{"id":5815,"date":"2020-10-20T18:46:51","date_gmt":"2020-10-20T16:46:51","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=5815"},"modified":"2020-10-20T18:46:53","modified_gmt":"2020-10-20T16:46:53","slug":"how-to-prevent-ransomware-with-smart-it-operations","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/how-to-prevent-ransomware-with-smart-it-operations\/","title":{"rendered":"How to prevent ransomware with smart IT operations"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>Whatever you do: Don&#8217;t pay the ransom. Learn how the right tools and procedures can enable IT ops admins to prevent, mitigate and recover from a ransomware attack.<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/kirsch_brian.jpg\" alt=\"Brian  Kirsch\"\/><\/figure>\n\n\n\n<p>By <a href=\"https:\/\/www.techtarget.com\/contributor\/Brian-Kirsch\">Brian Kirsch<\/a><\/p>\n\n\n\n<p>When it comes to ransomware attacks, IT operations plays a big role alongside security experts. They identify, prevent and &#8212; if all else fails &#8212; mitigate the effects of ransomware.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>A strong IT operations team is a weapon in security&#8217;s arsenal, along with widespread\u00a0security awareness\u00a0across all employees &#8212; in and out of IT. The IT team can prevent ransomware with regular patching and software updates, reduce the effect of an attack with good and frequent backups, lead the recovery to get systems up and running, and\u00a0analyze logs\u00a0to gain insights on the attack.<\/p><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Keep software and systems up to date<\/strong><\/h3>\n\n\n\n<p>One of the best ways to fight ransomware is prevention. IT teams must keep software and firmware up to date and install patches to prevent\u00a0vulnerabilities. The IT operations team should work with security on system updates. Security teams can advocate for updates and keep track of vendor bulletins, while IT operations implements changes and tracks systems history.<\/p>\n\n\n\n<p>Because these teams are separate groups in many companies, communication and coordination can be difficult. The security team should scan for new threats and issues and alert IT operations to required updates and their priority level. Ensure that IT operations manages\u00a0patching\u00a0activities. They should analyze all changes to IT systems to estimate the scope of downtime and any other effects from these updates, such as broken dependencies from new software versions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Get to know ransomware<\/strong><\/h4>\n\n\n\n<p>Ransomware is one of the many kinds of malware that infect corporate endpoint computers and servers. Ransomware takes control of data &#8212; typically by encrypting files &#8212; until the company pays the attackers to release it. Ransomware does not destroy data, as other types of attacks do. Also unique to ransomware, attackers alert their victim to the attack. High-profile ransomware attacks include 2017&#8217;s\u00a0WannaCry\u00a0and\u00a0Bad Rabbit\u00a0outbreaks.<\/p>\n\n\n\n<p>Workers can spread ransomware by opening email attachments or other infected downloads. It also can infiltrate a business through infected software, falsified OS messages and other means. Data center servers hosting mission-critical applications are lucrative targets for a ransomware attacker.<\/p>\n\n\n\n<figure class=\"wp-block-embed-youtube wp-block-embed is-type-video is-provider-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"What is Ransomware? How Does Ransomware Work?\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/fls3dTUqkOE?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Maintain backups and testing plans<\/strong><\/h3>\n\n\n\n<p>The better your organizations backups are, the less power ransomware attackers have. Backups should have much higher priority in IT than they often receive.\u00a0<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>Weak backup policies\u00a0give ransomware the power to devastate an organization: With limited or no ability to restore systems, the business must engage with the ransomware attacker. <\/p><\/blockquote><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>While backups cannot prevent a ransomware attack, they can restore the data held hostage with minimal &#8212; or no &#8212; disruption or\u00a0money lost.The best defense against ransomware is solid IT admin work.<\/p>\n\n\n\n<p>IT operations teams should commit backups at an appropriate frequency for business workloads and data. Additionally, they should have a system restore plan in place and test it frequently. Testing doesn&#8217;t need to run through the full disaster recovery playbook. Instead, test the backup repository weekly with restores from a random sampling of servers. This routine operation helps ensure that backups are valid and available.<\/p>\n\n\n\n<p>Additionally, coordinate backups with updates and patches. IT operations and security teams should review which endpoints and systems have updates available and set smart backup schedules.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Lead the response<\/strong><\/h3>\n\n\n\n<p>In the event of a successful ransomware attack, the company is in a race to understand the ransomware&#8217;s area and depth of effect &#8212; as well as its data recovery options.<\/p>\n\n\n\n<p>Because ransomware is an attack, security teams assume they should handle the\u00a0incident response communication\u00a0and coordination. However, the IT operations team possesses the knowledge and access to keep systems online or bring them back to working order. Many enterprise applications are\u00a0distributed across multiple environments, which complicates efforts to map an attack and its recovery. For ransomware attacks, IT operations should lead the response and bring in security for support.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/security-ransomware_incident_response_plan_steps-f.png\" alt=\"\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Collect logs<\/strong><\/h3>\n\n\n\n<p>After ransomware recovery, the security and IT operations teams should work together to understand what happened &#8212; and how &#8212; during the attack. IT operations should collect evidence in the form of logs and other monitoring information from affected systems.<\/p>\n\n\n\n<p>Look for log data that shows how the system got infected in the first place. Then, determine what changes will prevent future ransomware success. Recovered systems are just the start &#8212; a ransomware response must leave the IT environment safer than it was before.<\/p>\n\n\n\n<p>Because ransomware threatens the\u00a0business&#8217;s data\u00a0deliberately, many believe the fight against it is solely the security team&#8217;s responsibility. But the best defense against ransomware is solid IT admin work. IT operations team members are subject matter experts on applications, infrastructure and support. Pair the security team&#8217;s tools to identify, track and neutralize threats with the IT operations teams&#8217; maintenance expertise for strong ransomware prevention and recovery.<\/p>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>Whatever you do: Don&#8217;t pay the ransom. Learn how the right tools and procedures can enable IT ops admins to prevent, mitigate and recover from a ransomware attack. By Brian Kirsch When it comes to ransomware attacks, IT operations plays a big role alongside security experts. They identify, prevent and &#8212; if all else fails &#8212; mitigate the effects of<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/how-to-prevent-ransomware-with-smart-it-operations\/\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[104,8,19,4,5,30,3],"tags":[],"class_list":["post-5815","post","type-post","status-publish","format-standard","hentry","category-application-maintenance-on-production-systems","category-data-center-hardware","category-data-centre-servers","category-datacenter-news","category-engage-the-experts","category-expert-advise-and-opinion","category-industry-news-and-expert-advise"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5815","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=5815"}],"version-history":[{"count":1,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5815\/revisions"}],"predecessor-version":[{"id":5816,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/5815\/revisions\/5816"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=5815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=5815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=5815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}