# How to press cancel on the threat of subscription-style ransomware services
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2022-11-22
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: Ransomware as a Service (RaaS): The Subscription Threat
Meta Description: Learn how criminals are now using subscription models to sell ransomware toolkits, posing a significant online threat in the UK. Stay informed and protected.
URL: https://financedigest.com/how-to-press-cancel-on-the-threat-of-subscription-style-ransomware-serviceshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/istock-693643766-1736814837567-compressed.jpg)

![](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/john-davis-1736814837539-compressed.jpg)

_By_ **_John Davis,_** _UK & Ireland Director, SANS Institute,_

We can now subscribe to any number of convenient services with the click of a button – from movies to music, dog food to diet supplements. Not to [miss an opportunity](https://www.financedigest.com/accountants-risk-missing-post-brexit-opportunities.html "Accountants risk missing post-Brexit opportunities") for easy cash, criminals are also turning to the subscription economy to sell their technical know-how. Ransomware as a Service (RaaS) now grants access to ransomware toolkits, presenting sophisticated attacks for purchase by amateur hackers.

Ransomware is now the most significant online [threat facing](https://www.financedigest.com/3-top-digital-asset-threats-facing-your-brand-in-2017.html "3 top digital asset threats facing your brand in 2017") the UK. Tactics have evolved from simple phishing missions to increasingly professional tactics using the latest ‘toolkit.’ Ransomware as a service (RaaS) now offers hackers a slice of the ransomware pie through fully baked [subscription models](https://www.financedigest.com/the-rise-of-the-subscription-model.html "The rise of the subscription model") marketed on the dark web, designed to appeal to a range of criminal clients.

With different levels, RaaS clients may purchase a single attack or sign up for the rough equivalent of a retainer relationship, [paying a monthly cryptocurrency fee for advice and assistance – even around-the-clock support](https://www.financedigest.com/supporting-apple-pay-integration-in-japan.html "Supporting Apple Pay Integration in Japan") for attacks and negotiations with a victim. The client may also share a portion of any payment extracted from a victim with the RaaS provider.

**RaaS providers wising up to detection methods**

As this model gains traction, more and more [ransomware attacks](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK –  DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?") are being carried out using the RaaS model, making it harder to track down assailants. However, attribution is possible. For example, clues such as snippets of malicious code may help authorities trace an attack [back to a perpetrator known to be running a RaaS operation](https://www.financedigest.com/ubisoft-vows-to-get-back-to-operating-margin-above-20-in-medium-term.html "Ubisoft vows to get back to operating margin above 20% in medium term"). Attackers, when caught, may give up relevant details. From the victims’ perspective, ransomware crimes appear the same, whatever the underlying organisational structure behind them might be.

RaaS [providers are wising up to these breadcrumbs and prefer keeping](https://www.financedigest.com/red-box-and-bloomberg-partner-to-provide-comprehensive-record-keeping-and-trade-reconstruction-services-for-financial-compliance.html "Red Box and Bloomberg Partner to Provide Comprehensive Record Keeping and Trade Reconstruction Services for Financial Compliance") the client at arm’s length to avoid detection and prosecution. Indeed, it can be harder to prosecute RaaS than conventional ransomware attacks because there are more moving parts, and they may move in several jurisdictions governed by competing laws and authorities. The advent of RaaS and ransomware, generally, have increased the impetus to harmonise regulations and foster law enforcement cooperation in this area.

What IaaS and RaaS providers do have in common is that the latter [increasingly are conducting business](https://www.financedigest.com/seventy-three-percent-of-the-c-suite-state-that-increasing-visibility-into-network-and-application-performance-will-drive-business-innovation.html "Seventy-Three percent of the C-suite state that increasing visibility into network and application performance will drive business innovation ") with the former – taking advantage of the economics of cloud-based computing and storage the same way their victims do. The participation of most IaaS companies is usually unintentional, and the desire to maintain their clients’ [data security](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") – and their own reputations for safety – makes legitimate IaaS providers a formidable ally in the war against ransomware and RaaS providers.

Just as in legal and commercial undertakings, ransomware skills are continually honed, and standards are elevated through competition. As RaaS providers raise their game, the [stakes for potential targets are also raised](https://www.financedigest.com/chinas-tencent-raises-stake-in-assassins-creed-maker-ubisoft-2.html "China’s Tencent raises stake in ‘Assassin’s Creed’ maker Ubisoft"). The threats they face will be more acute, at least until [cybersecurity professionals and law enforcement raise their game and improve their methods for combating threats](https://www.financedigest.com/forescout-and-fireeye-expand-partnership-enabling-faster-response-to-cybersecurity-threats.html "FORESCOUT AND FIREEYE EXPAND PARTNERSHIP, ENABLING FASTER RESPONSE TO CYBERSECURITY THREATS").

