Ransomware has been weaponized by the major cyber-crime organizations and bad-actor governments, posing a potentially lethal threat to businesses that are successfully attacked. Modern versions of crypto-ransomware target everything, including online backup, making even partial restoration a challenging and expensive exercise. New variations of ransomware like Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), Phobos, Snatch and Egregor have made the headlines, replacing WannaCry, TeslaCrypt, and NotPetya in notoriety, sophistication, and destructive impact.
Most ransomware penetrations come from innocuous-looking emails that have dangerous hyperlinks or file attachments, and many are "zero-day" strains that elude detection by traditional signature-based antivirus (AV) filters. While user training and frontline identification are critical to defend your network against ransomware attacks, leading practices dictate that you assume some attacks will eventually succeed and that you prepare a solid backup solution that permits you to recover rapidly with little if any damage.
Progent's ProSight Ransomware Preparedness Assessment is an ultra-affordable service built around an online discussion with a Progent cybersecurity expert experienced in ransomware defense and repair. During this interview Progent will cooperate directly with your Portland IT management staff to collect critical information about your cybersecurity configuration and backup environment. Progent will use this data to generate a Basic Security and Best Practices Assessment detailing how to apply leading practices for configuring and administering your security and backup solution to prevent or recover from a crypto-ransomware attack.
Progent's Basic Security and Best Practices Report focuses on key areas associated with ransomware defense and restoration recovery. The review covers:
Security
About Ransomware
Ransomware is a variety of malicious software that encrypts or deletes a victim's files so they are unusable or are made publicly available. Ransomware sometimes locks the victim's computer. To avoid the damage, the victim is asked to send a specified amount of money (the ransom), typically in the form of a crypto currency such as Bitcoin, within a short time window. It is not guaranteed that delivering the extortion price will restore the damaged files or avoid its exposure to the public. Files can be altered or deleted across a network based on the target's write permissions, and you cannot break the military-grade encryption technologies used on the hostage files. A typical ransomware attack vector is booby-trapped email, in which the user is tricked into responding to by means of a social engineering technique known as spear phishing. This makes the email message to appear to come from a trusted source. Another popular vulnerability is a poorly protected Remote Desktop Protocol port.
CryptoLocker ushered in the modern era of crypto-ransomware in 2013, and the monetary losses attributed to by the many versions of ransomware is said to be billions of dollars per year, more than doubling every two years. Notorious examples are Locky, and Petya. Current headline threats like Ryuk, Maze and CryptoWall are more complex and have wreaked more havoc than earlier strains. Even if your backup procedures allow you to restore your encrypted files, you can still be threatened by exfiltration, where ransomed documents are exposed to the public (known as "doxxing"). Because new versions of ransomware are launched daily, there is no certainty that conventional signature-matching anti-virus filters will block the latest malware. If an attack does appear in an email, it is important that your users have been taught to be aware of social engineering techniques. Your ultimate defense is a sound process for performing and retaining offsite backups and the use of dependable recovery tools.
Contact Progent About the ProSight Ransomware Preparedness Report in Portland
For pricing information and to learn more about how Progent's ProSight Crypto-Ransomware Vulnerability Audit can bolster your protection against ransomware in Portland, phone Progent at