Ransomware has been weaponized by cyber extortionists and malicious states, representing a potentially lethal threat to businesses that are victimized. Modern versions of ransomware target everything, including backup, making even partial restoration a complex and expensive process. New versions of crypto-ransomware such as Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), Phobos, Snatch and Nephilim have made the headlines, replacing WannaCry, Cerber, and NotPetya in prominence, sophistication, and destructiveness.
90% of crypto-ransomware breaches come from innocent-looking emails with dangerous hyperlinks or attachments, and a high percentage are "zero-day" attacks that can escape detection by legacy signature-based antivirus filters. While user training and frontline detection are critical to defend your network against ransomware attacks, best practices dictate that you assume some malware will eventually succeed and that you implement a strong backup mechanism that enables you to recover quickly with little if any damage.
Progent's ProSight Ransomware Vulnerability Assessment is an ultra-affordable service built around an online interview with a Progent security consultant skilled in ransomware protection and repair. During this assessment Progent will cooperate with your St. Paul IT management staff to collect critical information about your security profile and backup processes. Progent will utilize this information to generate a Basic Security and Best Practices Assessment documenting how to adhere to best practices for configuring and administering your security and backup solution to block or recover from a ransomware attack.
Progent's Basic Security and Best Practices Report highlights key areas associated with crypto-ransomware defense and restoration recovery. The report addresses:
Security
About Ransomware
Ransomware is a type of malicious software that encrypts or steals files so they are unusable or are publicized. Ransomware sometimes locks the victim's computer. To avoid the damage, the victim is required to pay a certain amount of money, typically via a crypto currency such as Bitcoin, within a brief period of time. It is not guaranteed that delivering the ransom will recover the damaged data or avoid its publication. Files can be encrypted or deleted across a network depending on the target's write permissions, and you cannot break the strong encryption algorithms used on the hostage files. A typical ransomware attack vector is tainted email, in which the user is tricked into interacting with by means of a social engineering technique known as spear phishing. This causes the email to look as though it came from a trusted sender. Another common vulnerability is an improperly protected RDP port.
CryptoLocker ushered in the modern era of crypto-ransomware in 2013, and the monetary losses attributed to by the many strains of ransomware is said to be billions of dollars per year, roughly doubling every two years. Notorious attacks are WannaCry, and NotPetya. Current high-profile variants like Ryuk, Maze and Cerber are more elaborate and have caused more damage than earlier strains. Even if your backup/recovery procedures permit you to recover your ransomed files, you can still be threatened by exfiltration, where ransomed data are exposed to the public (known as "doxxing"). Because new variants of ransomware are launched every day, there is no certainty that traditional signature-based anti-virus tools will block the latest malware. If threat does show up in an email, it is critical that your users have been taught to be aware of social engineering tricks. Your last line of protection is a solid scheme for performing and retaining offsite backups plus the deployment of reliable restoration tools.
Contact Progent About the ProSight Ransomware Readiness Checkup in St. Paul
For pricing information and to find out more about how Progent's ProSight Crypto-Ransomware Susceptibility Testing can bolster your defense against crypto-ransomware in St. Paul, phone Progent at