Ransomware has become the weapon of choice for cybercriminals and rogue governments, representing a potentially existential risk to businesses that are victimized. Current versions of ransomware target all vulnerable resources, including online backup, making even partial recovery a long and expensive process. New strains of crypto-ransomware like Ryuk, Maze, Sodinokibi, Netwalker, Phobos, Conti and Egregor have made the headlines, displacing Locky, Spora, and NotPetya in notoriety, elaborateness, and destructive impact.
Most ransomware infections are the result of innocent-looking emails that have malicious hyperlinks or file attachments, and many are so-called "zero-day" variants that elude the defenses of traditional signature-based antivirus (AV) filters. Although user education and up-front detection are critical to defend your network against ransomware, best practices demand that you take for granted some malware will eventually get through and that you implement a strong backup solution that permits you to recover rapidly with minimal losses.
Progent's ProSight Ransomware Vulnerability Report is a low-cost service built around a remote discussion with a Progent cybersecurity consultant skilled in ransomware protection and repair. In the course of this assessment Progent will work with your Chesapeake IT managers to collect critical information about your security posture and backup processes. Progent will use this information to produce a Basic Security and Best Practices Assessment documenting how to adhere to leading practices for implementing and administering your cybersecurity and backup systems to block or recover from a crypto-ransomware attack.
Progent's Basic Security and Best Practices Report focuses on key areas associated with crypto-ransomware defense and restoration recovery. The review addresses:
Security
About Ransomware
Ransomware is a form of malicious software that encrypts or steals a victim's files so they are unusable or are publicized. Crypto-ransomware sometimes locks the victim's computer. To avoid the carnage, the victim is required to send a certain ransom, usually in the form of a crypto currency such as Bitcoin, within a brief period of time. There is no guarantee that delivering the extortion price will recover the lost data or prevent its publication. Files can be altered or erased throughout a network depending on the target's write permissions, and you cannot solve the military-grade encryption technologies used on the hostage files. A common ransomware delivery package is tainted email, whereby the victim is tricked into responding to by a social engineering exploit known as spear phishing. This causes the email to look as though it came from a familiar sender. Another popular attack vector is an improperly protected Remote Desktop Protocol port.
The ransomware variant CryptoLocker opened the modern era of crypto-ransomware in 2013, and the monetary losses caused by different strains of ransomware is said to be billions of dollars per year, more than doubling every two years. Famous attacks include Locky, and NotPetya. Recent high-profile threats like Ryuk, DoppelPaymer and CryptoWall are more sophisticated and have wreaked more havoc than earlier strains. Even if your backup/recovery procedures permit your business to recover your encrypted files, you can still be hurt by so-called exfiltration, where ransomed data are made public (known as "doxxing"). Because new versions of ransomware are launched daily, there is no certainty that conventional signature-matching anti-virus filters will block a new attack. If an attack does appear in an email, it is important that your end users have been taught to be aware of phishing tricks. Your ultimate defense is a solid scheme for performing and retaining offsite backups plus the use of dependable restoration platforms.
Contact Progent About the ProSight Crypto-Ransomware Preparedness Consultation in Chesapeake
For pricing information and to learn more about how Progent's ProSight Crypto-Ransomware Susceptibility Report can enhance your defense against crypto-ransomware in Chesapeake, call Progent at