WannaCry notification - How to Protect Your Business From Ransomware

Ransomware is growing at a exponential rate and is affecting businesses of all sizes and Industries.  Below we share some information on how to protect your business from ransomware attacks.

One such Ransomware variant was WannaCry. It exploited a weakness in Microsoft SMB File Sharing Service.  The NSA exploited this Weakness and developed “EternalBlue” allowing them to Hijack and spy on Targeted Computer Networks.  These tools were stolen, then leaked and published on the internet allowing Cyber Criminals to create “WannaCry” that exploited a Microsoft Vulnerability for all versions prior to Windows 10.

The effectiveness of this ransomware is extreme as it performs the following actions

  • It scans All mapped Drives, encrypting Files (including OneDrive, Dropbox etc)
  • Deletes VSS Shadow Copies to prevent recovery from previous file versions
  • Installs Tor (Dark Web) as a proxy to preserve Anonymity
  • Deploys tools to scan public IP Networks to seek new targets

Put more simply, once inside the system WannaCry ransomware creates encrypted copies of specific file types before deleting the originals, leaving you only with the encrypted copies, which can’t be accessed without a decryption key. We have also heard that in some situations, WannaCry has progressively increased the ransom amount, and threatens loss of data at a predetermined time, creating a sense of urgency and greatly improving the chance that you will pay the ransom.

But don’t feel you’re the only one who was left unprotected, 10 Separate Industries were affected and over 100 large global corporate companies were impacted, as the most effective part of Wannacry was that “No User Interaction” was required to execute this malware.

The scars of Wannacry have not healed yet, and there is always a new ransomware attack being announced to haunt businesses.  Understanding a new ransomware is being unleashed everyday, small, medium and enterprise businesses need to realise the urgency for an effective business continuity solution to protect their most important asset, their data….

How do we protect ourselves from Ransomware?

Make sure that you:

  • Utilise Anti-Virus and Malware protection software
  • Patch your Systems regularly
  • Monitor your Systems
  • Enforce Strong IT Policy (Password Changes, Use of Admin Accounts etc)
  • Educate your Staff
  • Use an Intelligent Business Continuity Solution that
    • Backs up your Data as Frequently as possible (Multiple times per day)
    • Uses Advanced Verification Processes to test the backups
    • Tests your Backups for Ransomware
    • Uses a Hybrid Cloud Solution for storage of Backups (Local & Cloud)
    • Able to Instantly Virtualise a server from Backup

