Ransomware – how to prevent it and what to do in the event of an attack?

26 November 2020

The threat posed by malware is a common phenomenon. Ransomware attacks are among the most dangerous due to their potentially catastrophic consequences for our data. Proper preparation, the development of an action plan, and the implementation of effective security measures can minimize potential losses.

What is malware?

The term “malicious” refers to all software whose operation is undesirable to the user due to its nuisance, harmfulness to the computer system, or the data stored in the system. Malware can hinder or prevent the use of a device, lead to the deletion or leakage of information (including personal and authentication data), and even result in partial or complete takeover of control over the device.

The English term malware is derived from the combination of the words “malicious” and “software.” There are many types of malware. For example, adware can be bothersome as it displays unwanted and irritating advertisements on the user's screen. Another type of malware – spyware – can collect information about the websites visited by the user. This action violates privacy, and the aim of spyware may not necessarily be to cause harm, but to gather statistical information about user preferences in order to tailor the displayed marketing content.

A significantly greater threat is posed by malware whose primary goal is to cause harm, for instance, to data stored on electronic device resources. In the 21st century, information, despite its intangible nature, can hold greater value than tangible assets. For this reason, any threats to collected data should be taken very seriously.

Ransomware – a particular danger to data

One of the most dangerous types of malware is ransomware (from the English ransom), which is typically aimed at extorting money. Ransomware operates based on the technical capabilities provided by modern cryptography. In principle, it is significantly easier to effectively encrypt data than to break the encryption without having the appropriate key. This means that data can be encrypted in the blink of an eye by the processor of a regular laptop, and decrypting it without knowledge of the key can take many years, even if the most powerful supercomputers in the world are used.

Individuals using ransomware software exploit the above conditions to encrypt data on computer storage devices, subsequently demanding payment of a specified sum of money in exchange for the decryption key. In theory, the encrypted data remains on the disks of the attacked system; however, in practice, the victim cannot be certain that they will receive the necessary key after making the payment. There is also no effective way to verify whether the data has already been permanently destroyed.

Ransomware Attack – How to Protect Yourself? The Role of Backups

Given the threat of ransomware attacks, the system administrator should take appropriate steps in advance to effectively eliminate, or at least limit, the potential losses. Recommendations for preparing for a ransomware attack are presented in the National Cyber Security Centre guide (hereinafter referred to as "NCSC"), a British government institution advising the public and private sectors on cybersecurity.

First and foremost, regular backups should be created. Backups are the most effective method of mitigating the effects of a ransomware attack. However, backups must be performed correctly. We caution that backups are typically a target for parallel attacks. Cybercriminals are aware that destroying or simultaneously encrypting backups increases the likelihood of receiving a ransom, as it places the victim in a no-win situation.

To minimize risk, we suggest that devices containing backups should not remain constantly connected to the network, even if it is the organization's internal network. If possible, devices storing backups should be kept in a separate location. It is advisable to create multiple copies.

An alternative solution aimed at protecting backups is to utilize appropriate cloud services that allow for the retention of previous versions of files. This is significant, as the latest version of a file, which is automatically synchronized from the user's device to the cloud service, may already be encrypted by ransomware.

Cybersecurity Training

Preventing the Spread of Malware and Protecting Devices from Infection

Measures should be taken to prevent the spread of malware between devices on the network. One preventive action is the automatic monitoring and filtering of content transmitted through devices. An example of this is filtering emails for attachments containing malicious software. Another example of filtering is blocking websites known for distributing malware.

The spread of malicious software can be limited by actions such as securing remote access protocols (RDP and SSH), using DNS services dedicated to security, and securing communication via VPN. It is essential to regularly patch known software vulnerabilities. An effective security measure is the use of multi-factor authentication (MFA), an example of which is two-step authentication, familiar to Polish users from banking applications.

GDPR. Support is useful!

The standard level of remote access, even for privileged users, should be set lower than administrative, with the possibility of elevating privileges after successful login. It is important to regularly review existing accesses and limit those user accesses that are not essential.

A separate group of security measures should protect devices in case the above barriers do not prevent the spread of malware. The necessity for constant software updates is also evident here, especially regarding patches that eliminate detected vulnerabilities. We recommend setting up automatic updates and using the latest versions of the operating system.

