Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Ransomware Detection 101: Six Best Practices To Prevent Propagation And Minimize Damage
Articles

Ransomware Detection 101: Six Best Practices To Prevent Propagation And Minimize Damage

Javvad MalikBy Javvad MalikDecember 12, 2017Updated:April 8, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Research shows that, on average, more than 4,000 ransomware attacks have occurred daily since January 1, 2016. Ransomware is a type of malware designed to either block access to a victim’s data, or threaten victims with publishing or deleting data, unless a ransom is paid.

While the threat vector has been around for years, it’s now becoming an epidemic because of its lower execution costs, high returns and minimal risk of discovery (compared to other forms of malware). Not to mention, thanks to Ransomware as a Service (RaaS) toolkits available on the dark web, it’s now easier than ever for virtually anyone – even individuals with minimal security knowledge – to extort money from companies and individuals.

Ransomware can have a huge impact on business operations within a very short period. For example, within one day, the WannaCry malware forced the National Health Service (NHS) in the U.K. to cancel thousands of operations and medical appointments due to ransom threats. Within hours, WannaCry infected more than 200,000 computers in over 150 countries. Other high-profile examples of detrimental ransomware campaigns that you’ve likely heard about include Petya, Locky, TeslaCrypt, CryptoLocker, CryptoWall and CryptoDefense.

Ransomware attackers don’t seem to have a preference on who they target; they’ll hit organizations of any size, of all types and across industries. According to a June 2016 survey from Osterman Research, nearly one in two participants indicated that their organization suffered at least one ransomware attack in the previous 12 months. And, ransomware criminals collected $209 million in the first three months of 2016 alone.

So, whether you’re a one-person shop or working for a Fortune 500 company, knowing how to detect ransomware as quickly as possible to isolate the infected systems and prevent the malware from spreading can minimize its impact. Here are six best practices to help you in this endeavor.

  1. Perform Asset Discovery and Vulnerability Scans – Because the goal of a ransomware attack is to steal your most valuable assets – data and applications – having an updated and reliable asset inventory is critical. This means knowing what’s on your network, and in your public and private clouds, at all times. Additionally, periodic vulnerability assessments are also important, so susceptible assets can be patched or reconfigured to address new vulnerabilities and exploits.
  1. Implement Intrusion Detection – While ransomware can be difficult to detect before it’s too late, it’s not impossible. If you know what to look for, and you have the right intrusion detection systems (IDS) in place (e.g., cloud-based IDS, network-based IDS and host-based IDS), you can act quickly to contain the damage and quarantine the infected systems. Examples of ransomware signature behaviors include: communicating with an IP or domain with a bad reputation (e.g., Command-and-Control or C2 Server); forcing group policy updates to fail; sending data via a covert channel; updating an audit policy; disabling firewall or antivirus software; or running unauthorized or unexpected network scans.
  1. Enable File Integrity Monitoring – Ransomware, like most malware, will kick off system processes and access system files that aren’t necessarily part of normal system operations. With File Integrity Monitoring (FIM) technology, you’ll be alerted any time a critical system file is accessed, modified or changed in any way. Once the encryption process begins, you may not be able to save that particular system; but, once alerted, you can prevent further spread of the ransomware attack by isolating the compromised system.
  1. Implement Security Automation and Orchestration – Rapid response is a critical success factor in any type of emergency, and a ransomware outbreak is no exception. The faster you can detect and respond to a potential ransomware attack, the more likely you can contain the damage. Unfortunately, cyber security defenses are often a patchwork of controls and consoles, making it difficult to respond quickly and in a coordinated way when attacks happen. But, recent innovations in security automation and orchestration have enhanced incident response by allowing disparate security tools to work together more effectively – all from a single management platform.
  1. Conduct Log Monitoring and Analysis (via SIEM) – The sheer volume and endless variety of event log data (e.g., system logs, application logs and access and activity logs) makes it essential to have an automated event correlation solution (e.g., SIEM) in place to parse through massive volumes of information and alert you when ransomware attacks happen.
  1. Integrate Security Monitoring with Updated Threat Intelligence – Ransomware attackers have an entire ecosystem at their disposal, and they’re constantly evolving their methods. Security researchers have studied their tradecraft and infrastructure in-depth, and continue to monitor their attributes, activities and innovations. These insights translate into fine-tuned security controls (e.g., event correlation rules) to detect the latest ransomware attacks and a better understanding of how an attacker’s tools, techniques and procedures work for an enhanced response. Additionally, leveraging continuous threat intelligence updates can help you stay ahead of emerging threats.

Today’s reality is that no matter how thick or high the wall, cybercriminals are finding ways in. And this prompts the question: Do you and your company have the tools and strategies in place to detect and respond to vulnerabilities and attacks quickly? Being able to immediately identify and act on threats is the most effective way to minimize risk. And, in today’s cybersecurity landscape, this is the best outcome we can hope for.

[su_box title=”About Javvad Malik” style=”noise” box_color=”#336588″][short_info id=’103990′ desc=”true” all=”false”][/su_box]

Javvad Malik
Javvad Malik
Javvad Malik is the Lead Security Awareness Advocate at KnowBe4 and is based in London. Malik is an IT security professional with over 20 years of experience as an IT security administrator, consultant, industry analyst and security advocate. He is also a multi-award winner and is currently a Guinness World Records holder for the most views of a cybersecurity lesson on YouTube in 24 hours.
  • Javvad Malik
    https://informationsecuritybuzz.com/author/javvad-malik/
    Exploring the Implications of DORA
  • Javvad Malik
    https://informationsecuritybuzz.com/author/javvad-malik/
    7 Real Security Predictions

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}