Skip to main content

Guide to Ransomware Prevention

Page 1

A G U I D E F O R LO C A L G OV E R N M E N T

RANSOMWARE P R E V E N T I O N


2 | Ransomware Prevention: A Guide for Local Government

Part 1:

Ransomware: A Primer What is ransomware? Ransomware is a type of malicious software used by cybercriminals that encrypts digital information, making it inaccessible to the rightful owners and authorized users. Encryption is typically used to safeguard sensitive information as it converts data into a code that requires a “key,” a piece of software that can convert the encrypted code back to its original form. Ransomware uses encryption for nefarious purposes, rendering files unreadable by both humans and computers and rendering applications and equipment unusable until a ransom is paid. Any computer file, from a JPEG photo or MS Word document to the software that runs the office copier or the internet-based phone system, can be encrypted by ransomware, completely disrupting normal operations. While ransomware has been around since the start of the internet, the advent of cryptocurrency, such as Bitcoin, has provided a means for criminals to receive payment that is considerably more difficult to trace than traditional payment options. This, coupled with other factors, led to a 6,000% spike in ransomware in 2016 (IBM X-Force Study, 2016). While the volume of ransomware attacks has steadily decreased since that peak, the level of sophistication has increased. Attacks are becoming more targeted, more damaging, and costlier as cybercriminals continue to refine their tactics and become more organized.

How does it work? One reason ransomware has become more sophisticated is that cybercriminals have evolved, forming large-scale, well-funded, multinational crime syndicates. These criminal organizations investigate potential targets extensively. They learn what types of equipment and software the organization uses and select or create malware that takes advantage of known vulnerabilities in those systems. They examine the target organization’s finances to determine a ransom amount that is both affordable and less expensive than the cost to replace the affected systems. They scrutinize employees, studying their role in the organization, their interests,

...cybercriminals have evolved, forming large-scale, well-funded, multinational crime syndicates.


cyberflorida.org | 3

and their habits to craft highly targeted spear-phishing emails designed to entice an individual to click on a link or open an attachment, which covertly installs the ransomware. This method bypasses technological security protocols such as firewalls by luring the end-user to install the ransomware inadvertently. Targeting an organization using a phishing email is currently among the most popular attack methods, but there are other points of entry as well. Unsecured networks, vulnerable websites, malvertising (malware-laced web ads), and “drive-by” downloads (visiting malicious websites) are other methods cybercriminals use to install malware and ransomware, often completely unnoticed. Once the malware is installed, cybercriminals can “hide out” in the network for months, using the malware to gather information about the system, users, and data. Once they feel well-positioned to take control of as much of the system as possible, they launch the attack. The ransomware encrypts data and applications—virtually anything connected to the network that runs on software has the potential to be affected—and the ransom demand is sent.


4 | Ransomware Prevention: A Guide for Local Government

Part 2:

Prevention and Mitigation Fortunately, there are some fundamental cybersecurity best practices you can put in place to reduce your chances of becoming a victim of ransomware. 1. Back up everything, now. Create multiple backups for all critical data, including any data or applications needed to maintain daily operations and any sensitive data, such as payroll information and customer data. Preferably, employ a cloud backup service that can maintain multiple iterations of backups in at least two separate geographic locations. If you have viable backups of your data and applications, they can’t be held ransom. 2. Make sure everything is up to date. Most cyberattacks rely on known vulnerabilities that are often fixed through manufacturer updates and patches. Review all hardware, software, applications, operating systems, and devices to ensure all are operating with the latest updates and ensure that auto-update functions are enabled. 3. Train everyone. Make sure every employee that has access to the network, customer databases, or any sensitive information has basic cybersecurity awareness training that covers phishing, social engineering, malware, and responsible data protection practices. 4. Make sure you have a documented Cyber Incident Response Plan and Business Continuity and Disaster Recovery Plan in place and test them periodically. Prepare for the possibility of a ransomware attack by creating a Cyber Incident Response Plan that lets all employees know what to do in case of a cyberattack. A Business Continuity and Disaster Recovery Plan will allow the organization to maintain operations and recover more easily in case of an attack. Identify key equipment and programs and have a plan in place to recover or replace those systems quickly. Identify key personnel and make sure they are aware of their role and responsibilities in case of an attack. Periodically test these plans to look for gaps in coverage and ensure your team is prepared to act when an attack strikes. 5. Employ spam filters, firewalls, antivirus, and anti-malware solutions. Many operating systems and applications come with a host of built-in security features, such as firewalls and antivirus scanning. Most email programs offer spam filters and flag suspicious emails. Ensure that all security features are enabled at the most restricted setting and set to update automatically. 6. Employ the principle of least privilege. Restrict who has access to systems and files to only those who need access. Set file, directory, and network share permissions for each user based on their work role. Implement Software Restriction Policies (SRP) to prevent programs from executing from common ransomware locations, such as temporary and local app data folders.


cyberflorida.org | 5

7. Isolate systems when possible, especially legacy systems. If your organization uses a legacy system, that is, a piece of older software or equipment that is no longer supported by manufacturer updates, keep that system separated from all other systems as much as possible. Keep data categorized and segmented, virtually or physically, as much as possible. 8. Disable macro scripts from Microsoft Office files transmitted via email. Use Office Viewer to open MS Office files transmitted via email instead of full Office suite applications.

Part 3:

Final Takeaway A common problem faced by many organizations is that good cybersecurity practices are often inconvenient. People don’t use strong passwords because they can be difficult to remember; people skip multifactor authentication because of the extra time it takes; people check the box that says, “remember this card for future purchases” so they don’t have to pull out their wallets next time. Better cybersecurity requires vigilance on the part of every person using the system. One of the most cost-effective cybersecurity measures an organization can undertake is to build a cyber-aware culture by committing to training all users and making cybersecurity a priority in day-to-day operations. Become cyber-resilient by creating and periodically testing a Cyber Incident Response Plan as well as a Business Continuity and Disaster Recovery Plan. Include your employees in these endeavors, so they know that the organization takes cybersecurity and data privacy seriously.

FO R MO RE INFO RMAT IO N VIS IT:

cyberflorida.org/gov


C Y B E R F LO R I D A . O R G | 8 1 3 - 9 74 -2 6 0 4 | 4 2 0 2 E . F O W L E R AV E . , TA M PA , F L 3 3 6 2 0


Turn static files into dynamic content formats.

Create a flipbook
Guide to Ransomware Prevention by Cyber Florida: The Florida Center for Cybersecurity - Issuu