Ransomware is a type of malware that encrypts an organization’s data and demands payment as a condition of restoring access to that data. Ransomware can also be used to steal an organization’s information and demand additional payment in return for not disclosing the information to authorities, competitors, or the public. Ransomware attacks target the organization’s data or critical infrastructure, disrupting or halting operations and posing a dilemma for management: pay the ransom and hope that the attackers keep their word about restoring access and not disclosing data, or do not pay the ransom and attempt to restore operations themselves.
A Ransomware Profile (NISTIR 8374) has been recently published by NIST. This Ransomware Profile identifies the NIST CSF’s security objectives that support identifying, protecting against, detecting, responding to, and recovering from ransomware events. The profile can be used as a guide to manage the risk of ransomware events. Even without undertaking all of the measures described in this Ransomware Profile, there are some basic preventative steps that an organization can take now to protect against and recover from the ransomware threat. These in summary, include:
Educate employees on avoiding ransomware infections:
Avoid using personal websites and personal apps – like email, chat, and social media – from work computers.
Make it harder for ransomware to spread:
Make it easier to recover stored information from a future ransomware event:
Stay healthy, stay secure!