Ransomware and Ransom Attacks

Between 2016 and 2018, ransomware attacks increased by more than 350% worldwide and are widely recognized as the second greatest threat to organizational information assets, following insider threats.

8 slides · 2 min read · Domain 3

Slide 1

Organizations should be prepared for ransomware attacks and ready to respond in the event an attack occurs. The organization should have policies and procedures for a response to this situation and should train its staff to respond in the event it does occur. Many steps can be taken to improve an organization's ability to respond to ransomware attacks:

Back up Data

Back up data regularly and verify the ability to restore from backups.

Separate Backups

Separate backups from the computer and network they are backing up (cloud or storing offline).

Isolate processes

Physically isolate sensitive processes on networks disconnected outside connections. Implement cross-domain solutions where appropriate to limit and review the types of information moved between the different classifications of networks.

Use licensed software

Use legally licensed and supported software properly updated through patch management practices, including OS, applications and firmware on devices.

Conduct training

Conduct security awareness training to make users aware of ransomware vectors, indicators and actions to take in the event of compromise.

Configure Tools

Configure anti-malware tools to automatically update signature files and conduct mandatory storage scans.

Implement Protections

Implement email spam protections, including blocking unauthorized gateways and potentially malicious attachments.

Verify Systems

Verify IDS and IPS systems are implemented as designed and reporting status.

Reassess Practices

Reassess organizational incident response practices to authorize faster organizational decision-making in response to ransomware indicators. Authorize quarantine of select network segments in the event of compromise.

Conduct Exercises

Conduct tabletop exercises and simulations based on ransomware events to identify weaknesses in processes and procedures.

Define Processes

Define decision-making processes, procedures and legal authority if the organization decides to pay the ransom demand.

Organizations should also strongly consider threat hunting techniques such as those used by endpoint detection and response (EDR) and extended detection and response (XDR) systems. These more powerful systems can incorporate cuttingedge use cases for various types of ransom and ransomware attacks.

It's worth noting that in some legal jurisdictions, such as the United States, there is a presumption of what is called strict liability, meaning that an organization that negotiates with and pays a ransom in any circumstances - has to presume that the party they are paying may be on a government sanctions list that prohibits any form of commerce with them without first obtaining special permission from the government.

These are not new policies. Cyber insurance and general liability insurance providers are normally well aware of these issues, and work with the respective government authorities (such as the U.S. Office of Foreign Assets Control) to keep their clients on the right side of the regulations. Nonetheless, this adds additional emphasis to work with the organization's legal counsel before the first ransom attack happens, rather than during the response phase of it.

Test this domain