In recent years, ransomware incidents have become increasingly severe and they now make up the vast majority of the cyber claims payments made by CFC. Costs are not solely limited to paying a ransom demand, but also often extend to system damage, business interruption, forensics, legal and notification costs. Given this, it’s fair to say that ransomware is now one of the most serious cyber threats that organisations currently face, so having cyber security controls in place to help prevent, detect and mitigate ransomware attacks is essential.
This article will take a look at some of the measures that business owners can take to make their organisations more resilient to ransomware attacks, but before we do so, it’s worth considering what the typical ransomware attack usually involves.
Step 1 – gain access
There are three main ways in which hackers look to gain access to organisations’ computer systems:
- Exploiting remote access solutions – hackers will look to exploit remote access solutions, such as the remote desktop protocol (RDP), by using a computer program that tries to crack passwords by trying numerous possible passwords in quick succession (this practice is commonly known as brute forcing). Alternatively, they may use login credentials that have been stolen in data breaches or voluntarily handed over to cyber criminals in social engineering scams
- Exploiting vulnerabilities – there are thousands of known vulnerabilities that exist within software programs and operating systems, and hackers can use these vulnerabilities to gain a foothold in an organisation’s computer systems. Commonly exploited vulnerabilities include unpatched firewalls and virtual private networks (VPNs).
- Exploiting human error – hackers know that humans are prone to error and they regularly look to make use of this fact in order to gain access to organisations’ computer systems. A common method of entry is to trick employees into clicking on malicious links and attachments in phishing emails. Clicking on these harmful files and links will usually result in malicious software being downloaded onto the employee’s computer, allowing the hacker to gain remote access to the device.
Step 2 – research the organisation, escalate privileges, delete back-ups and exfiltrate data
Once a hacker has gained access to an organisation’s computer systems, they will usually look to do a bit of research on the organisation, looking at what the organisation does and what its annual revenues are. This will usually give the hacker a good idea as to whether the organisation is worth infiltrating further.
If the hacker has managed to gain access by exploiting remote access solutions or getting an employee to click a malicious link or attachment, they will usually only have access to that employee’s computer and the things that particular account has access to. In many cases, the hacker won’t automatically have access to administrator privileges, so escalating user privileges is often the next step. This will usually be done by downloading malicious software from the internet onto the computer that can be used to scrape passwords. What this password scraping malware will do is download every username and password ever used on the computer. Because the computer in question will usually have been set up by an administrator account, this means that administrator login credentials will also be compromised. With these login credentials at their disposal, the hacker can look to move up the network.
Before the hacker looks to unleash ransomware onto the computer systems and begin encrypting data, they’ll usually do a couple of things first. For a start, they will typically look to see if there are any back-ups stored on the organisation’s live environment (often referred to as “online” back-ups). Back-ups are important because if an organisation can successfully recover from back-ups, the incentive to pay a ransom demand is much reduced. As a result, if a hacker can find back-ups on the organisation’s live environment, they will look to delete them to increase their leverage in any ransom negotiations. Alternatively, even if the hacker doesn’t delete these “online” back-ups, the back-ups may be encrypted by the ransomware and rendered inaccessible.
In addition, many hackers will look to steal sensitive data from an organisation’s systems. This helps to increase hackers’ leverage in ransom negotiations, because even if the organisation is able to recover from back-ups, the threat of having that data leaked will still hang over them.
Step 3 – unleash the ransomware and make the ransom demand
With all the preliminary work done, the final step for the hacker is to unleash the ransomware onto the organisation’s computer systems, encrypting data and leaving a ransom note detailing who to contact and what the ransom demand is.
Thankfully, there are measures that business owners can take to make their organisations more resilient to ransomware attacks. These cyber security controls can be broadly divided into three groups: controls that can help prevent hackers gaining access to computer systems, controls that can help detect hackers and controls that can help mitigate a ransomware attack once it’s happened.
Controls to prevent access
We saw earlier that the main ways in which hackers gain access to computer systems are by exploiting remote access solutions, exploiting vulnerabilities and exploiting human error. Fortunately, there are safeguards that can be put in place to reduce the chance of hackers taking advantage of these access points.
One way of helping to better secure remote access solutions is to implement multifactor authentication (MFA). MFA works by requiring that a user has to use more than one method to authenticate themselves before being granted remote access to the network. Typically this requires a username and password to be entered as the first authenticator, followed by a passcode or token generated by a mobile app or SMS message acting as the second authenticator. MFA is usually an effective measure against brute forcing or credential theft because in order for hackers to gain access, they would require not only login credentials but also access to the second device used for authentication, which is unlikely. By having MFA in place, the chances of a cyber criminal exploiting remote access solutions are much reduced.
To help protect against hackers exploiting vulnerabilities in software and operating systems, organisations should ensure that they have good vulnerability and patch management programs in place. Vulnerability management refers to the process of regularly identifying vulnerabilities, evaluating them and taking steps to mitigate risks associated with them. One key component of vulnerability management is to carry out routine vulnerability scans. Vulnerability scanners are software tools used to test systems and networks for security issues by using a database of known vulnerabilities. These scans can help identify vulnerabilities within the organisation’s computer systems and hopefully allow action to be taken before a hacker discovers them.
Patch management is another key component of dealing with vulnerabilities. The term “patch” just refers to any type of code written to correct a bug or vulnerability or to improve the performance of existing software or operating systems. Even though vendors regularly release patches, these patches are only beneficial if they are actually applied by the organisation. This is why patch management is so important, particularly in relation to zero-day vulnerabilities which have only just been identified. Organisations should ideally implement these patches within days of the patch being released by the vendor and within a few weeks at a maximum. By carrying out patches promptly, organisations can significantly reduce the chance of vulnerabilities being exploited by cyber criminals.
