Ransomware has been weaponized by cyber extortionists and rogue states, posing a potentially lethal risk to businesses that are breached. The latest versions of ransomware go after everything, including online backup, making even partial restoration a long and expensive exercise. New strains of ransomware such as Ryuk, Maze, Sodinokibi, Netwalker, Phobos, Snatch and Nephilim have emerged, displacing WannaCry, Spora, and Petya in prominence, elaborateness, and destructiveness.
Most crypto-ransomware infections come from innocent-seeming emails that have dangerous links or attachments, and a high percentage are "zero-day" variants that can escape the defenses of legacy signature-based antivirus tools. Although user education and up-front identification are important to protect against ransomware, best practices dictate that you assume some malware will inevitably succeed and that you prepare a strong backup mechanism that permits you to recover rapidly with little if any losses.
Progent's ProSight Ransomware Preparedness Assessment is a low-cost service built around a remote interview with a Progent cybersecurity consultant skilled in ransomware protection and recovery. In the course of this assessment Progent will collaborate with your Corpus Christi IT managers to collect pertinent information about your security posture and backup processes. Progent will use this data to generate a Basic Security and Best Practices Assessment documenting how to apply best practices for implementing and administering your cybersecurity and backup systems to prevent or clean up after a ransomware assault.
Progent's Basic Security and Best Practices Assessment focuses on key areas related to crypto-ransomware prevention and restoration recovery. The report covers:
Security
About Ransomware
Ransomware is a form of malware that encrypts or steals files so they are unusable or are made publicly available. Ransomware sometimes locks the target's computer. To avoid the carnage, the target is required to pay a specified amount of money (the ransom), usually in the form of a crypto currency such as Bitcoin, within a brief period of time. There is no guarantee that paying the extortion price will restore the damaged files or avoid its exposure to the public. Files can be encrypted or deleted throughout a network based on the target's write permissions, and you cannot reverse engineer the strong encryption technologies used on the compromised files. A typical ransomware attack vector is spoofed email, in which the user is tricked into responding to by a social engineering technique called spear phishing. This makes the email message to look as though it came from a familiar source. Another popular vulnerability is an improperly protected RDP port.
CryptoLocker opened the modern era of crypto-ransomware in 2013, and the damage caused by different versions of ransomware is said to be billions of dollars annually, more than doubling every two years. Notorious attacks are Locky, and Petya. Current headline threats like Ryuk, DoppelPaymer and Cerber are more elaborate and have caused more damage than older strains. Even if your backup/recovery processes allow you to recover your ransomed data, you can still be threatened by so-called exfiltration, where ransomed documents are exposed to the public (known as "doxxing"). Because additional versions of ransomware are launched every day, there is no certainty that conventional signature-matching anti-virus filters will detect a new attack. If threat does appear in an email, it is critical that your users have been taught to be aware of phishing tricks. Your ultimate defense is a sound process for scheduling and keeping remote backups and the use of dependable recovery tools.
Contact Progent About the ProSight Crypto-Ransomware Susceptibility Evaluation in Corpus Christi
For pricing details and to learn more about how Progent's ProSight Ransomware Preparedness Audit can bolster your protection against ransomware in Corpus Christi, call Progent at