CLOUDTWEAKS CONTRIBUTOR PROGRAM

Join the CloudTweaks thought leadership contributor program which includes a customized profile, branded identity page, newsletter marketing, social amplification and more...

The program is currently available to consultants, influencers or executive level contributors.

Vibhav Agarwal

Ransomware Cyber-Attacks: Best Practices and Preventative Measures

Ransomware Cyber-Attacks

WanaCrypt0r 2.0” or “WannaCry,” an unprecedented global ransomware cyber-attack recently hit over 200,000 banking institutions, hospitals, government agencies, and other organizations across more than 150 countries. The ransomware encrypted user data, and demanded a payment in bitcoins to unlock the data. The companies that were hit included Telefonica – Spain’s largest telecom provider, more than 16 hospitals in England’s National Health Service (NHS), US package delivery company – FedEx, and many other high profile targets.

Across the world, cyber-attacks are on the rise. CSO magazine cited the FBI as saying that $209 million had been collected in ransomware payments in the first quarter of 2016 alone. These attacks illustrate how unprepared most organizations are to counter the growing menace of cyber threats. Many large organizations still use unsupported or older versions of software, encounter significant delays in patching vulnerabilities, and perform fewer automated backups, thereby putting themselves at grave risk. As the scale and impact of cyber-attacks grow, it is imperative for CIOs, CISOs, and other business leaders to diligently address basic areas of cybersecurity to avoid disruptions in their critical business operations.

KEEPING CYBER THREATS IN CHECK

Detecting covert cyber threats lurking in enterprise networks, and orchestrating a common cyber risk taxonomy are integral to an organization’s security blueprint. The first step in that direction is to strengthen data governance and accountability by building a centralized repository and consistent taxonomy to manage the cybersecurity areas of compliance, IT assets, IT policies, risks, and controls, as well as the relationships across these data elements. In addition, an integrated IT GRC solution can be leveraged as a strategic and operational tool to solve complex ransomware and cyber security challenges. The solution can help manage and mitigate IT security risks, vulnerabilities, and advanced attack threats by leveraging multiple threat modeling and risk assessment methodologies such as STRIDE, DREAD, and other approaches based on quantitative factors. Pre-built methodologies for IT risk assessments and threat assessments can help organizations improve visibility into the overall IT and cyber risk landscape. Organizations will also gain from pre-built integrations with leading threat feed providers. By consolidating “early warnings” or notifications from these trusted sources into a searchable database, users receive comprehensive details on each threat, CVE ID, source, affected technologies, controls, threat and patch records, and possible remediation mechanisms.

Using this data, users can automatically notify the responsible personnel to proactively address the threats before systems are compromised. A robust IT GRC solution can also help organizations integrate with patch management solutions, vulnerability scanning devices, and infrastructure management tools to centralize data and assets, classify critical assets, identify issues, and track the vulnerability remediation status on an asset-by-asset basis. The solution can serve as a repository of the latest patches released by various software vendors to mitigate specific vulnerabilities. This data will enable enterprises to prioritize the implementation of patches or workarounds based on the criticality of each asset.

The other benefit of an IT GRC solution is that it can serve as a path to organizational compliance with industry-standard cybersecurity regulations by standardizing and harmonizing control sets across multiple regulations. It can also provide a consolidated view of the status of compliance with cybersecurity standards through a detailed gap report of operating controls that have not been mapped to reference controls as prescribed by the standard. This report will enable organizations to take proactive steps towards closing compliance gaps. Visualization tools can help users manage and monitor threat and vulnerability trends, as well as the organization’s risk posture, and issues in real time. Configurable dashboards can also help the company view underlying risk data, and gain a complete understanding of the potential impact of these risks on the business.

KEY BEST PRACTICES

  • Manage software updates systematically

Update old software and ensure that patches are also updated to avoid any weak spots that can be exploited by hackers.

  • Assess and mitigate IT security risks

Align IT security operations with business priorities, and perform periodic IT risk assessments based on vulnerabilities, patch levels, and security policy reviews to ensure a higher state of readiness.

  • Ensure consistent compliance, privacy, and security

Establish security policies or protocols to prevent external threats, and proactively anticipate potential ransomware attacks.

  • Develop contingency plans with regular online backups

Identify the most critical assets, and implement strong periodic backup mechanisms (e.g. cloud-based backups).

  • Gather threat intelligence

Ensure prior intelligence on threats which can help in patching the vulnerabilities that are most likely to be exploited by cyber criminals.

