Site icon bbrief

How to be more resilient in the face of sophisticated ransomware threats


Clive Brindley | Security Lead | Accenture Africa | mail me |


Impacts vary, but in many cases, ransomware disrupts businesses for significant periods or even forces them to suspend operations or close. A growing population of highly capable cyber extortionists is developing a new means to counter defences and increase the level of disruption they can inflict constantly.

Threats are widespread and extend across industry and the public/ private sector, affecting large and small businesses alike.

Threats can disrupt production, delivery, customer services, or a loss of sensitive commercial data and protected information. There can be direct costs of remediation, recovery, or potential ransom payment, as well as costs associated with litigation. Further, there is a high risk of legal and regulatory sanctions and reputational damage.

Security leaders must understand and counter new ransomware challenges, strengthen defences across people, processes, and technology and demonstrate why security is critical to the business strategy. In short, security leaders need to help their organisations gain ransomware resilience fast!

Challenge 1: Successful ransomware extortionists are ramping up attacks

Established ransomware operators are upping their game, focusing on new monetisation opportunities, and seeing no limits to potential profits. At the same time, the barrier to entry is low; ransomware tools and supporting operations are readily available through various markets and affiliate networks.

The population of extortionists is growing as new cybercriminals are drawn to the low-risk, high-reward operations.

To plan for resilience, organisations should focus on the business and operational risks presented by the threat across their unique value chain and prioritise planning and defence efforts accordingly.

Challenge 2: Extortionists are constantly improving their ability to disrupt

The incentive for cyber extortionists is to develop ever-more disruptive ways of working. The more disruption they can inflict, the larger the ransom they can demand.

Operators keep innovating by first using ransomware targeted against critical assets and then combining that with data leak extortion. There are indications that certain operators are increasing their ability to interfere with operational technology (OT) processes and honing other means to pressure payment, including layering distributed denial-of-service attacks with encryption and data leakage.

The commodification of the skills and services required enables and rewards the development of new, more disruptive techniques. This includes initial access brokers and intrusion specialists to ransomware-as-a-service models with partners and affiliates and specialist negotiator middle-men.

In December 2020, extortionists targeted one of the world’s largest manufacturers, claimed encryption of 1,200 servers, realised the theft of 100GB of data, deleted 20 to 30TB of backups and demanded a $34 million ransom.

Challenge 3: Business growth and service strategies lack resilience

Downtime (business standstill or minor non-availability) from ransomware is still growing. Coveware explains that firms experienced on average 23 days of downtime in the first quarter of 2021 up from 21 days in the fourth quarter of 2020.

Encryption can deny access and interrupt essential resources, including internal and customer communications and platforms and operational or production systems.

Long periods of downtime can affect tens of millions of people. The theft and publication of data give attackers new extortion opportunities. Ransom demands are growing and becoming more customised – with threat actors assessing who is more likely to pay. If ransoms are paid, it can open the door to further criminality.

Additionally, some ransomware operators have been sanctioned, potentially placing a ransom-paying victim in further legal jeopardy.

Five steps you can take now

Operate under the assumption that you are already breached and focus on resilience across the end-to-end value chain.

Focus on the basics:

Prevent and protect:

Know your operations:

Make it personal:

Prepare, prepare and prepare again:

So, you’ve been hit – what’s next?


 

Exit mobile version