Showing posts with label ransomware attacks. Show all posts
Showing posts with label ransomware attacks. Show all posts

Friday, March 27, 2020

3 Tips for Protecting your Company Against Ransomware Attacks


Ransomware has been on a rise this year and is expected to rise even more in the coming years. Ransomware damages are expected to cost $11.5 billion in 2019 and about $20 billion by 2021. The good news, however, is that there are relatively easy things any company can do to protect themselves from an attack and also recover from an attack if an attack happens to strike.

Implement The 3-2-1 Backup Strategy
One of the simplest and cost-effective things a company can do to protect themselves against ransomware attacks is to implement a cloud backup a strategy which is reliable and effective. This is where the 3-2-1 strategy comes in and since it is so effective, it is widely used.
The 3-2-1 strategy states that you should have three copies of data, stored on two different types of storage media and one of those copies should be stored offsite.
To further clarify this, it simply means that the three copies should be your production copy and the other two should be backup copies. The two backup copies should be on different types of media such as a separate network-attached storage (NAS) device and finally, one of those copies should be at an offsite location or in the cloud. Backup to Azure can be used for cloud backups.

Stay Updated on Security Patches
One of the most primary targets for hackers are operating systems, software, and device firmware. If these are not updated with the latest security patches, hackers figure out and take advantage of the vulnerabilities in the systems and this can help them to launch an attack, so keeping them updated with the latest security patch is very important.
Regularly check for updates and whenever an update comes, install it immediately. If this seems like a lot of work, security updates can be automated. Simply allow updates to be updated automatically whenever a new update comes and it will install on its own.

Educate Employees
Hackers often launch attacks through phishing emails and if employees are not trained well enough to distinguish between a phishing email and a regular one, they might fall prey to these scams.
Phishing emails usually have, grammatical mistakes, urgency inclined towards making you do or click something, an attractive offer about a product or a notice stating that something has happened to your bank or apple account but these emails usually have an unauthentic domain name. Backup disaster recovery solution techniques must be adopted to save your data from disasters.

Conclusion
Ransomware is a hot topic and will continue spreading the heat in 2020. Making sure that your company is protected against ransomware has become a topic priority nowadays. Cloud backups, Veeam backup to Azure and the above tips can help greatly to achieve it.

Tuesday, December 3, 2019

Disaster Recovery Testing-Key to a successful DR


Disasters can occur at any time and at any place and can be very cruel. Having a disaster recovery plan sure can help an enterprise in protecting their data but in order for it to do that, it needs to work first. The only way to know for sure that your disaster recovery plan will actually work is to test it, regularly.

Exactly How is Testing Important for an Enterprise
So much emphasis is made on building a disaster recovery plan but enterprises often forget that they actually need to make sure that their DR plan works or not.
An untested plan is just a set of steps in which some things might work and some might not. In order to ensure efficiency, all the steps of a DR plan should work. So, testing your DR backup plan is as important as setting up one.

Decide What Needs to be Tested
Testing a DR plan maybe simple or a bit complex, depending on your system. If there is only a single testing, then it may be quite simple rather than a multi-tiered system. Depending upon the criticality of your system, you need to test the plan accordingly.

Testing Frequency
Having talked about the importance of a DR plan testing it is also important to know the frequency of the tests performed on it.
The testing frequency should be based on how often your plan changes. If it changes a lot, then it should also be testing a lot frequently. If not so much, then it’s okay to test it only once a while.
To emphasize more on this, workloads or systems that don’t change at all only need to be tested maybe once a year, while workloads that tend to change a lot need to be regularly tested throughout the year.

More Efficient Disaster Recovery
Testing your DR plan enables you to identify any errors or issues encountered while recovering your data. This helps greatly as it pin-points exactly what the issue is and allows you to resolve it so that, at the time of actually needed recovery, there are no issues and all your files and systems are recovered, easily and efficiently.

Conclusion
Testing your DR plan is undoubtedly a very vital part of any DR backup plan. It can help greatly in identifying the issues or problems you might face while recovering your files and gives you an idea of whether your DR backup plan works or not. To ensure a more efficient DR backup plan, make sure you test your plan regularly. veeam cloud connect azure is also good for doing data backups.

Monday, September 16, 2019

A Massachusetts City dodges ransomware demand after attack



A major ransomware attack was recently targeted on a Massachusetts City, New Bedford. The attackers demanded more than $5 million. This is one of the highest ransomware demand ever reported. The city announced that they would instead try to restore their data through backups and will recover whatever is possible instead of paying the ransom. 
Therefore you must have a backup and disaster recovery mechanism to be on the safer end.
If they had decided to pay the ransom, then this would have been the largest ransom money ever payed by anyone.

How it happened?

The MIS staff identified a computer virus attack on 5th July 2019. It was a few later fully identified a ransomware attack. It happened in the early hours, before the employees began their day shift.
The staff has reported said that they have recovered most of the systems affected by the attack and daily services were not disrupted either because of the attack.

Negotiations

It is reported that the city officials made several attempts to negotiate the $5.3 million demand with the attackers but they did not accept. The last offer made by the officials was $400,000 which was also rejected by the attackers. To their dismay, the city officials decided to restore their systems manually without waiting or asking for the decryption key.

According to reports, about 4 percent of systems (158 computers to be exact) were affected by the attack. This is due to the fact that the staff immediately disconcerted the servers and shut down the systems before the attack could spread. This smart planning and decision making helped them to protect themselves from further damage.

It is unclear whether the city was able to fully recover all the data and systems affected but they reported that they were working on it and recovered their data and systems to some extent. This is a win for the tech community as it sends a message that there are other ways to deal with the problem, rather than paying ransom and giving in to these cyber thugs.
Even though the city saved themselves from paying the ransom they were still not able to fully recover all their data which can be critical as many companies and organizations have mission critical data and cannot afford to lose even 1% of it. This is where a backup and disaster recovery plan comes in.

Backup & Recovery Plan

If the city had a proper Cloud Backup and recovery plan in place they would have not worried about their data getting lost and wouldn’t have wasted time with negotiating with the attackers and risking to pay ransom to them. If they had a recovery plan they would have easily recovered their data in a matter of minutes. Veeam backup to azure can be used to backup your data.

There are many vendors who offers such services (for e,g, StoneFly’s DR365 & DR365V) and setting up a backup and recovery plan is as easy as ever.

Conclusion

Massachusetts City saved themselves from paying the largest amount of ransom ever demanded but on doing so they gambled highly with their data. The only safe and reliable way is to setup a backup & recovery plan and be prepared beforehand.