SUMMARY

With ransomware and other cyber-attacks on the rise, it is of utmost importance that organizations of all sizes have the right detection and preventive techniques to proactively counter these attacks. Getting one’s basics right is the first step. A robust backup strategy, coupled with threat or risk assessments, and employee training can go a long way towards preventing cyber-attacks. These small investments can eventually save the organization tens of millions of dollars, as well as its reputation and brand.

By Vibhav Agarwal

Vibhav Agarwal

Vibhav Agarwal is the Director, Product Marketing at MetricStream.

Vibhav has 11+ years of progressive experience in Enterprise product marketing, sales management, ERP & CRM program planning and delivery, software vendor selection and implementation across Hi-Tech, Trading & Capital Markets and Internet domains. Worked extensively in various roles dealing with multinational conglomerates as well as mid-sized companies like Info Edge India, in deals ranging between 0.5-30 million USD. Exposure to all stages of product and IT applications, sales & marketing, product management, and enterprise implementations.

View Website
The Lighter Side Of The Cloud - Information Highway
The Lighter Side Of The Cloud - Surprise!
Cloud Marketing Professional
Protect Against Network Failures

Five Things Organizations Can Do To Protect Against Network Failures

Protect Against Network Failures It is no surprise that whenever there is an outage in a public or private cloud, ...
How prepared are you to overcome the misuse of AI

How prepared are you to overcome the misuse of AI

Overcome the Misuse of AI Have you ever considered that the AI system integrated into your organisation's computing infrastructure could ...
Malware Will Cripple Cloud And IoT Infrastructure If Not Contained

Malware Will Cripple Cloud And IoT Infrastructure If Not Contained

The Malware Cloud Concern This year we’ve had two cyber attacks in which malware was used to cripple government computer ...
Quantum Computing opens new front in Cloud!

Quantum Computing opens new front in Cloud!

Quantum Computing As the amount of data in the world is rapidly increasing, so is the time required for machines to ...
A Closer Look at the Hidden Costs of Collaboration Solutions

A Closer Look at the Hidden Costs of Collaboration Solutions

The Hidden Costs of Collaboration Solutions Collaboration technology is key to efficient communication and productivity for a dispersed and global ...
MarTech’s Fragmented Landscape is Failing Brand Marketers

MarTech’s Fragmented Landscape is Failing Brand Marketers

MarTech’s Fragmented Landscape Mapping the customer journey is one of the biggest strategic shifts currently underway in the marketing industry ...
Istio 1.0: Making It Easier To Develop and Deploy Microservices

Istio 1.0: Making It Easier To Develop and Deploy Microservices

With the recent availability of Istio 1.0 it is not surprising that it continues to capture much attention from the ...
Top 50 Cloud Hosting Services

Top 50 Cloud Hosting Services

The methodology behind our top 50 cloud list is based on several years of experience understanding and following who the key players are in the industry. Click to review the current top 50 and stay tuned for future discussion ...
12 Promising Business Intelligence (BI) Services For Your Company

12 Promising Business Intelligence (BI) Services For Your Company

Business Intelligence (BI) Services Business Intelligence (BI) services have recently seen an explosion of innovation and choices for business owners and entrepreneurs. So many choices, in fact, that many companies aren’t sure which business intelligence company to use. To help ...
15 Promising Cloud-Based Video Conferencing Services

15 Promising Cloud-Based Video Conferencing Services

Cloud Video Conferencing Services We have put together a compilation of some of the best cloud based conferencing services for businesses. The cloud video conferencing services market is expected to reach US$ 6.40 Billion by 2020 from the current $3.31 ...
Network Management Software Buyer Guide 2018

Network Management Software Buyer Guide 2018

This concise data-driven report covers the Network Management software landscape, as of August 2018. he 24-page report includes: Market Overview - Top 10 Network Management products in 2018, User reviews and vendor size data, In-depth look at the Top 3 ...
10 Prototyping Tools To Help Build Your Startup

10 Prototyping Tools To Help Build Your Startup

Prototyping Tools We are continuing this week by focusing on startup tools, tips and tweaks that will help you build, design, manage and market your way into the cloud based business that you want to be. Last week we offered a ...
8 Cloud Characteristics Every ERP System Needs

8 Cloud Characteristics Every ERP System Needs

ERP System Cloud-based ERP systems offer many benefits to a growing organization. And those benefits are catching on in a big way in recent years. In fact, according to the RightScale State of the Cloud 2016 Survey, which has collected ...