Commercial Integrator December 2021 - 14

THE SERVICE DESK
Evolution of Ransomware
8 vital steps integrators must take on every project to secure your client's network.
by Stanley Louissaint
RANSOMWARE... you've heard of it and
there is a high likelihood that one of your
clients has already been held hostage.
As the ransomware industry matures, it
has evolved from its origins. Yes indeed, I
called it an industry, and for a reason. If you
can secure millions of dollars in payouts and
create billions in losses for businesses, you
have earned the right to be called an industry.
Ransomware is no longer about holding
data hostage for a payment (or ransom).
Now, ransomware groups are threatening
to publicly disclose that the victim has been
hacked. Even more damaging is the threat
to release sensitive data to the public if the
victim doesn't pay.
As an industry we have been focused
on recovery of critical business systems
in the event that one of our clients falls
prey to a ransomware attack. What is our
recovery point objective (RPO)? What is
our Recovery Time Objective (RTO)? What
is the cost of downtime? What is the cost
of recovery? These are the questions that
we have been asking to help businesses
fi nd the proper solutions to implement for
recovery during an unfortunate circumstance.
Armed with this information we
would deploy a solution that would save
our clients from having to pay any form of a
ransom since we had the necessary data to
get them back up and running. Up to this
point in time, we weren't concerned that
the data itself was being ex-fi ltrated from
the network. To our defense, we didn't
have to be because it wasn't.
As the ransomware industry has evolved
the cybercriminals have had to get creative
to construct a situation where even if we
had the company data, we still had an
incentive to pay. The goal of most businesses
is to have clients hand over their cash or
in this case some form of cryptocurrency
payment.
Instead of taking a reactive approach
and focusing on how we will recover in
the event of a ransomware, we have to be
proactive in preventing the attacks. As a
14
3. Next-Generation Firewalls: Make
sure your fi rewall has built-in antispyware,
malware, and ransomware detection.
Application whitelisting/blacklist. Intrusion
Detection and Prevention Systems (IDS/IPS).
4. Endpoint Detection and Response
Integrators need to take a proactive
approach to preventing ransomware
attacks instead of a reactive stance.
Managed Service Provider (MSP) we wear
our proactive nature as a badge of honor
and even use it to diff erentiate ourselves
from a typical break/fi x shop. Part of our
value to our clients is to help them maintain
a positive public persona. Through the
proper protection of their computer and
network systems we can help the image of
our clients via these important steps:
1. Security Awareness Training to
End-Users: I cannot stress enough how
important this part of the puzzle is. End
users are oſt en our fi rst line of defense.
Educating users is highly important and will
never go out of style. At a minimum you
should run phishing tests or have end-user
training quarterly.
2. Spam Filtering: Most ransomware
enters a network through a phishing
campaign. Cloud-based spam fi ltering
has evolved greatly over time. We need
a solution that will block spam, phishing
attempts, malware, impersonation, and
ransomware. There are many layers to
having a successful spam fi ltering solution.
Look for solutions that off er features such as
sandboxing and malicious link protection to
help protect against 0-day threats.
Commercial Integrator DECEMBER 2021
(EDR): These systems help you to gain
insight into end-user devices. During an attack
these systems have the ability to isolate
machines from the network to prevent the
spread of ransomware.
5. Multi-Factor Authentication (MFA):
Usernames and passwords aren't suffi cient
anymore. MFA is the new standard. Every
e-mail account should have MFA enabled
and critical business systems that are
accessed from outside of the environment.
All administrative access should have MFA
turned on.
6. Soſt ware Patching: Vulnerabilities
are found every day and having a proper
patching schedule ensures that you are
plugging up any holes that have been
found in soſt ware.
7. DNS Filtering: Using third-party DNS
fi ltering providers helps you to save your
users from malicious domains that are trying
to get them to input their user credentials.
8. Data Loss Prevention (DLP): With
DLP solutions you will be able to help monitor
the data that's exiting your network.
This can be a game changer if you notice
sensitive data leaving the environment.
A new security model that is being
introduced into environments is the Zero
Trust Security model. Although this method
requires the most support, it is beginning
to gain more ground in our industry. The
framework is that by default no device or
user is trusted even if they are allowed on
the network. This is a solution, when implemented
automatically, that keeps users in
their corner of the world.
Stanley Louissaint is Principal
& Founder of Fluid Designs Inc.
He has been a member of The
ASCII Group since 2014.
commercialintegrator.com
IVAN/STOCK.ADOBE.COM
http://www.commercialintegrator.com

