{"id":148,"date":"2024-09-08T19:10:03","date_gmt":"2024-09-08T19:10:03","guid":{"rendered":"https:\/\/kaizenmarketing.noumanshahid.com\/?p=148"},"modified":"2024-09-08T19:10:03","modified_gmt":"2024-09-08T19:10:03","slug":"the-essential-guide-to-understanding-ransomware","status":"publish","type":"post","link":"https:\/\/kaizenmarketing.noumanshahid.com\/?p=148","title":{"rendered":"The Essential Guide to Understanding Ransomware"},"content":{"rendered":"<p>Ransomware is a serious threat for companies of all sizes. The objective of this article is to showcase the dangers of ransomware and (more importantly) to give companies cutting-edge tactics they can use to protect themselves.<\/p>\n<h2>The False Narrative About Ransomware<\/h2>\n<p>This article\u2019s readers will fall into two categories: those who have been recently affected by a ransomware attack and those who haven\u2019t. The former group will have no illusions about the perniciousness of modern ransomware. However, the latter group may be under the misconception that ransomware is becoming extinct. After all, there are many headlines on the web touting the decline of ransomware.<\/p>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2018\/07\/12\/malware_sitrep\/\">Ransomware Is so 2017<\/a><\/p>\n<p><a href=\"https:\/\/www.techrepublic.com\/article\/why-cryptomining-is-the-new-ransomware-and-businesses-must-prepare-for-it\/\">Why Cryptomining Is the New Ransomware<\/a><\/p>\n<p><a href=\"https:\/\/healthitsecurity.com\/news\/cybercriminals-move-from-ransomware-attacks-to-crypto-mining\">Cybercriminals Move from Ransomware Attacks to Crypto Mining<\/a><\/p>\n<p><a href=\"https:\/\/resources.infosecinstitute.com\/the-decline-of-ransomware-and-the-rise-of-cryptocurrency-mining-malware\/#gref\">The Decline of Ransomware and the Rise of Cryptocurrency Mining<\/a><\/p>\n<p>Nevertheless, the statistics gainsay the decline of ransomware. The headlines don&#8217;t tell the whole story. Ransomware is still alive and thriving. Look at the following statistics.<\/p>\n<ul>\n<li>48% of IT consultants noted an increase in ransomware related consolation and inquires. (Intermedia, 2017)<\/li>\n<li>From 2016 to 2017 Ransomware attacks spiked 350%. (Dimension Data, 2018)<\/li>\n<li>In 2017, 25% of cyber insurance claims were because of ransomware. (AIG, 2018)<\/li>\n<li>WannaCry ransomware could cost businesses $4 billion (Cyence, 2017)<\/li>\n<\/ul>\n<p>Organizations of all sizes are impacted by ransomware attacks, even as rumors of ransomware\u2019s decline float around the internet. These attacks are inconvenient and expensive. For instance, the town of Matanuska-Susitna, Alaska had its phones, servers, computers, and email exchange crippled by ransomware, forcing the town\u2019s employees to use <a href=\"https:\/\/mashable.com\/2018\/08\/02\/malware-alaska-town\/?europe=true#bA_nUjlXmOqU\">typewriters<\/a>. Likewise, the city of Atlanta had to pay <a href=\"https:\/\/www.ajc.com\/news\/confidential-report-atlanta-cyber-attack-could-hit-million\/GAljmndAF3EQdVWlMcXS0K\/?icmp=np_inform_variation-control\">17 million<\/a> to clean up the devastating SamSam ransomware attack.<\/p>\n<p>In summary, ransomware is still active and pernicious.<\/p>\n<h2>No Industry Is Safe From Ransomware<\/h2>\n<p>You may have noticed the examples above (Atlanta and Matanuska-Susitna) involve public sector organizations. It\u2019s true that many high-profile ransomware salvos are against municipalities. At the same time, there is a myriad of ransomware attacks against the private sector. Here are some headlines that show the private sector is not immune to ransomware assaults.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.wane.com\/news\/local-news\/ransomware-attack-targets-adams-memorial-hospital\/1035687429\">Ransomware Attack Targets Adams Memorial Hospital<\/a><\/li>\n<li><a href=\"https:\/\/www.healthcareitnews.com\/news\/allscripts-sued-over-ransomware-attack-accused-wanton-disregard\">Allscripts sued over ransomware attack, accused of \u2018wanton\u2019 disregard<\/a><\/li>\n<li><a href=\"http:\/\/www.greenfieldreporter.com\/2018\/01\/16\/01162018dr_hancock_health_pays_ransom\/\">Hospital pays $55,000 ransom; no patient data stolen, Greenfield, IN<\/a><\/li>\n<li><a href=\"https:\/\/www.beckershospitalreview.com\/cybersecurity\/labcorp-90-recovered-from-samsam-ransomware-attack.html\">LabCorp 90% recovered from SamSam ransomware attack, Burlington, NC<\/a><\/li>\n<\/ul>\n<p>You can find a myriad of examples of private sector companies that have fallen victim to ransomware. Here\u2019s another point to consider: some ransomware attacks are never reported. Municipalities and hospitals typically have government regulations that demand disclosure. Conversely, many private sector businesses are bound by no such regulations and wish to stay out of the press. Therefore, the rate of ransomware attacks against private organizations is likely much higher than we know.