Ransomware has been widely adopted by cyber extortionists and malicious governments, representing a potentially existential threat to companies that are breached. Current versions of crypto-ransomware target everything, including online backup, making even partial restoration a challenging and costly process. New variations of ransomware such as Ryuk, Maze, Sodinokibi, Mailto (aka Netwalker), Phobos, LockBit and Egregor have made the headlines, displacing Locky, Cerber, and NotPetya in notoriety, elaborateness, and destructiveness.
90% of crypto-ransomware infections are the result of innocent-looking emails that have malicious hyperlinks or attachments, and many are so-called "zero-day" strains that elude detection by traditional signature-matching antivirus tools. While user training and frontline identification are critical to protect against ransomware attacks, leading practices demand that you expect that some attacks will eventually succeed and that you put in place a strong backup solution that enables you to repair the damage rapidly with little if any losses.
Progent's ProSight Ransomware Preparedness Checkup is an ultra-affordable service built around an online interview with a Progent security consultant experienced in ransomware defense and recovery. In the course of this assessment Progent will collaborate directly with you to collect pertinent information concerning your security posture and backup processes. Progent will use this data to generate a Basic Security and Best Practices Report detailing how to follow best practices for implementing and administering your security and backup systems to block or clean up after a ransomware assault.
Progent's Basic Security and Best Practices Report focuses on vital issues associated with crypto-ransomware defense and restoration recovery. The report addresses:
Security
About Ransomware
Ransomware is a form of malware that encrypts or deletes files so they are unusable or are publicized. Crypto-ransomware sometimes locks the target's computer. To prevent the carnage, the victim is required to send a certain amount of money (the ransom), usually via a crypto currency like Bitcoin, within a brief period of time. There is no guarantee that delivering the ransom will recover the damaged data or avoid its exposure to the public. Files can be encrypted or deleted throughout a network depending on the target's write permissions, and you cannot solve the military-grade encryption algorithms used on the compromised files. A common ransomware delivery package is spoofed email, in which the victim is lured into interacting with by means of a social engineering exploit known as spear phishing. This makes the email to look as though it came from a familiar sender. Another popular attack vector is a poorly secured RDP port.
The ransomware variant CryptoLocker opened the new age of ransomware in 2013, and the damage attributed to by different strains of ransomware is estimated at billions of dollars per year, more than doubling every other year. Famous attacks include WannaCry, and NotPetya. Recent headline variants like Ryuk, DoppelPaymer and Cerber are more sophisticated and have wreaked more havoc than older versions. Even if your backup/recovery procedures allow you to restore your encrypted files, you can still be threatened by so-called exfiltration, where ransomed documents are made public. Because new versions of ransomware are launched every day, there is no guarantee that traditional signature-based anti-virus tools will detect a new attack. If threat does appear in an email, it is important that your users have been taught to be aware of phishing tricks. Your last line of protection is a solid scheme for scheduling and retaining offsite backups plus the deployment of reliable restoration tools.
Ask Progent About the ProSight Ransomware Vulnerability Assessment
For pricing information and to learn more about how Progent's ProSight Ransomware Preparedness Checkup can enhance your protection against crypto-ransomware, call Progent at