Ransomware has been weaponized by cyber extortionists and rogue governments, representing a possibly lethal threat to businesses that fall victim. The latest strains of crypto-ransomware go after everything, including backup, making even selective recovery a complex and expensive exercise. Novel strains of crypto-ransomware such as Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), Phobos, Snatch and Nephilim have made the headlines, replacing WannaCry, Cerber, and CryptoWall in prominence, elaborateness, and destructiveness.
90% of ransomware breaches are the result of innocent-looking emails with malicious hyperlinks or attachments, and a high percentage are so-called "zero-day" strains that elude the defenses of legacy signature-based antivirus (AV) filters. While user training and frontline detection are critical to protect against ransomware, leading practices demand that you expect that some attacks will eventually succeed and that you prepare a solid backup solution that enables you to repair the damage rapidly with minimal losses.
Progent's ProSight Ransomware Vulnerability Report is an ultra-affordable service built around an online interview with a Progent cybersecurity consultant experienced in ransomware defense and recovery. During this interview Progent will cooperate directly with your New Haven IT management staff to collect critical information concerning your security setup and backup environment. Progent will utilize this information to create a Basic Security and Best Practices Assessment documenting how to adhere to leading practices for configuring and administering your security and backup solution to block or recover from a crypto-ransomware assault.
Progent's Basic Security and Best Practices Assessment highlights key areas related to ransomware prevention and restoration recovery. The review covers:
Cybersecurity
About Ransomware
Ransomware is a form of malicious software that encrypts or deletes files so they cannot be used or are made publicly available. Crypto-ransomware sometimes locks the target's computer. To prevent the carnage, the victim is required to pay a specified ransom, usually in the form of a crypto currency such as Bitcoin, within a brief period of time. It is never certain that delivering the extortion price will recover the lost files or avoid its publication. Files can be encrypted or deleted across a network depending on the target's write permissions, and you cannot break the military-grade encryption technologies used on the hostage files. A common ransomware delivery package is booby-trapped email, in which the target is lured into responding to by a social engineering exploit called spear phishing. This causes the email to look as though it came from a trusted sender. Another common vulnerability is a poorly secured RDP port.
CryptoLocker opened the modern era of crypto-ransomware in 2013, and the damage caused by the many versions of ransomware is estimated at billions of dollars annually, roughly doubling every other year. Notorious examples are Locky, and Petya. Current high-profile variants like Ryuk, Maze and CryptoWall are more complex and have wreaked more damage than earlier versions. Even if your backup processes enable your business to recover your ransomed files, you can still be hurt by so-called exfiltration, where ransomed documents are exposed to the public (known as "doxxing"). Because new variants of ransomware crop up daily, there is no guarantee that traditional signature-matching anti-virus filters will detect the latest malware. If an attack does appear in an email, it is important that your users have learned to identify social engineering techniques. Your ultimate protection is a sound process for performing and keeping remote backups and the deployment of reliable restoration platforms.
Contact Progent About the ProSight Ransomware Readiness Assessment in New Haven
For pricing information and to find out more about how Progent's ProSight Ransomware Preparedness Audit can bolster your defense against ransomware in New Haven, phone Progent at