Ransomware has been weaponized by cyber extortionists and rogue governments, representing a potentially existential risk to businesses that fall victim. The latest variations of ransomware target everything, including backup, making even selective restoration a long and expensive exercise. New strains of ransomware like Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), DopplePaymer, Conti and Egregor have made the headlines, displacing Locky, Spora, and Petya in notoriety, elaborateness, and destructiveness.
Most ransomware breaches come from innocuous-seeming emails that include malicious hyperlinks or file attachments, and many are "zero-day" variants that can escape detection by traditional signature-matching antivirus tools. While user education and up-front detection are important to protect your network against ransomware attacks, best practices dictate that you assume some attacks will inevitably get through and that you put in place a solid backup mechanism that allows you to recover rapidly with little if any damage.
Progent's ProSight Ransomware Preparedness Assessment is a low-cost service built around an online discussion with a Progent cybersecurity expert experienced in ransomware defense and repair. In the course of this assessment Progent will collaborate with your Beverly Hills IT management staff to collect critical information about your security configuration and backup environment. Progent will use this information to create a Basic Security and Best Practices Assessment documenting how to follow best practices for configuring and managing your security and backup systems to block or clean up after a ransomware attack.
Progent's Basic Security and Best Practices Report focuses on vital areas related to crypto-ransomware prevention and restoration recovery. The review addresses:
Security
About Ransomware
Ransomware is a type of malware that encrypts or deletes files so they are unusable or are made publicly available. Ransomware sometimes locks the victim's computer. To avoid the damage, the victim is required to send a specified amount of money (the ransom), typically in the form of a crypto currency like Bitcoin, within a brief time window. It is not guaranteed that paying the ransom will restore the lost files or avoid its publication. Files can be altered or erased across a network depending on the target's write permissions, and you cannot reverse engineer the strong encryption algorithms used on the hostage files. A common ransomware delivery package is spoofed email, whereby the user is tricked into interacting with by means of a social engineering technique called spear phishing. This makes the email message to appear to come from a trusted sender. Another common vulnerability is an improperly protected RDP port.
CryptoLocker ushered in the new age of ransomware in 2013, and the monetary losses attributed to by the many versions of ransomware is estimated at billions of dollars annually, roughly doubling every other year. Notorious examples are Locky, and NotPetya. Recent high-profile variants like Ryuk, DoppelPaymer and CryptoWall are more sophisticated and have caused more havoc than earlier versions. Even if your backup procedures permit you to recover your ransomed files, you can still be threatened by so-called exfiltration, where stolen documents are exposed to the public (known as "doxxing"). Because additional versions of ransomware are launched every day, there is no certainty that conventional signature-matching anti-virus tools will detect the latest malware. If threat does show up in an email, it is important that your end users have been taught to be aware of phishing techniques. Your last line of defense is a solid scheme for performing and keeping offsite backups and the deployment of dependable restoration tools.
Contact Progent About the ProSight Ransomware Preparedness Assessment in Beverly Hills
For pricing information and to learn more about how Progent's ProSight Ransomware Preparedness Assessment can enhance your defense against ransomware in Beverly Hills, call Progent at