One should not forget about the details that make devices more susceptible to attack, such as disabling the auto-run feature for software placed on external media. System administrators should also secure or even limit the functionality of scripts and macros run through PowerShell, as well as macros in the Office suite.

An additional layer of security can be provided by a centralized management system for corporate devices, which will block users from installing applications from unknown sources.

READ MORE:How to Check the Quality of GDPR Implementation in IT?

Finally, in addition to ensuring the preparation of devices, it is essential to prepare the staff. Employees should possess knowledge regarding the threats associated with malware, which they can acquire, for example, through information security training. This final element is crucial, as the best security measures will be ineffective if the weakest link remains the human factor.

Actions to Take in the Event of a Ransomware Attack

One must warn against trivializing the threat posed by ransomware attacks. It is a misconception to believe that such attacks are directed against specific large organizations. In fact, victims of an attack can be entirely random entities, as malware can spread automatically. The best example was the WannaCry attack, which began in 2017 and infected over 300,000 computers in 99 countries, affecting both large multinational corporations and small businesses as well as public organizations. The existence of a widespread threat justifies the preparation of appropriate procedures and methods of action in the event of the worst-case scenario, in which practically all devices in the organization will be locked, and part or all of the data may become irretrievable.

In the event of an attack, infected devices should be immediately disconnected from the network; this applies to both wired and wireless connections. In critical cases, one should consider completely disabling access via Wi-Fi, as well as key switches in the internal network. All used passwords should be promptly changed, and encrypted devices securely wiped in order to reinstall the system. Before restoring data from backups, it is necessary to verify that the data archived in the backups is free from malware. Only after restoring the backups can devices be reconnected to the network, while carefully monitoring the generated network traffic for any further presence of malware.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
Do not succumb to blackmail. Payment to online criminals does not guarantee the receipt of the key necessary for data decryption. This data may not be encrypted at all, but may already be permanently destroyed, despite misleading messages that payment of the requested amount will lead to obtaining the decryption key. There are also other reasons against paying the ransom: such actions may support criminal groups, which—encouraged by a single success—may attempt further attacks of the same type in the future.

Prior Development of an Action Plan

An action plan in the event of an attack is essential to clearly establish the division of responsibilities and duties of individual employees in a crisis situation. The organization should be prepared for the possibility that documents prepared for the event of an attack may also be encrypted; therefore, action procedures and key information, such as contact lists, should be stored in an area free from ransomware threats, e.g., in resources disconnected from the network (including internal) or in paper form.

Preparing any plan requires an analysis of the current situation. The organization's management should identify key data resources within the organization and assess the consequences of their potential loss. Furthermore, it is advisable to determine the scope of legal obligations related to a ransomware attack in advance.

Example
In a situation where personal data is encrypted as a result of an attack, the data controller should identify its obligations arising from Article 33 and 34 of the GDPR related to a personal data breach. According to Article 4(12) of the GDPR, a personal data breach is understood as a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to personal data that is transmitted, stored, or otherwise processed. The above situation typically occurs in the case of a ransomware attack, as encryption means that the data has been altered, and in the absence of a backup, it can be assumed that it has also been destroyed or lost. There is a risk that the attack has simultaneously led to a data leak to unauthorized persons, which is tantamount to their unauthorized disclosure.

The data controller is obliged to report the incident to the President of the Polish Data Protection Authority if the breach results in a risk to the rights or freedoms of natural persons. The report must be made within 72 hours of becoming aware of the breach. In situations where the risk to the rights and freedoms of natural persons is high, the affected individuals must also be notified of the incident without undue delay.

READ MORE:How to Manage Breaches?.

Summary

The risk of a ransomware attack is widespread and therefore cannot be underestimated. Such attacks pose one of the most serious threats to stored data due to the ease of spreading malicious software.

Implementing appropriate safeguards, supported by effective plans and procedures, is not easy, as it requires knowledge and experience. If an organization lacks adequate preparation in this area, it should seek support from specialists in an outsourcing model, as careful preparation for a ransomware attack is a fundamental obligation of every data controller.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.