Topics: Ransomware in 2021; Twitter Alerts; Ransomware Reality - 92% Don't Get Data Back; Ransomware Recovery and Responders; Sanctions Risks for Facilitating Ransomware Payments; Incident Response and Cyberattack Exercises; and Tips & Best Practices
- The State of Ransomware 2021
Sophos’ annual ransomware survey delivers fresh new insights into the experiences of mid-sized organizations across the globe. It explores the prevalence of attacks, as well as the impact of those attacks on victims, including year-on-year trends. This year, for the first time, the survey also reveals the actual ransom payments made by victims, as well as the proportion of data victims were able to recover after they had paid.
https://secure2.sophos.com/en-us/medialibrary/pdfs/whitepaper/sophos-state-of-ransomware-2021-wp.pdf
- Twitter recommendation: @ransomalert
- Ransomware Reality Shock: 92% Who Pay Don’t Get Their Data Back: https://www.forbes.com/sites/daveywinder/2021/05/02/ransomware-reality-shock-92-who-pay-dont-get-their-data-back/?sh=4750bd00e0c7
- Third Party Ransomware Recovery and Responders:
- Read the Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments October 1, 2020. U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) here.
- Incident response and cyberattack exercises
- https://www.blackhillsinfosec.com/projects/backdoorsandbreaches/
- https://www.ncsc.gov.uk/information/exercise-in-a-box
- https://www.cisecurity.org/wp-content/uploads/2018/10/Six-tabletop-exercises-FINAL.pdf
Tips and Best Practices from Shardul Amarchand Mangaldas & Company, on protecting your firm from Ransomware:
- Email security with sandboxing capabilities
- NextGen firewall with AMP
- Web-filter with sandboxing to deal with zero day threats and C&C over web traffic
- OEM managed XDR solution for complete datacenter (24/7 alert monitoring, correlation, and prioritization, which helps to contain threats and automatically generates IoCs (indicators of compromise) to prevent future attacks)
- Custom on-premise sandboxing based on our infrastructure/applications
- Multifactor authentication – to deal with brute force/password guessing attacks
- Cyber Security awareness training
- SMIME Digital Signature
- Continuous data backup and data recovery
- Patch management: Patching is a critical component in defending against ransomware attacks as cyber-criminals will often look for the latest uncovered exploits in the patches made available and then target systems that are not yet patched & VAPT (Vulnerability Assessment and Penetration Testing)
- Endpoint protection
- Shared Desktop Virtualization
- Mobile container for corporate email and data access
- Restrict Permissions: least privileged policy
- 24x7 SOC
- WatchDog for DMS
- UEBA (User Entity Behavior Analytics)