Purchase our Anti-Phishing Bundle


Ransomware

Have you ever been hit by Ransomware? Do you even know what Ransomware is? Regardless of whether you answered yes or no, this is good info to have.

First, let's start with what Ransomware is. Regardless of how it happens, the methodology is the same: your data (whatever it is) is encrypted and then held for ransom. You are told to pay the ransom, typically in bitcoin, to obtain the decryption key. Quite often, the ransomware has no idea how much was encrypted, so it wouldn't know if it was one machine or an entire network. Although ransomware technology is changing, more of that may come to light. Once the ransom is paid, a smart ransomer will hold off before accessing the bitcoin.

Unfortunately, it's not that easy, though. In the criminal underworld, there is a slight bit of honor among thieves. In other words, if someone is going to hold your data ransom and never give you the decryption keys, there is no real reason to pay the ransom, right? As it is, about 70% of the time you receive decryption keys, meaning that 30% of the time the criminals either don't give you the keys or give you the wrong ones. Thus, there is a bit of a gamble if you choose to pay.

Currently, the FBI recommends that you contact them to clarify a few things. First, you need to let them know what is going on. Second, the FBI may already have decryption codes from a prior case. Lastly, the FBI tracks these things, so they are likely to let you know if you pay a ransom, you will get good results.

So what some companies are doing is, as part of an incident response (IR) plan, having $5K in bitcoin ready to go and authorization to use it from the IR manager. The reasoning is that if a ransom of $300 will release much more valuable data, it's better to pay the ransom than to manually recover the data, which would cost more in time and effort. To us, this seems like a good idea, as it reduces the red tape at the last minute. Of course, we aren't condoning paying a ransom, but if $300 is all it takes to make a $100K problem go away, it seems like good business sense.

However, one thing you absolutely must consider before paying a ransom...and that is who exactly you are paying.  Should the ransom be associated with a terrorist organization, then "technically" you would be supporting a terrorist organization, which can result in serious company and individual issues, including incarceration.

So, who makes a good target? Well, those forced to remain on legacy operating systems, for one. Or those with slow update cycles due to mission-critical dependencies, where updating or patching could pose a risk. Hospitals are a prime target because if they update too quickly, they may cause an issue that could put a life in danger. So the hospital has an aversion to staying on the cutting edge of updates. On the flip side, if the hospital updates too slowly, they become more of a target, and maybe some complacency naturally develops among the IT staff.

Ransomware will certainly evolve as defenses and user education increase. Having said that, the evolution is fast. See below for a sample evolution chart of ransomware.

Read our one-pagers on Enterprise Risk Management, Disaster Recovery/Business Continuity, and Business Impact Assessments.


Contact us by filling out this form - Contact Us



Purchase our Anti-Phishing Bundle


The above graphic clearly shows a rapid increase in Ransomware, as well as its evolution per year to increase its effectiveness. Even though this graphic only shows 2005-2016, Ransomware has been around since 1989; it just wasn't popular or newsworthy then. Ransomware is even offered "as a service" by some of the more advanced cybercriminal organizations, as well as by easier-to-deploy Ransomware agents.

As time goes on, you will see more advanced forms of Ransomware. Possibly ransomware transmitted via Bluetooth, ransoming a phone, iDevice, or other IoT device such as a TV or refrigerator. Imagine a BT-capable ransomware that can interface with your car and remove your ability to drive it. Don't rule out WiFi and anything that transmits through it; WiFi makes a natural conduit for connectivity and dangerous malware.

What you can do to help yourself, within budget, is versioning, read-only snapshots of critical servers, and secure backups. The more money you spend up front to prevent the problem, the more you save on the backend. This is primarily because the estimated cost of company-wide downtime is $8,600 per hour for a $ 0-50MM-sized company and $700K per hour for a company over $1BB per year.

Arrakis can help you avoid Ransomware and act as a trusted agent or advisor during your difficult time dealing with it. If you are in trouble, give us a call.


Purchase our Anti-Phishing Bundle


We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us