Ransomware: the rapidly evolving threat

17 Nov

By: Ian Kennedy-Compston

News, info & events

Over the past few years, ransomware has become a more prevalent threat to organisations trying to accommodate the need for remote working. As companies have gone increasingly remote and mobile, cybercriminals have sought to maximise their profits by exploiting the vulnerabilities that come with a rapid expansion of an organisation’s network perimeter without the focus of maintaining cyber resilience.

During 2021, ransomware has seen a significant uptrend – with a 151 percent increase for the first six months. The FBI has warned that there are over 100 different ransomware strains currently circulating around the world.

The number of ransomware attacks is huge and will continue to increase as the trend to online, digital business and remote working continues to grow.

Turning a blind eye and pretending that it’s not going to happen to you is false security. The cost of recovering from a ransomware attack can include the cost of paying the ransom, the cost of removing the ransomware from your systems, the cost of lost business while your systems were down and the cost of lost business due to reputational damage.

So what can be done?

Here’s our 5 point plan based around a multi-layered approach:

  1. Start with assessing your current IT environment –  you need to establish the ‘baseline’ of your IT infrastructure to assess your current levels of cyber resilience. 
  2. Put in place effective protection that defends your infrastructure against threats proactively. Ransomware needs to be prevented from entering your IT systems before it does damage. We offer leading edge cybersecurity tools which will help mitigate against even the newer types of ransomware.
  3. Ensure you have immutable data backups. We have solutions for both encrypted, cloud backups and private cloud appliances, so if ransomware does enter your IT systems, you have a non-infested copy of your data you can recover back to. 
  4. Once the above systems are in place, you need to continue to ensure you test your environment in a systematic way. Regular, automated penetration testing helps IT resilience to be maintained as your environment and threat landscape changes. 
  5. Further protection can be provided by continuous, effective cyber security behaviour training for employees. There are several tools for this but it is best to choose an accredited, recognised system that keeps pace with the constantly changing environment.

Together, the above actions will improve your cyber resilience and minimise the chances of your organisation being breached with a ransomware attack.

EnterpriseRed has a number of capabilities that can assist you and your organisation. Talk to us today to show you how.

Sidebar: