Don’t Pay a Ransom?? The Rise of Ransomware….

Ransomware…CISO’s worst nightmare right? Trust me, it’s something that keeps me awake at nights as well. Ransomware is the fastest growing threat there is today and its targeting everyone, whether they are home users, corporate users or government networks, etc. Cyber crime isn’t always about fancy hacks and killer exploits. It’s as simple as sending an email to transfer funds or pay an invoice from the MD – click on the attachment, boom there go your files!!

I am pretty sure when the bad guys started creating this kind of malware all they could think of is “show me the money” …look up Jerry Maguire if you want to know what I am talking about J….

So what is ransomware? It’s a piece of malware that blocks access to user files in simple terms. It encrypts all documents, pictures, etc. with a virtually unbreakable encryption key. You either pay up in cyber currency such as bitcoins or wipe out & rebuild your entire system, hoping you have a recent backup of all your data. If you do decide to pay up, there is no guarantee that you will be able to decrypt your data either. Oh, just so you know, if you do not revert to the attacker in the stipulated time he / she has given, the ransom also increases…: P

Of course there are different variants of ransomware – some are aimed at the Microsoft family, whilst some are aimed at the MAC family. The new age ransomware variants are more aggressive, stealthier in nature, advanced and of course created to evade traditional antivirus systems.

I am not getting in to basics of Ransomware, there are way too many articles on the same online…. the reason I decided to write this up is from a CISO’s perspective.

Good guys have to win always; bad guys have to win just once. The need of the hour – have effective and efficient cyber security controls in place. Think about it, in case of a cyber attack, who is the first one to get whacked? – the CISO. The job and the profile is tough, most of the times we have to do with the limited resources available with us – a magic wand to say. ;). Organizations across the globe are vulnerable to this threat and if anyone has told you they are protected against ransomware are sadly mistaken.

How do CISO’s reduce the risk from this menace? Awareness, awareness and more awareness for all end users. That is the key!! Of course you also need to ensure you have adequate “Secure” & “tested” backups as well. Why secure you may ask? For heaven’s sake, please ensure your backup copies are not “live” on your network or connected to your network all the time. Have an offsite rotation of your tapes if possible. I know many organizations who do their backups, but have never bothered testing whether the restoration works seamlessly, and when the time actually comes to do a restoration, there are issues. Murphy’s law huh?

I believe Incident preparedness is a major key area that is also gaining focus. The sooner you detect a ransomware attack on one of your systems, the faster you will be able to act. Disconnect the system from the network, get into forensics mode….

Everyone has a plan until they get punched in the face…. Then what? Do you freeze due to fear? It’s how you react to adversity that defines you…. let me know what you think?


Shilpa Krishnan

Vice President & Head Talent Acquisition at Bajaj Allianz General Insurance Co. Ltd.

7 年

Well written Delzad !

Sunil Kumar M.

Regional IT Service Management (India and Southeast Asia) | IT Governance and Audit Compliance | ITIL - Incident and Service Request Management | Strategic Planning | IT Asset Management | Budget Planning and Tracking |

7 年

A well written article, highlighting the risk in a very simplistic and straight manner. The risk is very high and organizations need to take such threats seriously and have the contingency plans always ready. And yes end user awareness is key... ??????

Abhishek Haridasan

Marketing Manager | M&A, Branding, Social Media, Event Management

7 年

Thanks for the article, Delzad. Educative and spooky at the same time. It's surprising that in today's age there are these so called anti-online elements who derive pleasure by hackling (read:hacking) into systems for that sadistic pleasure. While organizations take pride in their contingency planning, it'll only when they're thrown into the bull ring, that they are really tested. Keeping up to pace with online security is quite an onerous task and I'm sure you're 'GAME ON' for it. #Cheers #CyberSec in privy hands!

Vikas Arora

Senior Vice President - Global IT & Security | CISO | CIO | Security Leader | Privacy Leader | CISSP | CIPM

7 年
Nausika-Georgia Liossi

Sales & Operations at Magna Aviation

7 年

Excellent article, containing invaluable advice.

要查看或添加评论,请登录

Delzad P Mirza的更多文章

  • The Unwinnable War? Maybe, Maybe Not.....

    The Unwinnable War? Maybe, Maybe Not.....

    Robert Mueller said, and I quote “In future, the cyber threat will equal or even eclipse the terrorist threat”. One of…

    1 条评论
  • Fidarsi e' bene, non fidarsi e' megio….

    Fidarsi e' bene, non fidarsi e' megio….

    So, what does the headline mean? No, I don’t speak fluent Italian ;), It’s an Italian proverb which I came across…

    2 条评论

社区洞察

其他会员也浏览了