Commercial Integrator December 2021

Table of Contents for the Digital Edition of Commercial Integrator December 2021

Commercial Integrator December 2021 - Cover1
Commercial Integrator December 2021 - Cover2
Commercial Integrator December 2021 - 1
Commercial Integrator December 2021 - 2
Commercial Integrator December 2021 - 3
Commercial Integrator December 2021 - 4
Commercial Integrator December 2021 - 5
Commercial Integrator December 2021 - 6
Commercial Integrator December 2021 - 7
Commercial Integrator December 2021 - 8
Commercial Integrator December 2021 - 9
Commercial Integrator December 2021 - 10
Commercial Integrator December 2021 - 11
Commercial Integrator December 2021 - 12
Commercial Integrator December 2021 - 13
Commercial Integrator December 2021 - 14
Commercial Integrator December 2021 - 15
Commercial Integrator December 2021 - 16
Commercial Integrator December 2021 - 17
Commercial Integrator December 2021 - 18
Commercial Integrator December 2021 - 19
Commercial Integrator December 2021 - 20
Commercial Integrator December 2021 - 21
Commercial Integrator December 2021 - 22
Commercial Integrator December 2021 - 23
Commercial Integrator December 2021 - 24
Commercial Integrator December 2021 - 25
Commercial Integrator December 2021 - 26
Commercial Integrator December 2021 - 27
Commercial Integrator December 2021 - 28
Commercial Integrator December 2021 - 29
Commercial Integrator December 2021 - 30
Commercial Integrator December 2021 - 31
Commercial Integrator December 2021 - 32
Commercial Integrator December 2021 - 33
Commercial Integrator December 2021 - 34
Commercial Integrator December 2021 - 35
Commercial Integrator December 2021 - 36
Commercial Integrator December 2021 - 37
Commercial Integrator December 2021 - 38
Commercial Integrator December 2021 - 39
Commercial Integrator December 2021 - 40
Commercial Integrator December 2021 - 41
Commercial Integrator December 2021 - 42
Commercial Integrator December 2021 - 43
Commercial Integrator December 2021 - 44
Commercial Integrator December 2021 - 45
Commercial Integrator December 2021 - 46
Commercial Integrator December 2021 - 47
Commercial Integrator December 2021 - 48
Commercial Integrator December 2021 - Cover3
Commercial Integrator December 2021 - Cover4
https://www.nxtbook.com/emerald/commercialintegrator/august_2023
https://www.nxtbook.com/emerald/commercialintegrator/july_2023
https://www.nxtbook.com/emerald/commercialintegrator/june_2023
https://www.nxtbook.com/emerald/commercialintegrator/may_2023
https://www.nxtbook.com/emerald/commercialintegrator/april_2023
https://www.nxtbook.com/emerald/commercialintegrator/march_2023
https://www.nxtbook.com/emerald/commercialintegrator/february_2023
https://www.nxtbook.com/emerald/commercialintegrator/january_2023
https://www.nxtbook.com/emerald/commercialintegrator/december_2022
https://www.nxtbook.com/emerald/commercialintegrator/november_2022
https://www.nxtbook.com/emerald/commercialintegrator/october_2022
https://www.nxtbook.com/emerald/commercialintegrator/september_2022
https://www.nxtbook.com/emerald/commercialintegrator/august_2022
https://www.nxtbook.com/emerald/commercialintegrator/july_2022
https://www.nxtbook.com/emerald/commercialintegrator/june_2022
https://www.nxtbook.com/emerald/commercialintegrator/may_2022
https://www.nxtbook.com/emerald/commercialintegrator/april_2022
https://www.nxtbook.com/emerald/commercialintegrator/march_2022
https://www.nxtbook.com/emerald/commercialintegrator/february_2022
https://www.nxtbook.com/emerald/commercialintegrator/january_2022
https://www.nxtbook.com/emerald/commercialintegrator/december_2021
https://www.nxtbook.com/emerald/commercialintegrator/november_2021
https://www.nxtbook.com/emerald/commercialintegrator/october_2021
https://www.nxtbook.com/emerald/commercialintegrator/september_2021
https://www.nxtbook.com/emerald/commercialintegrator/august_2021
https://www.nxtbook.com/emerald/commercialintegrator/july_2021
https://www.nxtbook.com/emerald/commercialintegrator/june_2021
https://www.nxtbook.com/emerald/commercialintegrator/may_2021
https://www.nxtbook.com/emerald/commercialintegrator/apr_2021
https://www.nxtbook.com/emerald/commercialintegrator/march_2021
https://www.nxtbook.com/emerald/commercialintegrator/february_2021
https://www.nxtbook.com/emerald/commercialintegrator/january_2021
https://www.nxtbookmedia.com