<\/p>\n<h2>Practical Ways to Protect Your Company From Ransomware<\/h2>\n<p><strong>Inventory Your Internet-Facing Assets-<\/strong> When your network is connected to the internet, your security is tested. Your internet-facing assets are open to being probed by hackers. The first step to securing these ports is to catalog them. Once they\u2019re totally archived, you can ensure they\u2019re protected by your security measures.<\/p>\n<p><strong>Filter All Email for Spam Messages-<\/strong> Email attachments with ransomware infect <a href=\"https:\/\/www.dcsny.com\/technology-blog\/invoice-email-attachment-is-ransomware-locky\/\">millions of computers<\/a>. You can protect yourself by not opening up unsolicited attachments in unverified emails.<\/p>\n<p><strong>Macros-<\/strong> Disallow macros unless they\u2019ve been verified by your IT admin or your managed IT team.<\/p>\n<p><strong>Limit RDP Access-<\/strong> Require all RDP access to be routed over a VPN secured by 2-factor authentication.<\/p>\n<p><strong>Comprehensive Backup System-<\/strong> Disaster recovery as a service and a potent cloud backup will help remove the sting of ransomware.<\/p>\n<p><strong>Ransomware Protocol for Employees-<\/strong> Don\u2019t allow bad company policy to compound the negative effects of ransomware. Employees must know who to alert in case of a ransomware attack. Also, employees often fear retribution when coming forth about a cyber-attack. Time is critical in these instances, so it\u2019s imperative you alleviate these concerns so employees feel comfortable coming forward. Lastly, employees should have a clear directive about what can be discussed with the outside world.<\/p>\n<h2>Should You Pay a Ransom<\/h2>\n<p>IT professionals are of two minds about paying a ransom. First off, you have a couple of alternatives. <a href=\"https:\/\/www.welivesecurity.com\/2018\/03\/07\/ransomware-revolution\/\">David Harley<\/a>, the Senior Research Fellow at ESET, suggests contacting your security software vendor because recovery may be possible without paying the ransom. Second, Harley opines you may be able to restore your data from backups.<\/p>\n<p>Recovering from backups can be more expensive than paying a ransom. That\u2019s why businesses decide to pay. This is often a bad idea. Even if you pay, there\u2019s no guarantee the hackers will keep their word and decrypt your data. There are many accounts of hackers asking for second payments or never decrypting data. On a macro scale, you\u2019re also validating the business model behind the crime.<\/p>\n<p>If you decide to implement a policy of paying ransoms, then make sure you designate someone in the company to be the negotiator. Having the proper policy and procedure is key.<\/p>\n<h2>Conclusion<\/h2>\n<p>More and more companies are depending on data and technology. As that trend continues, ransomware will likely continue to grow. To deal with the growing ransomware threats it\u2019s critical that your organization addresses risk management tactics. This can be done internally or by consulting endpoint security experts like your managed IT company. Contact us today for more info.<\/p>\n<p><a href=\"https:\/\/globalit.com\/shop\/\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1480 size-full aligncenter\" src=\"https:\/\/info.globalit.com\/wp-content\/uploads\/2016\/10\/managed-it.png\" alt=\"\" width=\"345\" height=\"53\" \/><\/a><\/p>\n<p>https:\/\/info.globalit.com\/wp-content\/uploads\/2018\/12\/ransomware-2321665_960_720.png<\/p>\n<p>https:\/\/info.globalit.com\/wp-content\/uploads\/2018\/12\/ransomware-2321665_960_720.png|https:\/\/info.globalit.com\/wp-content\/uploads\/2018\/12\/dde-ransomware.jpg|https:\/\/info.globalit.com\/wp-content\/uploads\/2018\/12\/ransomware-2430833_960_720-e1546460865291.jpg<\/p>\n<p>Computer Security|IT Services|Tech News<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware is a serious threat for companies of all sizes. The objective of this article is to showcase the dangers of ransomware and (more importantly) to give companies cutting-edge tactics they can use to protect themselves. The False Narrative About Ransomware This article\u2019s readers will fall into two categories: those who have been recently affected [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":149,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[],"class_list":["post-148","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-securityit-servicestech-news"],"_links":{"self":[{"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/posts\/148","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=148"}],"version-history":[{"count":0,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/posts\/148\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=\/wp\/v2\/media\/149"}],"wp:attachment":[{"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kaizenmarketing.noumanshahid.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}