A startling number of security professionals, when asked about ransomware readiness, admit that they do not feel confident they have the right tools, processes, or people in place. In fact, many organizations struggle to identify and implement the right solutions for ransomware prevention in the first place. The main reason for the disconnect tends to revolve around a few key misconceptions about ransomware. Take for instance, the thought that endpoint protection is all an organization needs. If you look at the headlines, plenty of organizations had solid endpoint detection and response capabilities and still became victims of ransomware. With that said, what does an organization need for a successful ransomware readiness approach?

10 Tactics for a Successful Ransomware Readiness Approach

[dvmd_table_maker tbl_row_header_count=”0″ tbl_responsive_breakpoint=”none” tbl_image_proportion=”100%” tbl_image_scale=”contain” tbl_image_align_horz=”left” tbl_image_align_vert=”top” tbl_stripes_active=”on” tbl_stripes_apply=”on|off|off|off|off” tbl_stripes_order=”odd” tbl_tcell_cell_align_vert=”left” tbl_tcell_cell_padding=”20px|20px|20px|20px|true|true” tbl_chead_cell_color=”#193F6F” tbl_chead_cell_align_horz=”left” tbl_chead_cell_align_vert=”left” tbl_chead_cell_padding=”20px|20px|20px|20px|true|true” tbl_rhead_cell_color=”#F2F2F2″ tbl_column_max_width_last_edited=”off|phone” tbl_tcell_cell_padding_tablet=”20px||20px||true|true” tbl_tcell_cell_padding_phone=”|5px||5px|true|true” tbl_tcell_cell_padding_last_edited=”on|phone” _builder_version=”4.9.3″ _module_preset=”default” tbl_tcell_text_font_size=”16px” tbl_tcell_text_line_height=”1.5em” tbl_chead_text_font=”|800|||||||” tbl_chead_text_font_size=”16px” tbl_tcell_text_font_size_tablet=”14px” tbl_tcell_text_font_size_phone=”14px” tbl_tcell_text_font_size_last_edited=”on|phone” tbl_chead_text_font_size_tablet=”” tbl_chead_text_font_size_phone=”13px” tbl_chead_text_font_size_last_edited=”on|phone” border_radii=”on|10px|10px|10px|10px” border_radii_tbl_tcell_cell_border=”on|10px|10px|10px|10px” border_radii_tbl_chead_cell_border=”on|10px|10px|10px|10px”][dvmd_table_maker_item col_label=”TACTIC” col_content=”TACTIC
%22%22
Endpoint Protection, Detection, and Response

