Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What To Do When Ransomware Strikes
Articles

What To Do When Ransomware Strikes

ISBuzz TeamBy ISBuzz TeamAugust 21, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

An employee walks over to your office, fingers fidgeting and brow sweating. They tell you that there’s something you have to see. Concerned, you quickly rush to their desk. On their computer screen is a single message that reads:

“We have gained access to your computer and your files have been encrypted. If you want your data back, you’ll need to pay us.”

Your company has been hit with ransomware, the malicious digital ransom note that is every exec’s nightmare. Unfortunately, this is becoming more common with 86 percent of SMEs having been recently victimized by ransomware in 2019, and 56 percent of all malware attacks being caused by ransomware. Ransomware is proving to be the single biggest destructive force for business data, surpassing even hard drive failures as the leading cause of data loss, and is costing organizations up to $17 million. 

Ransomware has evolved to take advantage of the many developments in technology since the first attack occurred in 1989 with floppy desks distributed across organizations purporting to raise money to fund AIDS research. At the time, the users were asked to pay $189 to get their files back, a mere drop in the ocean compared to some of the amounts demanded in modern day.

Since then, ransomware has grown significantly due to the advent of multiple facilitators. Encrypted files are becoming more difficult to decrypt due to sophisticated RSA encryption coupled with increasing key sizes, and ransomware is becoming more accessible with kits being sold on the dark web for as little as $10. Joined with the fact that cryptocurrency has made payments virtually untraceable and irreversible, recovery from ransomware has become more difficult, causing the cost to business to rise to more than $75 billion per year. 

How to Defeat Ransomware

So, what do you do if your company falls victim to one of these attacks? The first thing to do would be to isolate any infected computers and get them off the network ensuring the malware doesn’t continue to spread. Next you should begin to assess the damage by determining the origins of the infected file and locating others that were affected.

Okay, you can breathe now that you’ve successful stopped the malware from spreading any further throughout the network. Once this has been secured, your thoughts should turn to the backup strategy you have in place. If you have implemented either a backup or sync solution (see the next section for a warning about using sync) to get your data offsite, you are more prepared than most. However, this level of preparedness rarely is tested against the exact scenario it’s needed for. 

When it comes time to restore the company’s data after a ransomware attack, there are three weak points that need to be immediately considered: 

  1.     The security breach has affected the backups

Many people confuse cloud sync services with backup. If you are utilizing a sync solution, and the syncing process is happening during the time of the attack, the newly infected files are going to automatically sync to the cloud, therefore infecting your entire backup set.

Luckily, this can be avoided by using backup software that offers multiple versions of your files. This type of backup software saves the original file as it is the first time it is backed up, and then creates a new backup file with every change made – meaning that if a file was to become encrypted by ransomware, the simple solution would be to restore a prior version of the file that existed before the attack.  

  1.     Restoring data will be burdensome and time-consuming

If you have a large dataset, which most companies do, then the process of restoring data stored on the cloud can be a long and tedious one, taking away valuable time that could be spent securing your company’s next client.

The way around this is to employ snapshots. Snapshots allow you to restore all of your data from a specific point in time, which is crucial when tackling the effects of ransomware. Some backup solutions providers offer the ability to take a snapshot of your data and archive that snapshot in the cloud. Others even go as far as to ship USB drives to their customers containing the archived data. 

  1.     Not all of the critical data was backed up

The second leading cause of data loss is… human error! Making mistakes is a natural part of the human experience, however some of these mistakes could cause significant impacts on your company. The mistakes can be from forgetting to save something, to accidentally leaving a laptop on a plane. Some data backup procedures require employees to save files to a specific file in order for it to be correctly backed up; this can lead to an easily made error of simply forgetting.

The most effective backup solutions are the ones that are easiest for the end users and require the least amount of human intervention. It is best practice to invest in a backup process that automatically backs up all user-generated data by default. It should always be viewed as the responsibility of the backup solutions provider to protect business data, regardless of where the end user saves it.

As ransomware is becoming more common and cybercriminals are constantly developing new ways to break through security measures, the necessity to ensure that your company has a solid backup solution is imperative to ensuring that business can quickly get back to normal following an attack.

Making sure that your backup process addresses the three weak points mentioned above can be the difference between suffering a ransomware attack or avoiding an attack all together. It’s essential to make sure that your data is backed up and unreachable by ransomware infection, which will ensure that your downtime and data loss is minimal, or none if you ever suffer an attack. 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}