Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Thursday, 14 December 2023

Guarding Your Business: Ransomware Security and Data Recovery

Guarding Your Business: Ransomware Security and Data Recovery

Protecting your digital assets and information against the growing ransomware threat is crucial in the current digital and security landscape. The ever-evolving sophistication of cyber threats, particularly ransomware attacks, poses a significant risk to small and medium enterprises (SMEs). These businesses, often with limited IT resources, face daunting challenges when protecting their critical data and ensuring a swift and effective recovery in the face of an attack.

As National Computer Security Day approaches, our conversation with Dr. Shekhar Pawar aims to enlighten the audience about the risks associated with ransomware and effective strategies that businesses can implement to strengthen their cybersecurity defenses. Dr. Shekhar Pawar is a distinguished cybersecurity expert, holding a Ph.D. from SSBM Geneva. He is widely recognized as the founder and CEO of SecureClaw Inc. and GrassDew IT Solutions Pvt. Ltd. Dr. Pawar’s passion for advancing cybersecurity extends to his contributions as an author and inventor. He is the visionary behind the BDSLCCI cybersecurity framework. With his extensive knowledge, experience, and achievements, Dr. Shekhar Pawar is a leading figure in cybersecurity, dedicated to protecting digital assets and enhancing the security landscape for individuals and organizations worldwide.

In this interview, he delves into the world of ransomware security and data recovery, equipping you with the knowledge and tools needed to protect your business from these insidious threats and recover swiftly in the event of an attack.

1. What is your take on the current landscape of ransomware attacks and their impact on small and medium businesses (SMBs)?


Ransomware, a cyber attack implemented using malicious software, is the most popular financial gain-motivated cyber attack performed by cyber criminals. It can target personal devices as well as organization-level infrastructure and devices. The aim of any ransomware software is to encrypt files or systems and stop users from accessing them. In this malicious scenario, files, and at times, entire devices, are subjected to encryption and subsequently held captive until the target submits a ransom in return for a decryption key. This key serves as the means by which the user can regain access to their encrypted files or the affected software systems. It was known as a single extortion attack. After that, cyber criminals started a new technique to gain an additional ransom from their targets, which can be called double extortion. In cases of single extortion, many organizations overcome the threat of file encryption with a simple, up-to-date backup system. Cyber criminals aim at stealing sensitive information from organizations and threatening to release or sell it, often on the dark web or other information black market platforms. However, even if the targets pay a ransom for data recovery, they may still be forced to pay another ransom to prevent their stolen data from being made public.

Furthermore, in addition to double extortion attacks, triple extortion attacks in various areas are also possible, where cyber criminals add another layer of threat by disrupting the organization’s services to apply extra pressure. Taking this a step further, quadruple extortion is possible if ransomware attacks impact the third-party associates of the targeted organization.

Ransomware attacks have a long chain of extortion for their targets; hence, it is recommended to implement preventive measures as well as not pay ransom money to threat actors. According to my recent research studies among small and medium companies, a lack of funds to implement available cybersecurity standards in the market, demand for dozens of controls to be deployed, a lack of skilled teammates to implement or maintain cybersecurity controls, and a lack of visibility of Return on Investment (ROI) while investing resources in adopting cybersecurity standards were four key issues faced by those companies.

2. What are some common TTPs and security gaps that cyber criminals use to initiate ransomware attacks for SMBs?


Many recent reports indicated that ransomware attacks originate from various social engineering tricks, remote desktop vulnerabilities, remote server attacks, unpatched software, password guessing, credential theft, third-party security gaps, misplaced USB drives, etc. Once a machine gets infected by the malicious software, the threat actor uses the command-and-control (CC) server to execute further steps. Using an encryption key, cyber criminals can encrypt the machine. Even before encrypting, they can back up data to their CC server or another place. After the encryption of data on the target device, a ransomware note is shown to the user of that device. Generally, it has instructions for targets on how they can communicate with cyber criminals and how they can transfer the ransom to a cryptocurrency account. Also, threatening comments ask not to try decrypting these devices using third-party tools, or the organization could lose the data.

Further, they threaten the target by giving them a timeline of, say, 24 hours or so to decide to pay ransom, with more threats to try to sell it on the darknet and so on. Human beings have been the weakest link in most cyber attacks. A malware attack followed by a ransomware attack is the kind of combination that works for threat actors. Many SMB companies are not able to invest more in advanced cybersecurity controls due to a lack of knowledge and budget. During my research studies, I even found that more than one-third of small and medium companies never had any cybersecurity training for their employees. Another one-third of them have a once-a-year kind of security awareness training, and the rest have different periodic such training. Around one-third of such companies do not have any security policies, procedures, or guidelines in place. Around 25% of companies do not implement physical and technical security controls.

3. What steps can businesses take to proactively protect their data and systems against ransomware attacks?


Today, there are various mature and leading standards of cybersecurity, such as NIST, ISO 27001, the Zero Trust Framework, and so on. The only thing is that many times, SMB companies do not have enough resources or readiness to adopt them. One of the observations is that many standards are generic for all business domains, which results in many cybersecurity controls being implemented. Every SMB should look at two verticals of cybersecurity control implementation. The first is the defense in depth mechanism, also known as the onion or castle model. It has various layers of cybersecurity controls, increasing the difficulty for cyber criminals to perform their tricks or techniques. Even if one layer is compromised, other layers often prevent malicious intent. Also, top management needs to identify mission-critical assets (MCAs) on which their maximum business is able to survive or grow. There should be extra attention provided to such MCAs. As part of my international research studies and publishing, I have invented a business domain-specific least cybersecurity controls implementation (BDSLCCI) framework for securing SMB or SME companies. As its name suggests, depending on the business domain of the SMB or SME company willing to adopt BDSLCCI, the list of cybersecurity controls for its business domain will vary. BDSLCCI also provides information on which control needs to be implemented first and the rest of the control order to be implemented. It helps SMBs protect themselves against cyber threats with a reduced number of controls and, hence, a reduction in the resources required to adopt BDSLCCI.

4. In the unfortunate event of a ransomware attack, what are the best practices for incident response and data recovery?


Yes, it is possible, due to any unaware employee’s mistake, associated supply chain, or any such circumstances, that despite lowering the overall risk of undergoing any successful ransomware attack, there may be a successful attack. The organization must have regular backups in different networks or locations, which should be operational. Also, backups should have been tested regularly to see if they were really going to work during recovery in case of a ransomware attack. After a specific device has been infected, the initial step is to quarantine it from the network to prevent the malware from spreading to other devices. A few cybersecurity experts can help you decrypt files using the few available tools. In many countries, as per law and compliance, it is required to report such cyber attacks to the Computer Emergency Response Team (CERT) or similar authorities within a few hours. If organizations suspect that their customer data or similar might have been impacted by ransomware, it is always better to inform affected customers. Otherwise, their hacked information can be used by hackers to perform another crime. It is a recommended best practice not to pay ransom in such cyber attacks, as no one should trust the unknown or hidden face of a cyber criminal.

5. How do data recovery and business continuity aspects for SMBs differ from those of MNCs?


For large organizations or multinational companies (MNCs), investing in and implementing data recovery and business continuity aspects is relatively easy as they can recruit or outsource certain IT or security functions. When we look at SMEs or SMBs, they are lagging in their respective skilled resources and funds, and their top management only prioritizes sustaining or growing their business goals.

Top management needs to write a practical business continuity plan prioritizing mission-critical assets to be safe and secure during unforeseen circumstances. SMBs need to identify critical data to be protected and take regular, secure backups of it. There can be incremental data backups or even full backups, as per the top management’s decision. Now that every SMB must have a work-from-home or remote working facility, it is possible to consider a backup site rather than not having anything in place. Only employees need to undergo regular cybersecurity awareness training to make sure they maintain cyber hygiene while working remotely. Only per-need access should be granted to the employees; no admin privileges must be given to every employee for their device. It is also recommended to simulate cyber drills once every six months to check business continuity readiness.

6. Are there any specific tools or technologies that you suggest SMBs to consider when planning their data recovery strategies?


Various data recovery tools are available on the market, and it is important to use trusted sources and read reviews of such tools. There are many websites that even compare the tools available on the market. SMBs need to do research. The top management decides to compare and choose. If the SMB’s business is data-centric, they need to purchase such tools. If the size or value of the data is not high, then they can even have a manual process or develop small tools using technology. Today, many endpoint protection software options have built-in data backup and recovery features. A few SMBs even develop small SQL batch jobs to take regular backups of crucial data or files. It is important to keep encrypted backups at secured locations so that even if backups get hacked, they can’t be used by threat actors. Always keep a backup teammate for crucial data backup and recovery operations. One important thing is that even encrypted backups can be kept on an external hard disk or tape, which should be kept in a secured physical locker. This preparedness helps during an actual incident.

7. How can SMBs balance the cost-effectiveness of data recovery solutions with the need for robust cybersecurity?


It is a myth that only costly tools can provide the best security. It is a combination of the operations team’s efforts and tools that makes a well-secured ecosystem for any organization. Adopting a particular data backup and recovery solution is a very strategic decision. The cloud is a good and cost-effective solution, according to my experience working with SMBs. A few SMBs even take backups at two different locations; this is good practice. Only the SMB needs to encrypt data in all three states: data in rest, data in transit, or data in use. Also, only limited access should be granted to the backups or their operations, as those are very sensitive. It is important to delete unnecessary data or even backup files to reduce the cost of backup and recovery operations. Data layer security policies are very important, especially to avoid insider threats and to have good access control. The smaller the size of the data, the better the performance of backup and recovery operations.

Source: eccouncil.org

Tuesday, 23 May 2023

Expert Insights: Combatting Malware Threats with a Holistic Security Strategy

EC-Council Career, EC-Council Skills, EC-Council Jobs, EC-Council Prep, EC-Council Preparation, EC-Council Guides, EC-Council Learning, EC-Council Insights

The threat landscape is changing. Attackers are becoming more sophisticated, as they know security teams are looking for a holistic approach to protect their organizations. Accompanied by the huge diversity of malware available, both in sophisticated and disruptive nature, the list of potential threats is long and comprehensive. Therefore, it can be quite overwhelming to start looking at everything from an “in-depth” perspective. Cybersecurity Exchange got in touch with Vinjaram Prajapati, cybersecurity director for Aligned Automation, to learn his views on how malware and the security landscape will evolve. Although novel approaches to combat malware, such as AI and ML, are emerging trends, Vinjaram states that organizations should not lose focus on finding a comprehensive security approach for responding to security incidents.

Vinjaram Prajapati, an information security expert, has over 17 years of experience in the industry. He has excellent client relationship-building prowess and is an established decision-maker who mentors his team to meet project milestones. As a leader, he oversees project milestones and mentors team members to achieve those goals. Over the course of his 17-year career, Vinjaram Prajapati has developed and delivered information security solutions to promote business opportunities in the cybersecurity space. The following are edited excerpts from the interview:

1. What are the top malware threats to information security today?


Below are some of the most prominent malware threats in today’s information security landscape:

  • Ransomware: Ransomware is malware that can spread to computers, phones, and other devices through an email or a website and encrypt the victim’s files until the victim pays a ransom.
  • Trojans: A Trojan is a malicious software that masquerades as licit software and can be used to gain access to a system for malicious purposes.
  • Spyware: Spyware is a kind of malware used to monitor a computer or device without the user’s knowledge.
  • Rootkits: A rootkit is a type of malicious software designed to hide within the operating system of a computer or device.
  • Adware: Adware is a malware designed to display advertisements on a system without the user’s knowledge or consent.
  • Cryptojacking: Cryptojacking is malware that uses a computer or device’s resources to mine cryptocurrency without the user’s knowledge or consent.
  • Bots: Bots are malicious software that can be used to carry out automated tasks, such as spamming, launching DDoS attacks, or stealing information.

Today, security threats are rampant and can be encountered online and offline. Online security threats can come in many forms, including phishing, viruses, and Trojans. Offline security threats include theft, vandalism, physical attacks, and other criminal activities.

2. What should organizations look for when it comes to security to ensure that both their business goals and their management will not be compromised?


Organizations should look at security from a holistic perspective, considering various elements such as risk management, compliance, data protection, authentication, access control, and more. All of this should be implemented so that the organization’s business goals or management are not negatively affected. For example, encryption should be used to protect sensitive data but must not impede the organization’s ability to do business. Similarly, authentication should be used to protect user accounts but should not be overly burdensome or intrusive. A comprehensive approach to security can ensure that your business goals and management are not compromised while still providing a secure environment.

3. How do you achieve and advise other security leaders to achieve a stable work-life balance?


There are several ways to achieve work-life balance, and here are some suggestions:

  • When it comes to achieving a work-life balance, the first step is to define boundaries between your personal and professional lives. Set clear expectations with your team and colleagues about the hours you are available and stick to them.
  • Setting achievable goals for your team and yourself will help you manage your workload and not feel overwhelmed.
  • It’s essential to make time for yourself each day, whether through walking, enjoying a book, or resting. Staying focused and minimizing stress will be more manageable if you take a break from your routine.
  • Prioritizing tasks and projects is the key to achieving a stable work-life balance. Focus on the most important tasks first so that you can be more efficient and have more time for yourself.
  • As a security leader, it is important to delegate tasks to team members or colleagues so that you can manage your workload and not be overburdened.
  • Staying organized and keeping track of tasks and deadlines will help you manage your time more effectively and help you stay on top of your workload.

4. Based on your experience delivering security solutions, what rudimentary security frameworks and policies do most organizations lack or overlook?


  • Many organizations lack a comprehensive security policy that outlines the roles and responsibilities of those responsible for security, the security measures in place, and the processes for responding to security incidents.
  • Lack of proper user access controls—such as user authentication, authorization, and segmentation of duties—can allow unauthorized users to gain access to business data and systems.
  • Some organizations lack secure configuration management processes, such as ensuring that systems are regularly patched, updated, and configured securely. Without these processes in place, systems can be vulnerable to attack.
  • Many organizations lack a data classification system that classifies data in terms of sensitivity and risk. Without this practice, organizations can be unaware of which data is most critical and vulnerable.
  • Security awareness training is necessary to ensure that users are aware of their roles in maintaining the organization’s security. Without this training, users may be unaware of the risks of their actions or may not understand their responsibilities.

5. How do you see malware-based threats evolving, given the significant changes occurring in technology today?


As technology becomes more complex, malware-based threats are likely to evolve in sophistication and complexity as well. Attackers will take advantage of the increasing number of connected devices and more sophisticated artificial intelligence, machine learning, and data analytics tools. Malware creators may also use more sophisticated techniques to hide malicious code, such as encrypting or inserting it into legitimate software. Additionally, attackers may use more advanced techniques to spread malware, such as social engineering, phishing, and other forms of cybercrime. Finally, attackers may use distributed computing platforms, such as botnets and distributed denial-of-service attacks, to disrupt systems and networks.

6. What novel and upcoming technology will impact defense against malware the most?


One novel and upcoming technology that will have a tremendous impact on defense against malware is artificial intelligence (AI). AI can be used to detect and identify malicious software before it spreads, as well as detect and respond to threat actors. For example, AI-based systems can be trained to identify malicious code, analyze malicious behavior, and even predict and prevent malicious attacks. It can also be used to streamline and automate security processes, allowing security teams to focus their efforts on more critical tasks.

7. As a decision-maker in an organization’s security, what aspects would you expect or advise security leaders to focus on or consider before implementing security policies or changes?


  • Assess the organization’s security risks and prioritize security initiatives based on their potential to mitigate the most significant risks.
  • Develop and enforce organization-specific security policies and procedures across all departments.
  • Monitor security measures regularly and review them for effectiveness.
  • Educate employees and other stakeholders on security policies and measures, and ensure they are aware of the potential consequences of violating them.
  • Utilize the appropriate technology and tools to protect the organization’s data and resources.
  • Evaluate all third-party service providers for compliance with the organization’s security criteria.
  • Prepare for incidents and disasters by having a plan and regularly testing it.
  • Allocate the necessary resources to keep your security measures up-to-date and effective.
  • Develop an incident response plan that includes a step-by-step process for dealing with a security incident.

8. What advice would you give aspiring professionals aiming for a successful threat intelligence and incident handling career?


  • Keep up to date on the newest developments in threat intelligence and incident handling.
  • Gain a thorough understanding of the various methods and tools used in threat intelligence and incident handling. This includes learning about different types of malware, attack vectors, and risk management processes.
  • Invest in training and certifications that will help you become more specialized in your field. Many organizations require specific certificates for employment in this field.
  • Network with other industry professionals and make connections with experts in the domain. This allows you to tap into abundant resources.
  • Build a portfolio of case studies and success stories that highlight your expertise. By doing this, you will set yourself apart from competitors and establish your competence as a professional.

Source: eccouncil.org