Playing Ransomware Odds

Playing the Ransomware Odds

Updated

Table of Contents

The odds that ransomware will exploit an unidentified (or unpatched) vulnerability in your network defenses are no longer negligible.

This is due to the porous nature of modern networks and applications, coupled with hackers’ realization that poorly secured midmarket enterprises and SMBs are far easier to hack into than large enterprises with their dedicated security operations and endless resources.

As a business owner or MSP in charge of security – what can you do to prepare?

Consider undergoing an ISO27001 or similar audit. Even if you don’t need itthe audit process will require you to consider all your data protection operations, from access controls to IPS/IDS, verifying data stores, and managing endpoint security.

Consider your DR policies

Sure, storing just one PITR (point-in-time restore) is cheaper than months of LTR (long-term retention), but consider that modern ransomware takes its time to find data and encrypt it, and by the time you realize what happened, your PITR may have been contaminated. Keeping a few months of LTR may help you recover data that the ransomware corrupted long ago.

Consider a layered defense

No defense mechanism covers 100% of exploits. Some recent exploits were only ever addressed by 1-2 AV/EDR vendors. Unfortunately, the law of diminishing returns works hard here—security products overlap by 99% of their coverage and, worse, affect performance. Yet, that is what enterprises have been doing for 15-20 years.

Manage and protect your data

Hackers are not after exploits or vulnerabilities. They are after your data. Specifically, they are after data that will cause you to pay their ransom requests. Since we all know selling IP is hard, they will look for easy-to-use data like medical, PII, and financial records. Understanding what type of data you store could be used for ransom or will put your company in difficulty – is an essential first step in scoping the risk.

The last line of defense

Reducing the amount of data available to steal should be a high priority. Finding the data, protecting it by encrypting it or locking it up in a safely guarded server or in the cloud, or even deleting it if possible, should also be a high priority.

While the risks are high, preparing for an inevitable event requires a clearly laid out plan that identifies the data targets, reduces their footprint, and addresses as many of the threats as possible.

Sensitive Data Discovery, Risk Quantification & Encryption

See how Actifile gives you unprecedented visibility to sensitive data files, discovers what needs protecting, and makes it useless to cyber criminals.