Ransomware has been widely adopted by the major cyber-crime organizations and bad-actor states, posing a possibly existential risk to companies that are successfully attacked. Current strains of ransomware go after all vulnerable resources, including backup, making even partial recovery a complex and expensive process. Novel versions of crypto-ransomware like Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), DopplePaymer, LockBit and Egregor have made the headlines, displacing WannaCry, Cerber, and Petya in prominence, elaborateness, and destructive impact.
Most ransomware breaches are the result of innocuous-seeming emails that include dangerous hyperlinks or attachments, and a high percentage are "zero-day" attacks that elude the defenses of legacy signature-matching antivirus filters. While user training and frontline detection are critical to defend your network against ransomware, best practices demand that you assume some malware will eventually get through and that you put in place a solid backup solution that permits you to restore files and services rapidly with little if any damage.
Progent's ProSight Ransomware Vulnerability Report is a low-cost service built around a remote interview with a Progent cybersecurity expert skilled in ransomware protection and repair. In the course of this assessment Progent will cooperate directly with your Palo Alto IT managers to gather critical information concerning your cybersecurity configuration and backup processes. Progent will use this data to create a Basic Security and Best Practices Report detailing how to follow leading practices for implementing and administering your cybersecurity and backup systems to block or clean up after a ransomware assault.
Progent's Basic Security and Best Practices Report focuses on key areas associated with ransomware defense and restoration recovery. The report covers:
Cybersecurity
About Ransomware
Ransomware is a form of malware that encrypts or steals a victim's files so they cannot be used or are publicized. Ransomware often locks the target's computer. To prevent the carnage, the target is asked to send a certain amount of money (the ransom), typically via a crypto currency like Bitcoin, within a short period of time. It is not guaranteed that paying the extortion price will restore the lost files or prevent its exposure to the public. Files can be encrypted or erased across a network based on the target's write permissions, and you cannot reverse engineer the military-grade encryption algorithms used on the compromised files. A typical ransomware delivery package is tainted email, whereby the target is tricked into interacting with by means of a social engineering exploit known as spear phishing. This makes the email to appear to come from a trusted source. Another popular attack vector is a poorly secured RDP port.
The ransomware variant CryptoLocker ushered in the modern era of crypto-ransomware in 2013, and the damage attributed to by different versions of ransomware is said to be billions of dollars annually, roughly doubling every other year. Notorious attacks are Locky, and NotPetya. Recent headline variants like Ryuk, Sodinokibi and Cerber are more complex and have wreaked more havoc than older strains. Even if your backup/recovery procedures allow you to restore your encrypted files, you can still be threatened by so-called exfiltration, where stolen documents are exposed to the public. Because additional variants of ransomware are launched every day, there is no guarantee that traditional signature-based anti-virus tools will block a new malware. If threat does show up in an email, it is important that your users have learned to be aware of phishing tricks. Your last line of protection is a sound scheme for performing and retaining remote backups and the use of reliable restoration platforms.
Ask Progent About the ProSight Crypto-Ransomware Susceptibility Consultation in Palo Alto
For pricing information and to learn more about how Progent's ProSight Crypto-Ransomware Readiness Checkup can bolster your protection against crypto-ransomware in Palo Alto, call Progent at