Skip to main content

What the Hack? April 2022

Page 1

What the Hack? April 2022

www.seconcyber.com


Secon

02

Ransomware 101. Always on, protecting you from ransomware Ransomware attacks have been omnipresent in the news recently and exploitable vulnerabilities are on the rise. Bad actors are diversifying both their approaches to delivering payloads and extorting money. When it comes to defending your organisation from ransomware, the core tenets you should keep in mind are protect, detect & respond, and recover. Below we set out the very basics every organisation needs to know to minimise the risk of ransomware and reduce its impact. If you’re interested in a more in-depth exploration into the Mitre att&ck framework and tips for what you should do if your organisation is hit, join our webinar ‘Ransomware response: Best practices’ on either 26 April 10:00 or 28 April 14:00. To learn more and register for the webinar, click the button below.

Register now

Protect Reduce likelihood of becoming infected •

Keep all operating systems and software up to date

•

Limit, and secure the use of RDP and force through VPN with MFA

•

Leverage least privileged access (especially for Privileged Accounts)

•

Deploy effective web and email gateway solutions

•

Enable and maintain IPS functionality on your Firewalls

•

Require MFA for all access (where not possible enforce strong and unique passwords)

•

Antivirus on all servers and endpoints and leverage EDR if possible

•

Train your users to be more “cyber aware”

•

Block all medium or high-risk access attempts

•

Only allow secure and patched devices to access your environment

•

Document and monitor all external remote connections

•

Segment networks

•

Document external remote connections

•

Control usage of cloud applications and block unapproved cloud applications (shadow IT )

•

Ensure third-parties that access, store or process your data have appropriate controls in place to safeguard it (should be at least at your baseline)


What the Hack? - April 2022

03

Detect & respond Reduce the likelihood of spread •

Always assume breach

•

Ensure logging enabled on all security tooling

•

Retain logs for 365 days

•

Leverage SIEM to correlate log telemetry for better detection

•

Leverage threat hunting to identify threats missed by security tools

•

Investigate anomalous access, traffic, and activity

•

Respond to threats identified quickly to contain

•

Where possible set access conditions leveraging geo-location and block any medium or high-risk access attempts

•

If possible, leverage automated response to anomalous behaviours, access, or activity

Recover Reduce the impact of the infection •

PLAN, PLAN, PLAN – Ensure you have a maintained and current incident response plan with playbooks for likely scenarios (e.g. ransomware)

•

TEST, TEST, TEST – Ensure regular testing of your incident response plan and update with lessons learnt

•

Ensure you can access your historical log data for investigation

•

Regularly tested 3-2-1 backup strategy •

3 copies of data (1 primary and 2 backups)

•

Keep data on at least 2 types of storage media

•

Store 1 of these offsite (without network connectivity to your environment)


Secon

04

How to stop email-borne ransomware. On-demand webinar One of the main attack vectors for ransomware is email. If you want to stop it from infiltrating your organisation, you need to stop it at the root cause. Unfortunately, email gateways are struggling to keep up with new attacks and more emails are getting through — ultimately ending up in employees’ inboxes. In April, we ran a series of webinars on how Secon and our partner Red Sift can help protect both your employees and your brand from email-borne ransomware threats. If you missed the webinar and are interested in how you can stop domain impersonation attacks, detect new malicious variations of your domain, and alert employees of sophisticated malicious emails, you can click below to watch it on-demand.

Key stats from the webinar.

95%

68%

$75k

of network compromise attacks started with a phishing or social engineering attack.

of phishing emails seen by Gmail today are new variations.

is the average amount lost in a single phishing email that ask for a wire transfer.


What the Hack? - April 2022

Always on call, supporting you through change. We know cyber security can be seen as overwhelming or scary, but we don’t think it should be. Our mission is to make security easy to understand and to get to the root of what people actually need: peace of mind. The way we work is constantly changing, and if you find yourself getting stuck or confused about a cyber security problem as your organisation evolves, please know that we’re always here for you and are happy to schedule a chat to discuss any security questions you have. Our team of Security Advisors have decades of experience in the cyber security industry and have helped hundreds of clients solve similar issues in their organisations. You can contact us anytime by visiting our website, by calling 0203 657 0707, or even booking in a quick meeting with our Chief Security Evangelist Andrew Gogarty at this link . No matter how you get in touch with Secon, we’ll always be ready to help identify your pain points and suggest the best course of action for your organisation. At Secon, we want to make the internet safe for everyone and see our cilents thrive. That’s why we’re always on hand, taking the stress out of cyber security.

Contact us

05


Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707

www.seconcyber.com


Turn static files into dynamic content formats.

Create a flipbook
What the Hack? April 2022 by Secon - Issuu