Ensuring that employees avoid clicking on malicious links and attachments in phishing emails is not a simple task – it’s more or less impossible to eliminate the risk of human error entirely. However, there are some measures that can be taken to reduce the risk. One control that can be implemented is employee awareness training. Human error plays a major role in the vast majority of social engineering scams, so simply raising awareness of the issue amongst employees can go a long way to reducing the risk of an employee clicking on suspicious links or attachments. A number of tools are available that can help raise awareness, including ones which allow businesses to send out fake phishing emails to test employees and better prepare them for real life incidents.
Email filtering software can also be used to reduce the chances of employees falling for phishing attacks. Email filtering software works by scanning an organisation’s inbound and outbound email messages and placing them into different categories, with the aim of filtering out spam and malicious content. Having this software in place can reduce the likelihood of an email with a malicious link or attachment making it through to an employee’s inbox, or by marking it as spam, it can at least alert the recipient that there may be something suspicious about the email and encourage them to treat it more cautiously.
Controls to detect hackers
Although the controls outlined above can help reduce the risk of a hacker gaining access to an organisation’s systems, there is no guarantee that hackers won’t be able to gain access. So the next step is to have tools which detect the presence of hackers once they’ve gained access to the organisation’s computer systems.
One tool that can be used to detect hackers is an endpoint protection solution. Endpoint protection essentially refers to anti-virus software that is installed on each endpoint (i.e. devices that are used to connect to an organisation’s network, such as desktop computers and work laptops). The quality of endpoint protection solutions can vary. Traditional anti-virus works by scanning files on the endpoint and cross-referencing it with a database of known virus and malware signatures. However, the problem with traditional anti-virus is that it only provides protection against known threats, meaning that the anti-virus is usually one step behind the cyber criminals.
In response to these shortcomings, more sophisticated endpoint protection solutions have been brought to market, which are usually referred to as advanced endpoint protection or next-gen anti-virus solutions. Like traditional anti-virus, advanced endpoint protection will scan, analyse and detect viruses and malware based on a database of signatures and definitions. But it will also conduct behavioural analysis in addition to this. This means that the software is looking out for the way malware and viruses behave and deploy themselves on the endpoint, allowing organisations to deal with new and emerging cyber threats that do not have known or identifiable signatures.
Having a good endpoint protection solution in place can be a really useful tool as it may be able to detect and block some of the precursor malware that hackers will download to help execute ransomware attacks.
Another solution that can be used to detect hackers is through the use of a network monitoring tool. A network monitoring tool constantly monitors the network for performance and security issues and can help detect suspicious or malicious behaviour on the network. For example, some network monitoring solutions can be used to place greater scrutiny on privileged user accounts and closely monitor those accounts for suspicious behaviour.
Controls to mitigate a ransomware event
Even if an organisation has cyber security controls in place that are designed to prevent access to and detect the presence of hackers, there’s no guarantee that this will stop a ransomware incident from taking place. It is therefore imperative that the organisation has measures in place to mitigate a ransomware event should it occur.
One of the key mitigation measures here is to ensure that the organisation can recover from back-ups, with the storage of back-ups playing a vital role here. If an organisation has “online” back-ups that are stored on their live environment, hackers will often delete these or they may end up being corrupted as a result of the encryption process. It is therefore vital that the organisation has offline back-ups that are completely disconnected and inaccessible from the organisation’s live environment. Alternatively, the organisation should use a cloud back-up solution that is secured by multifactor authentication.
Regardless of the storage method used, the frequency of back-ups is also important. The more frequently back-ups are taken, the less data there is to lose. Ideally, organisations should be taking daily back-ups of all critical data at the very least. It’s also essential that the organisation tests a full recovery from back-up on at least an annual basis to check that the back-ups are actually working correctly.
Regaining access to data is one thing, but dealing with data theft is another. Organisations should ensure that they have a good data management policy in place, understanding the types of data that they hold, where it is stored and how it is protected. This will allow the organisation to better understand whether sensitive data has been accessed or exfiltrated. It’s also important that organisations only keep data for as long as is strictly necessary for business or regulatory purposes. Simply put, if the data is no longer there, there is no way for it be accessed or disclosed by a hacker during the course of a ransomware attack.
Another useful tool that can be used is a security information & event management system, otherwise known as a SIEM tool. One of the primary benefits of a SIEM tool is that it will aggregate all of an organisation’s logs in one place, which can then be searched and analysed. These detailed logs can be very useful in the event of a security breach as the logs can be consulted, allowing forensic investigators to better establish exactly what has happened.
Conclusion
Ransomware poses a major threat to almost all modern organisations. Nevertheless, there are measures that can be taken to help prevent, detect and mitigate a ransomware attack. Although the measures mentioned here only scratch the surface in terms of the controls that organisations can implement, they should provide a solid framework for building resilience to ransomware events. However, organisations should not solely rely on cyber security controls to protect themselves from ransomware attacks. Even if an organisation implements all of the security controls outlined above, there is no guarantee that they will stop a ransomware attack and shelter a business from the significant financial impact that can ensue from such incidents.
This is why cyber insurance should also form a key part of any prudent business owners’ cyber risk management program. A cyber insurance policy will typically provide cover for any ransom payment made, as well as the cost of any forensics, business resumption and legal advice incurred in relation to the event. The policy will also usually include some form of business interruption insurance, indemnifying the organisation for any income loss that they incur as a result of the attack, providing a valuable financial safety net should things go wrong.