%22%22
DNS Protection

%22%22
Secure Email

%22%22
Secure Browsing

%22%22
Lateral Movement Prevention

%22%22
Least Privileged Architecture

%22%22
Data Governance

%22%22
Secure Backup Strategy

%22%22
Incident Response Plan

%22%22
Business Continuity Plan
” col_column_max_width=”0.5fr” col_icon_type=”%%59%%” col_icon_color=”#ec7424″ col_image_proportion=”100%” col_image_scale=”contain” col_image_align_horz=”left” col_image_align_vert=”top” col_column_max_width_tablet=”0.7fr” col_column_max_width_phone=”1.1fr” col_column_max_width_last_edited=”on|desktop” _builder_version=”4.9.3″ _module_preset=”default” col_tcell_text_font_size=”16px” col_tcell_text_font_size_tablet=”16px” col_tcell_text_font_size_phone=”16px” col_tcell_text_font_size_last_edited=”on|desktop”][/dvmd_table_maker_item][dvmd_table_maker_item col_label=”DESCRIPTION” col_content=”DESCRIPTION
A solid endpoint detection and response platform is key to overall ransomware protection. Pattern and behavior-based approaches, balanced with signature-based protection, is a compelling blend for overall ransomware prevention. Many consider ransomware reaching the endpoint as “too late” but it is better to have the capability then not.
Consider DNS protection as another layer of overall ransomware prevention. The malware is blocked from being downloaded if it is a known malicious website.
Many ransomware attacks begin with an email that either contains attached malware or a link to a location to download the malware. An email security solution scans for malicious attachments and strips them as well as protecting from clicking on malicious links.
Malware that is detonated in a sandbox is unable to impact an endpoint. Secure browsing solutions isolate browsing sessions in a container or sandbox and only replays input, output, and video to the end user, preventing ransomware from ever reaching an endpoint.
When all else fails, keeping ransomware contained on a single endpoint is the goal. Ransomware is insidious and attempts to spread to as many systems and file shares as possible. Lateral movement prevention keeps malware from moving across the network to additional systems.
Imagine an environment where people and systems only had enough access to perform a given task at a given time. This utopian compute approach is no longer science fiction, and many organizations are implementing just in time access control to prevent the spread of ransomware.
Who has access to what information? This question is key to preventing the spread of ransomware since if a limited number of users have write access to unstructured data, the malware essentially starves before it can do any real damage.
In the unlikely event that ransomware impacts an organization after implementing the steps above, a sound secure backup strategy is essential for ransomware recovery. Backups should be secure, scanned, and contain an offline copy that is free from ransomware that targets backups.
Often called the “Ransomware Response Playbook,” organizations need an incident response plan specific to a ransomware attack. The response plan should be kept “offline” to avoid having the file encrypted by the ransomware. It is suggested that as part of a ransomware readiness program, an organization keep a bitcoin bank at the ready in case a ransom needs to be paid.
How does an organization continue in the event of a ransomware infection? Having a well laid out recovery plan with local and federal law enforcement contacts is important to know what needs to be done to continue business.” _builder_version=”4.9.3″ _module_preset=”default”][/dvmd_table_maker_item][/dvmd_table_maker]

Ransomware readiness is achievable for any organization. Keep in mind, following the best practices outlined above will reduce the likelihood of breach, but with all things in cybersecurity, nothing is one hundred percent preventable. With the statistic stating that a compromise caused by ransomware is still possible, the most often asked question is “how do we return to normal?” The best way to return to normal is to make sure that any impacted systems or data are held for forensic analysis. A root cause analysis should be performed, and defenses need to be improved based on the findings. Once defenses are improved, data can be restored from a verified safe backup, and business can resume as normal.

Services

Security

Creating a strategy for managing risk and compliance while helping to filter the myriad of cybersecurity technologies

Modern Infrastructure

Empowering your enterprise to its greatest potential through an efficient and secure IT infrastructure

Digital Workplace

Enhancing enterprises with Application and Desktop Virtualization, Device Management, Identity and Security Compliance, and Communications and Collaboration.

Cloud Enablement

Accelerating IT service delivery through the adoption of agile methodologies using systems-oriented approach

Microsoft Expertise

Helping set goals and establishing benchmarks with the successful deployment of Microsoft solutions

Enterprise Managed Services

Best IT practices with design, configuration, implementation, licensing and environmental services

Markets and Market Support Vehicles

Business

Professional services and renowned expertise aligned with the trends and challenges facing a variety of industries

Healthcare

Addressing IT challenges faced by healthcare organizations through trusted services, solutions and relationships

Public Sector

Helping organizations manage costs and high availability while increasing security, compliance and efficiency

Group Purchasing

Industry-leading IT consulting services and technology solutions through a streamlined contracting process

Resource Library

Events

e360 in-person and online events

Solutions Literature

Access content on e360 services

Blog

Read about trending technology

Press Releases

Get official updates about e360

News Stories

Read about industry and e360 news

Media

e360 webinar and podcast content

About e360

Who We Are

Our mission, vision, leadership and team

Accolades

e360 awards and recognition

Privacy

e360's commitment to privacy

Community

e360's commitment to privacy

Careers

e360 career opportunities

Connect With e360

e360 locations and contact resources