How to Beat Ransomware
Ransomware is still one of the most common and costly attacks on small and medium businesses. Attackers encrypt a company's files, and increasingly steal them too, then demand payment to unlock them or keep them private. The question on everyone's mind is: what can we do to stop these attacks?
While there is no single answer that fits every business, there are certainly some basic steps everyone should take. Many attacks still start the same way the 2017 WannaCry outbreak did, which famously hit the UK's NHS: by exploiting a known vulnerability on a system that was never patched.
Keep systems up to date
In the WannaCry case, Microsoft had released a patch two months before the attack. Full stop. If you had an up to date system, and had your automatic updates turned on, it wouldn't have affected you. But then why, we ask, did it wreak so much havoc? Simply put, because there are many out of date systems still in operation. That may be an old, unsupported copy of Windows, or it may be that someone has turned off automatic updates. The same pattern repeats with nearly every major attack since.
Isolate older systems
Let's address the "old Windows" scenario. Many businesses and other institutions keep old versions of Windows around for various reasons. Older versions of Windows run many business critical machines such as CNC mills, and also shop floor computers for employee data entry. While these systems are out of date technologically speaking, they still fill a valid business purpose. However, they are often neglected by IT departments when in fact they should be given even more attention than other systems.
So, what's an IT department to do with these out of date systems? Of course, all the typical best practice stuff applies, such as having up to date virus protection and installing whatever application updates are available. Beyond that, there are some other steps that can be taken.
These computers should be isolated from the outside world (i.e., the Internet) as much as possible. Place them on a separate network (or VLAN) if possible, and do not allow any Internet access from them. Also, isolate them from other machines that do have Internet access. If, for example, a newer computer does get an infection, you don't want it to spread to these business critical computers. In cases where access to the computer from the larger LAN is necessary, route the traffic through a firewall which only allows as much access as needed.
A priority should also be placed on upgrading the operating systems on these machines if at all possible. Often this requires the application specific software to be updated as well, which is why it is also important to keep current with vendor maintenance agreements for software. The upgrade process is a far reaching one, and application vendors must be included in the conversation.
Turn on automatic updates
Once the OS is current (or if it was current to begin with), there is another critical protection: automatic updates. While some IT folks will freak out at the recommendation, we say the benefit far outweighs the risks. Occasionally an update causes problems for a few days, but overall they're not that bad. (Besides, isn't that what good backups are supposed to cover?) We'd be willing to bet that anyone infected with WannaCry would give anything to go back and undo the choice to turn off automatic updates.
Layer your defenses
Of course, having up to date systems is just a start. Today we consider these the baseline for any business:
- Multi-factor authentication on email, remote access and every cloud service
- Endpoint detection and response (EDR), which watches for suspicious behavior rather than only known viruses
- Good backups, with at least one copy that ransomware can't reach or alter, tested regularly
- User awareness training, since most ransomware still arrives through a phishing email or a stolen password
- Proper system isolation, so one infected computer can't reach everything else
We apply those and other concepts to our clients' systems and can boast that those who take our advice rest easy.