**Securing strong foundations of defence**

Despite numerous high-level warnings about the escalating ransomware threat, many [organisations are taking a dangerously reactive approach](https://www.financedigest.com/cloud-migration-for-financial-services-organisations-whats-the-best-approach.html "Cloud Migration for Financial Services Organisations – What’s the best approach?") to security. However, taking a proactive stance on cyber [protection should now be considered a foundation of any organisation](https://www.financedigest.com/protect-your-organisation-from-fraud.html "Protect your organisation from fraud") – large and small. The Centre for Internet [Security has shared 18 common-sense Critical Security Controls to defend](https://www.financedigest.com/how-financial-services-are-overhauling-security-to-defend-against-spoofing-scams.html "How financial services are overhauling security to defend against spoofing scams") against attacks, including those sourced through RaaS, and mitigate damage should one occur. There is much overlap among the 18, allowing them to be grouped into four broad measures

- **Take inventory of your electronic assets.** You can’t protect what you don’t know you have. Take stock of all fixed, portable, or [mobile devices](https://www.financedigest.com/emvco-streamlines-approval-process-for-mobile-payment-devices.html "EMVCo Streamlines Approval Process for Mobile Payment Devices") that can connect to your technology platforms physically or remotely. This will allow you to spot unauthorised or unmonitored devices and [remove them or make them secure](https://www.financedigest.com/fintechs-must-remove-security-and-compliance-friction-to-unlock-new-growth.html "Fintechs Must Remove Security and Compliance Friction to Unlock New Growth"). Do the same with [software assets](https://www.financedigest.com/why-a-modern-organisation-needs-an-agile-approach-to-software-asset-management.html "Why a modern organisation needs an agile approach to software asset management"), including operating systems, programs, and apps. Review credentials and permissions for each employee, and limit access, via your organization’s and your employee’s personal devices, on-premises and remote, to files, folders, apps, programs, and external websites to those that are appropriate for their duties and no others.
- **Monitor access points.** Your infrastructure is most at [risk](https://www.financedigest.com/france-seeks-strategy-as-nuclear-waste-site-risks-saturation-point.html "France seeks strategy as nuclear waste site risks saturation point") of a breach at the points where it meets the outside world. Enhance malware detection and defense techniques, focusing particularly on these points and the means through which a breach is most likely to occur, such as web links and emails. This, plus a rigorous permissions regime, could prevent a considerable expenditure of [time and money if Dave from accounting](https://www.financedigest.com/its-time-for-real-time-accountancy.html "It’s time for real time accountancy ") decides to click on the wrong Pornhub banner ad when he is supposed to be processing invoices.
- **Anticipate vulnerabilities and respond to threats.** Vulnerabilities can be limited but never eliminated, so you should prepare for the worst to ensure the [impact is not as bad as it might](https://www.financedigest.com/brexit-might-impact-our-migrant-pool-magazine.html "“Brexit might impact our migrant pool.”-Magazine") be. Use industry resources to stay aware of the latest threats and ensure that your operating [system and other software are updated](https://www.financedigest.com/a-fast-track-route-to-updating-legacy-system-code.html "A Fast-Track Route to Updating Legacy System Code"), and patches applied when available.  The most significant vulnerability is reusable passwords. Most [financial services](https://www.financedigest.com/the-future-of-financial-services-tech-evolution-not-revolution.html "The future of financial services: Tech evolution not revolution ") now require Multi-factor Authentication (such as text messages sent to the user’s registered mobile phone number) for login. Using this simple form of MFA stymie’s over 99% of all phishing attacks.
- **Make the most of your human assets.** Some vulnerabilities within an organisation may walk on two legs and draw a paycheck, like Dave from accounting. If properly trained and prepared, however, your employees can be an additional factor to aid in thwarting attackers. Their understanding of and reaction to ransomware attacks and other [threats should be evaluated and sharpened through the development of security](https://www.financedigest.com/5-ways-to-protect-your-company-from-cyber-security-threats.html "5 Ways to Protect Your Company From Cyber Security Threats") awareness programs that work to change user behaviour when presented with a bogus email or web page.  There should be simulations of threat scenarios to put these procedures and your employees’ preparations – and those of [senior management](https://www.financedigest.com/senior-managers-regime-what-does-it-mean-for-the-industry.html "SENIOR MANAGERS REGIME – WHAT DOES IT MEAN FOR THE INDUSTRY?") and security officials – to the test.
- **[Invest in your security team’s skills](https://www.financedigest.com/quantamental-investment-trends-to-make-profits-through-creative-skills.html "Quantamental Investment Trends to Make Profits Through Creative Skills") and tools –** there is a lot of press hype about a “cybersecurity staffing shortfall,” but successful security organisations have found that there is more of a skills gap than a headcount shortfall. By upskilling security analysts in critical areas such as cloud security, purple teaming, and [machine learning](https://www.financedigest.com/machine-learning-engineer-jobs.html "Machine learning engineer jobs"), you get a double benefit: the need for additional staff is reduced, and surveys show that security staff that gets regular training are less likely to jump to another company for a salary increase and expensive attrition is reduced.

**Support to** [stay one step ahead](https://www.financedigest.com/staying-ahead-of-risk-this-black-friday.html "Staying Ahead of Risk This Black Friday")

Organisations grapple with numerous business-critical issues, from soaring energy prices to talent gaps and [supply chain](https://www.financedigest.com/how-to-bring-immediacy-back-to-the-supply-chain-with-faster-payments.html "How to Bring Immediacy Back to the Supply Chain With Faster Payments") risks. Amid these challenges, criminals are keen to exploit any gaps in defences. Where eyes are turned away from cyber resilience, a [data breach is increasingly just a matter of time](https://www.financedigest.com/decision-making-in-times-of-crisis-should-they-be-based-on-gut-feeling-or-data.html "Decision-making in times of crisis: should they be based on gut feeling or data?"). Taking proactive steps, with the support of experts who can keep you one [step ahead of criminal innovations will give your organisation](https://www.financedigest.com/6-steps-to-organising-an-introvert-friendly-networking-event.html "6 Steps to organising an introvert-friendly networking event ") the proactive resilience it needs to unseat subscription-style cyber attacks.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

