This article was created based on the Guide for Board Members (Cyber Security Toolkit) prepared by the National Cyber Security Center.

It contains practical tips for management on how to avoid a ransomware attack and ensure data security in the organization's IT environment. Below, we present answers to questions that board members may and should ask their IT specialists.
Why should board members be concerned about ransomware?
The security of the IT environment in the organization is one of the most important responsibilities of the board. Its members should particularly ensure effective protection against ransomware, as such attacks are becoming increasingly frequent and sophisticated.
Ransomware attacks can have negative consequences for the organization and cause significant financial and reputational losses. Restoring systems and databases to proper functioning can take a considerable amount of time. Moreover, such incidents can very negatively impact the organization's image in the public eye and in the media, as well as lead to a loss of trust from contractors.
What should board members know about ransomware software?
The complex programming language is reserved for IT specialists, which is why board members do not need to know the difference between Trickbot and Ryuk, but understanding the basics of how ransomware operates will facilitate constructive discussions with IT specialists.
What, therefore, is worth knowing about ransomware software?
- it is a type of malicious software that prevents access to a computer (or the data stored on it). Typically, data is encrypted (so it cannot be used), but it can also be stolen or shared online.
- most ransomware software currently in existence threatens the entire organization's network, not just a single user or computer. Once access to the system is gained, the attacker usually needs some time to locate key data and understand how their backups are created and stored. With this knowledge, the attacker can encrypt the entire network at the most critical moment.
- a ransomware attack is a crime, and the attackers are cybercriminals.
- The attacker usually contacts the victim using an untraceable email address (or from an anonymous website) and demands payment to unlock the computer and/or access the data. Payment is typically required in cryptocurrency, e.g., Bitcoin, and may depend on the time the attacker spent analyzing the network and assessing the value of the data stored on it.
- The attacked organization never has a guarantee that after paying the ransom, it will regain access to the attacked computer or data.
- Cybercriminals typically threaten to disclose confidential data stolen from the network as a result of the attack if the ransom is not paid.
- Experts advise against paying ransom to attacking criminals, among other reasons, due to concerns that paying the ransom will encourage cybercriminals to continue such attacks.
Five Key Questions About Ransomware for IT Specialists
How should the organization and its board members know when an incident has occurred?
There is often a significant amount of time (referred to as dwell time) between the attacker gaining access to the organization's system and the activation of ransomware software. Early detection of unauthorized access to the system can help prevent an attack, therefore the following issues should be considered:
- Has the management clearly defined procedures for similar attacks, and how will they be informed about the incident?
- How are databases containing at least critical data, including personal data, monitored, the breach, loss, or alteration of which would impact the organization?
- Who in the organization is responsible for monitoring systems and logs, and do they have sufficient knowledge to identify abnormal activity in the network?
- What mechanisms allow employees and collaborators to report suspicious activities?
- Are alert levels appropriately set (i.e., are they low enough to warn of potential incidents, but at the same time high enough to prevent the team from being overwhelmed with irrelevant information)?
- Do IT specialists know all the resources in the organization and their status? (Many attacks can be carried out through equipment that has not been properly checked).
What measures should the organization take to minimize the damage that attackers can cause in its network?
Ransomware attacks cause significant damage and can quickly spread throughout the organization's system. Therefore, it is worth asking:
- How does the organization authenticate user or system access? Is it possible to breach barriers, and is access granted only on a need-to-know basis?
- How can the organization identify the presence of an attacker in the network? Does it utilize network monitoring?
- How is the network segmented so that if an attacker gains access to one device, they do not have access to the entire organizational system?
Does the organization have procedures for managing cybersecurity incidents, and how can it ensure the effectiveness of the system?
Organizations should approach ransomware attacks from a risk perspective, i.e., "when it happens" rather than "if it happens." Therefore, it is important for the organization to have appropriate incident management procedures in place that allow for a rapid response in the event of an attack.
Incident management procedures should include the following elements:
- Identification of key contact persons (e.g., incident response team or provider, senior management, lawyers, HR).
- Precise definition of potential threat pathways (e.g., for senior management) and defined processes for significant decisions.
- Clear division of responsibilities (particularly indicating whether it pertains to limited responsibility during working hours or full responsibility 24/7).
- Provision of a contact phone number for emergencies.
- Having procedural requirements (e.g., when to report incidents and when to seek legal assistance).
- Indication of emergency measures for critical situations.
- A basic action plan during which potential access to data can be obtained (even if the employee does not have access to their computer); additionally, offline availability of the most critical information should be ensured (e.g., incident management guidelines and resources such as checklists and contact information).
Working with good GDPR tools is not work!
- Are simulations of cyberattack incidents conducted, and if so, how often? What conclusions are drawn from them?
- What level of specialized IT knowledge can the organization expect? Is it possible to utilize the services of a company specialized in managing cyberattacks?
Does the incident management procedure in the organization address the specific challenges associated with ransomware attacks?
There are specific characteristics of ransomware attacks that general incident management plans may not fully account for. Therefore, it is essential to discuss the following issues:
- How should the organization respond to a ransom demand when attackers threaten to publish sensitive data? Who should make such a decision? (As mentioned above, paying the ransom is strongly discouraged. There is no guarantee that meeting the criminals' demands will yield a positive outcome, nor will it protect the network from future attacks or prevent data leaks in the future).
- Is the organization prepared for a data recovery process that may take several weeks, and whose effects are likely to last even longer (to the detriment of the company's and brand's reputation)?
How are backups of the organization's data created, and is there assurance that they will remain intact in the event of a ransomware attack?
Ransomware often targets data backups, as this increases the likelihood that the organization will pay the ransom. Therefore, it is important for management to understand how backups are created and how they are secured. Thus, the following questions should be asked:
- What data is considered significant, and how often are backups created?
- How frequently are data backups made?
- What is the level of certainty that data can be recovered from these backups? How often are backups checked?
- How are backups stored? Are they stored offline/in a location separate from the organization's network/in the cloud?
- Is there a backup policy in place, and is it compliant with the principles outlined in the guide "Offline Backups in an Online World"?
Summary
The discussed issues contain many valuable tips for the management of organizations. They primarily focus on the threat of ransomware attacks, which pose a serious risk to organizations worldwide. It is important to emphasize that management and decision-makers play a crucial role in protecting against ransomware through awareness, proactive measures, and appropriate investments in cybersecurity. However, this will not be successful without the appropriate, informed actions of management, the implementation of security policies, regular employee training, and the maintenance of regular data backups. It is essential for organizations to have procedures in place for responding to ransomware attacks and to collaborate with cybersecurity service providers to monitor and protect their IT infrastructure.


