Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - The Ransomware Threat: Three Steps to Stay Safe
Study & Research

The Ransomware Threat: Three Steps to Stay Safe

ISBuzz TeamBy ISBuzz TeamNovember 11, 2017Updated:December 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

By Michael Fimin, CEO and co-founder of Netwrix, the provider of visibility platform for user behavior analysis and risk mitigation in hybrid environments

According to the Verizon 2017 Data Breach Investigations Report (DBIR), ransomware was the top malware variant in Crimeware category in 2016. That trend is likely to hold this year. For example, the headline-making WannaCry ransomware attack, which will probably be marked as one of the greatest cyber attacks of the year, hit over 150 countries and affected hundreds of thousands of organizations worldwide.

Although the WannaCry attack seems to be contained, its success has inspired other hackers to jump on the bandwagon and develop viruses with similar impact. The latest example is the new strain of ransomware dubbed “Petya,” which uses the same EternalBlue exploit that WannaCry used to infect its victims.

Although researchers and industry experts offer many best practices for defending against ransomware attacks, practice shows that there’s no silver bullet against this threat. IT pros are more than familiar with backups, whitelisting and patch management — but these measures cannot guarantee that one day you won’t lose any of your critical data. So what else can you do to minimize the chance of being the next victim of ransomware? 

  1. Seek support from senior management
  2. Develop a strategy to fight back

After getting executive buy-in, it’s time to start developing a coherent strategy that will enable your organization to quickly discover attacks in progress and limit their impact on your systems, operations and data. In order to withstand a ransomware attack, you need to focus on two key aspects:  realizing that you have been hit by ransomware ASAP, and finding out where the attack originates from so you can disconnect this “patient zero” from the network to stop the spread of the attack. This will give you time for further investigations and help minimize the damage.

It is important to keep in mind that the growing sophistication of attacks and new evasion techniques combine to make detection of ransomware extremely challenging. Instead of phishing, which can be detected at early stages, hackers now widely exploit vulnerabilities in critical systems to infect numerous computers on the same network in a short period of time.

Therefore, rather than relying solely on common threat detection techniques, you need to also take steps to minimize the damage that an undetected ransomware attack can do. Here are key best practices that will help:  

Limit user privileges — Continuous enforcement of the least-privilege principle will minimize ransomware’s ability to cripple your files via employees’ accounts. Therefore, grant access rights to modify files in strict accordance with employees’ duties.

Segment your network — Segregate your network into different zones with unique access to each. By logically regrouping network assets, resources and applications (e.g., separating accounting, sales and IT groups), and prohibiting internet access for areas that don’t need it, you will be able to limit the volume of resources that malware can access and remediate security issues more quickly.

Back up in read-only mode — Make regular backups of all your sensitive data and store copies offline in secure storage. Make sure that your backup process works automatically under a separate account, and that no one (including system administrators) has any right to modify or delete a backup copy, since some ransomware variants are smart enough to encrypt every backup they are able to locate.

Never pay the ransom — Although you may be tempted to pay the ransom, it’s never a good idea. First, there’s no guarantee that you’ll get your data back; in some cases, decryption keys are neither stored nor sent anywhere. Second, once you’ve been identified as someone who will pay, criminals will keep attacking you and demanding more ransom. Instead, check the name of the ransomware, as it may be a well-known virus that has been already cracked by IT professionals. If not, look for other recovery tools or restore from your own backups.

  1. Gain visibility into user activity to detect an attack in progress

To substantially reduce the damage a ransomware attack can do, keep a close watch on what’s going on across your entire network. There are threat patterns that indicate a possible ransomware attack in progress — such as excessive file modifications in a short period of time, and a spike in failed access or modification attempts above your usual baseline. Deep visibility into user activity will enable you to detect anomalous behavior like this, block the attack and start investigating before hackers inflict serious harm. It will also help you identify affected files more quickly to optimize the data recovery process.

To learn more about how to reduce the damage from crypto-ransomware, please visit: https://www.netwrix.com/encryption_ransomware_threat.html

[su_box title=”About Michael Fimin” style=”noise” box_color=”#336588″][short_info id=’60706′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}