisdom [Last Updated On: March 30th, 2018] [Originally Added On: March 30th, 2018]
- Groundhog Day (1993) - Trivia - IMDb [Last Updated On: March 30th, 2018] [Originally Added On: March 30th, 2018]
- In Search of the Miraculous - Wikipedia [Last Updated On: March 30th, 2018] [Originally Added On: March 30th, 2018]
- The Amazing Benefits of Himalayan Pink Salt Collective ... [Last Updated On: April 5th, 2018] [Originally Added On: April 5th, 2018]
- ACHIEVEMENT - Motivating Quotes [Last Updated On: April 28th, 2018] [Originally Added On: April 28th, 2018]