How do I protect my company from ransomware attacks?
Ransomware is malicious software that locks your files and systems by encrypting them, then demands payment for the key to unlock them. Today, most attackers also steal your data first and threaten to publish it unless you pay. This is known as double extortion or data extortion.
Financial firms are frequent targets. They hold valuable client data, such as account numbers and Social Security numbers, and depend on their systems to operate every day. An attack can cause:
- Downtime.
- Recovery and forensic costs.
- Customer and regulatory notification obligations.
- Serious damage to client trust.
How ransomware gets in
- Phishing emails: a malicious link or attachment, often very convincing. See What are spear phishing, watering hole and evil twin attacks?
- Unpatched software: attackers exploit known security holes in outdated systems, plugins and devices, especially internet-facing ones.
- Stolen or weak passwords: especially on remote access tools such as RDP or VPNs without multi-factor authentication.
- Drive-by downloads: malware downloaded automatically from a compromised website.
- Third parties: a vendor or partner whose systems or accounts are compromised.
Attacks often launch during evenings, weekends or holidays, when fewer staff are watching.
How to protect your company
Protect your data
- Back up regularly, and keep backups separate. Follow the 3-2-1 rule: keep three copies of your data on two different types of storage, with one copy offline or off-site. Use immutable or offline backups that ransomware can't reach or change.
- Test your backups. Regularly restore files to confirm your backups actually work.
- Encrypt sensitive data, and know where it's stored.
Secure access
- Turn on multi-factor authentication (MFA) for email, remote access, and cloud and admin accounts. This is one of the most effective protections available.
- Limit access. Give employees access only to the data and systems they need, and restrict administrator rights.
- Secure remote access. Don't expose remote desktop (RDP) directly to the internet. Use a VPN with MFA.
- Use strong, unique passwords, managed with a password manager.
Keep systems secure
- Install updates promptly, especially for operating systems, browsers, VPNs, firewalls, and website software such as WordPress and plugins.
- Use endpoint protection (antivirus or endpoint detection and response) on every device.
- Use email filtering to block malicious attachments and links.
- Block unauthorized software from being installed.
- Segment your network, so an infection on one system can't easily spread to others.
Prepare your people
- Train employees to recognize phishing, and run regular phishing simulations.
- Make it easy to report suspicious emails or activity, without blame.
- Verify unexpected requests for software installs, logins or payments with your IT team or the requester, using a known phone number.
- Use a VPN or your phone's hotspot when working on public Wi-Fi.
Plan ahead
- Create an incident response plan that covers who to call, how to isolate systems, how to communicate, and your legal and regulatory notification duties.
- Keep contact details offline for your IT provider, cyber insurance carrier, legal counsel and law enforcement.
- Review your cyber insurance to understand what's covered and what the insurer requires.
For financial firms: regulators may require a written cybersecurity program and prompt reporting of certain incidents. See Why is it important that my financial website comply with NFA requirements?
If you're hit by ransomware
Follow these steps in order:
- Isolate affected systems immediately. Unplug network cables and disconnect from Wi-Fi. If many systems are affected, take the network offline. Only power devices down if you can't disconnect them, since shutting down can erase evidence needed for investigation.
- Report it right away to your IT team or managed service provider, and activate your incident response plan.
- Don't delete anything, and don't pay the ransom yet. Keep ransom notes, emails and logs as evidence.
- Contact your cyber insurance carrier and legal counsel, who can connect you with incident response specialists.
- Report the attack to law enforcement: the FBI through ic3.gov and CISA through cisa.gov/report. They may have decryption tools or information about the attackers.
- Assess what was affected, including whether data was stolen. This determines your customer and regulatory notification obligations.
- Restore from clean backups only after the ransomware has been removed and the entry point closed. Otherwise, you risk reinfection.
- Reset all passwords and review access once systems are clean.
Should you pay? The FBI and CISA strongly discourage it. Paying doesn't guarantee you'll get your data back or that stolen data won't be leaked, it can encourage further attacks, and it may violate US sanctions if the attackers are sanctioned. Discuss any payment decision with legal counsel and law enforcement first.
For the full official checklist, see CISA's #StopRansomware Guide and response checklist.
Need help protecting your systems or planning your response? Contact the Gate 39 team through the Customer portal.
References
[1] CISA – Ransomware Response Checklist (PDF)
[2] CISA – Ransomware Response Checklist
[3] FOSSlife – New Ransomware Guidelines Issued by CISA
[4] AICPA-CIMA – CISA #StopRansomware Guide Response Checklist excerpt
[5] TechTarget – CISA offers ransomware response guidelines to organizations
[6] CISA – I've Been Hit By Ransomware!