Ransomware Attack Protection

Ransomware attacks are growing in size and frequency and are threatening businesses all around the world. As more employees return to offices after working from home for months on end, cyber security dangers are a big concerns.
 
The shift to remote working triggered by the pandemic has also underlined significant cyber security threats for employers and employees alike. Now,  the head of the UK’s National Cyber Security Centre has warned that ransomware has become the biggest threat to British people and businesses. 
 
In a speech being given by Lindy Cameron, chief executive of the NCSC  she highlighted the need for ransomware problem to be taken seriously, and warns of the “cumulative effect” if society fails to properly deal with the rising threat. “Far more worrying is the cumulative effect of a failure to manage cyber risk and the failure to take the threat of cyber criminality seriously. For the vast majority of UK citizens and businesses, and indeed for the vast majority of critical national infrastructure providers and government service providers, the primary key threat is not state actors but cyber criminals,” she said. 

In 2018 cyber criminals stole 8 billion Euros, in 2020 they had stolen over 20 billion Euros.

  • Ireland’s health-care system has been in disarray since May 14th when the Health Service Executive, the state-funded health-care provider, was hit by a ransomware attack which led it to shut down most of its computer systems. The attackers threatened to release stolen data, including confidential patient records, unless the Health Service paid €16.5m, which it has declined to do.
  • The Colonial Pipeline attack shut down a system which delivers 45 percent of all the fuel to the US Eastern Seaboard, and the week-long ransomware attack caused public havoc with gas shortages on the East coast. The company confirmed that it paid $4.4 million in bitcoin to end the double-extortion ransomware attack, but i the FBI and managed to recover a substantial proportion of this. 
  • The highest reported payment targeting Travelex and the ransom settlement was thought to be about $6 million, though the exact amount remains unknown.  Another large 2020 ransomware demand involved the French construction firm Bouygues. The demanded sum was around $11.8 million.

How Ransomware Works 

Ransomware is a type of malware used by cyber criminals to make a lot of money. Malware, are software programs that enable cyber criminals to take over an electronic device once it is infected. The majority of ransomware attacks begin with phishing emails and the cyber criminals hide the malware in an attachment that poses as a benign file, like an invoice or a report. As soon as the victim opens the attachment, the ransomware spreads through their device, locking files and leaving behind a ransom note.

 

Once infected, there are numerous ways cyber criminals can leverage the victim’s system for profit, such as collecting credit card data which they then sell, harvesting logins and passwords to people’s bank accounts. They can then use the account to steal and transfer money, finding personal information which they leverage for identity fraud, or connect the victim’s computer into a botnet for attacks such as Distributed Denial of Service (DDoS) attacks. 

After cyber criminals infect a single computer in an organisation, they do not immediately demand a ransom. Instead, they use that infected system to stealthily infect other computers in the organisation, perhaps even the backups. Not until the cyber criminals believe almost every system has been infected, and not until they have exfiltrated an extensive amount of data will they then enable the ransomware, encrypt all the devices, and notify the organisation.
 
 Attackers will also threaten to publish data if payment is not made. To counter this, organisations should take measures to minimise the impact of data exfiltration.
 
Law enforcement agencies do not as a rule encourage the payment of ransom demands. If you do pay the ransom, there is no guarantee that you will get access to your data or computer. Furthermore, your computer system will still be infected and you are more likely to be targeted in the future. 
 
Ransomware has proven to be one of the fastest and more profitable than almost any other attack, but by teaching your people to spot phishing scams, you can prevent the majority of ransomware attacks.

Stopping Ransomware

In the highly developed world of cyber crime there are entire organisations dedicated to continually developing malware that cannot be detected. There are four general areas of vulnerability to ransomware infection that need to be carefully monitored: 
 
Social Engineering: These types of attacks, especially phishing, are one of the primary methods cyber attackers use to infect systems. Train people on how to spot and stop phishing attacks.
 
Passwords: Weak or insecure passwords are another very common way cyber attackers break into organisations today. Provide the training and tools to ensure people are using strong passwords.
 
Updating: Updated and current systems are much harder for cyber attackers to infect with malware. We want to ensure people are always using the most current operating systems and applications. In some cases, you may want to emphasise the importance of enabling automatic updating.
 
Training: Lessons for your workforce on how to report a suspected infected computer. Ensure they feel comfortable reporting, even if they know they caused the infection. 
 
As more employees return to offices after working from home for months on end, cyber security dangers are a big concern and every employee need to be aware of the risk of malware that could be waiting on their devices.
 
NCSC:      SANS:      Hornet Security:          Heimdal Security:     Cloudwards:      ITGovernance:
 
ZDNet:       Chain Analysis:    Komo News:      Economist:     Tripwire:     Legal Futures:        HLB
 
You Might Also Read: 
 
Negotiating Ransom: To Pay Or Not?:
 
 
« How To Write Learning Objectives For Cyber Security Training
Massive Attack: 200+ US Organisations Hacked »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

eco

eco

eco, with more than 950 member organizations, is the largest Internet industry association in Europe.

INCIBE-CERT

INCIBE-CERT

INCIBE-CERT is the reference security incident response center for citizens and private law entities in Spain

Cybersecurity Credentials Collaborative (C3)

Cybersecurity Credentials Collaborative (C3)

C3 provides a forum for collaboration among vendor-neutral information security and privacy and related IT disciplines certification bodies.

Cybersecurity Innovation Hub

Cybersecurity Innovation Hub

The main objective of the Hub is to bring cybersecurity and other advanced technologies closer to companies and as a result help to increase their performance as Industry 4.0.

IAR Systems

IAR Systems

IAR Systems are a frontrunner in a changing industry, and a future-proof software supplier enabling the IoT.

Visium Technologies

Visium Technologies

Visium Analytics provides innovative data visualization, cybersecurity technologies and solutions to businesses to protect and secure their data assets.

ACET Solutions

ACET Solutions

ACET Solutions delivers a wide range of Automation, Cyber Security and Enterprise IT/OT Integration Solutions to industrial clients.

Scarlett Cybersecurity

Scarlett Cybersecurity

Scarlett Cybersecurity provide cybersecurity services to US private and public organizations with specific emphasis on compliance and cybersecurity incident prevention, detection, and response.

Mindmajix Technologies

Mindmajix Technologies

Mindmajix is a live and interactive e-learning platform that offers professional online IT training in areas including cyber security.

Foundries.io

Foundries.io

Foundries.io have built a secure, open source platform for the world's connected devices, and a cloud service to configure this to any hardware and any cloud.

UK Cyber Security Association (UKCSA)

UK Cyber Security Association (UKCSA)

The UK Cyber Security Association (UKCSA) is a membership organisation for individuals and organisations who actively work in the cyber security industry.

Mirai Security

Mirai Security

Mirai Security are a cyber security company that specializes in Governance, Risk Management and Compliance, Cloud Security and Application Security.

Commvault

Commvault

Commvault's data protection and information management solutions help companies protect, access and use all of their data, anywhere and anytime.

ThreatER

ThreatER

ThreateER (formerly ThreatBlockr / Bandura Cyber) is a cybersecurity platform that provides active network defense by automating the discovery, enforcement, and analysis of cyber threats at scale.

Codenotary

Codenotary

Codenotary provide a comprehensive suite of verification and enforcement services to guarantee the integrity of your software throughout its entire lifecycle.

Coalition for Secure AI (CoSAI)

Coalition for Secure AI (CoSAI)

CoSAI is an open ecosystem of AI and security experts from industry leading organizations dedicated to sharing best practices for secure AI deployment and collaborating on AI security research.