# Maximize your chance of ransomware recovery
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-10-12
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: Ransomware Recovery Plan: Protecting Your Business
Meta Description: Learn how to preserve systems, coordinate solutions, and call in forensics to rescue your company from ransomware attacks. Be prepared for cyber crises.
URL: https://financedigest.com/maximize-your-chance-of-ransomware-recoveryhtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/smart-city-and-wireless-communication-network-abstract-image-visual-internet-of-things-sbi-301984969-1-1736837583347-compressed.jpg)

_By **Stuart Davis,** Director of Incident Response Services,_ [_CrowdStrike_](http://www.crowdstrike.com/)

It’s happened. Intruders have broken through your defences into your organization’s cyber environment. The dreaded ransomware note is glaring at your IT manager. Panic ensues. The note is not only demanding a large [crypto payment](https://www.financedigest.com/why-are-companies-implementing-crypto-payments.html "Why are companies implementing crypto payments?"), but it is also threatening to leak your sensitive customer information and destroy your organization’s reputation. This is your short window to rescue your company. A well-formulated ransomware recovery plan can [save enterprises time and money and help them prepare for and respond to the next](https://www.financedigest.com/6-tips-to-save-money-on-your-next-used-car-purchase.html "6 Tips to Save Money on Your Next Used Car Purchase") attempt.

When a ransomware disaster beckons, every detail is critical in protecting the [business’ reputation and preserving the customer’s trust](https://www.financedigest.com/trusting-your-gut-how-to-harness-the-power-of-your-business-instincts.html "Trusting your gut: how to harness the power of your business instincts"). There is a [small window of opportunity](https://www.financedigest.com/a-missed-opportunity-research-reveals-that-while-small-finance-accounting-businesses-view-themselves-as-cost-savvy-most-arent-switching-water-suppliers-or-other-services.html "A missed opportunity: research reveals that while small finance & accounting businesses view themselves as cost-savvy, most aren’t switching water suppliers, or other services") to react during a breach, and it requires coordinated internal response efforts and swift decision making.

**Preserve systems**

After a [ransomware attack](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?"), every instinct and fibre in an IT manager’s body might be saying to disconnect the whole system, but in this case, the classic IT ‘fix’ of switching it off and on again can be incredibly counterproductive. Shutting down the [network will alert the threat actor that they have been detected](https://www.financedigest.com/closing-the-door-before-the-horse-bolts-developing-a-proactive-network-detection-and-response-ndr-strategy.html "Closing the door before the horse bolts: Developing a proactive network detection and response (NDR) strategy "). So, to prevent a game of “whack-a-mole” from ensuing, best [practice states that all systems should be kept online](https://www.financedigest.com/6-practical-tips-for-starting-an-online-business.html "6 Practical Tips for Starting an Online Business"). The attacker will probably compromise additional [systems to establish new forms of persistence](https://www.financedigest.com/emission-control-systems-market-to-increase-at-a-cagr-of-5-through-2021-to-2031-persistence-market-research.html "Emission Control Systems Market To Increase At A CAGR Of 5% Through 2021 to 2031: Persistence Market Research") that may go undetected or have already prepared backdoors for these situations.

Many targeted [data breaches](https://www.financedigest.com/10-steps-to-stop-lateral-movement-in-data-breaches.html "10 Steps to Stop Lateral Movement in Data Breaches") first occur months before threat actors demand any payment. This is why log data is often crucial in determining how the incident started. Without understanding how the event happened, a double ransom situation may likely take place. For example, [an organization](https://www.ncsc.gov.uk/blog-post/rise-of-ransomware) that did not identify the rotten roots of a previous attack experienced ransomware re-deployment and paid another ransom just two weeks later. So, it is vital that logs are preserved and that critical server backups are available for inspection.

**Coordinate solutions**

In a [time of cyber crisis](https://www.financedigest.com/decision-making-in-times-of-crisis-should-they-be-based-on-gut-feeling-or-data.html "Decision-making in times of crisis: should they be based on gut feeling or data?"), it is even more important that internal communications are well-established. IT, security, legal, [management and public relations must](https://www.financedigest.com/managing-mobility-in-the-enterprise-must-have-consideration.html "Managing mobility in the enterprise must have consideration") be kept informed of the status of the data breach to allow the formulation of a response and the communication with regulatory agencies as well as customers. But it is also important to note that threat actors are [skilled in espionage and it is likely that internal communication](https://www.financedigest.com/these-top-5-interactive-skills-will-ensure-well-become-better-communicators-in-2021.html "These top 5 interactive skills will ensure we’ll become better communicators in 2021") channels may be compromised. So, additional out-of-band communications should be established.

**Call in forensics**

Sophisticated threats require next-generation antivirus responses. Long gone are the days of legacy signature-based antiviruses. Deploying a cloud-based EDR [solution is essential to enabling security](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions") staff to detect, prevent, record, search in real-time and accelerate ransomware recovery time.

[Businesses need](https://www.financedigest.com/what-is-premises-liability-coverage-and-why-does-your-business-need-it.html "What is Premises Liability Coverage … and Why Does Your Business Need It?") to begin looking at a ransomware incident like a crime scene. Endpoint forensic investigations can help enterprises determine [key insights](https://www.financedigest.com/automotive-electronics-market-key-insights-profiling-companies-and-growth-strategies-by-2026.html "Automotive Electronics Market Key Insights, Profiling Companies and Growth Strategies by 2026 ") such as how many systems have been accessed or compromised, what data may have been accessed, how long the incident has been occurring, the initial attack vector, persistence mechanisms in your environment and exfiltrated data.

This [data is imperative to preventing another attack](https://www.financedigest.com/modern-data-protection-how-organisations-can-protect-against-cyber-attacks.html "Modern Data Protection: How organisations can protect against cyber attacks"). It also gives businesses the opportunity to re-evaluate their security infrastructure and policies, identify weak points and determine which [data requires the most amount of protection](https://www.financedigest.com/4-steps-you-should-be-taking-to-protect-data.html "4 Steps You Should Be Taking To Protect Data") going forwards.

**Remediate the attack**

The key goal of remediation is to completely remove the threat actor’s presence from the environment and [limit their ability](https://www.financedigest.com/lack-of-collaboration-and-skills-shortage-is-limiting-organisations-ability-to-meet-ifrs-9-requirements.html "Lack of collaboration and skills shortage is limiting organisations’ ability to meet IFRS 9 requirements") to return in another way. Remediation techniques can include isolating critical systems from the broader network, [blocking access](https://www.financedigest.com/russia-blocks-facebook-accusing-it-of-restricting-access-to-russian-media.html "Russia blocks Facebook, accusing it of restricting access to Russian media") to the adversary’s command and control infrastructure, removing and completely refreshing infected hosts and performing credential resets.

A key aspect of remediation and an effective incident response [plan is partnering with a proficient cybersecurity](https://www.financedigest.com/crafting-a-business-continuity-cybersecurity-plan.html "Crafting a Business Continuity Cybersecurity Plan") provider. Experienced [cyber intelligence professionals can provide a comprehensive approach that ensures no threat](https://www.financedigest.com/cyber-threats-for-finance-organisations-to-watch-in-2023.html "Cyber threats for finance organisations to watch in 2023") goes undetected in the environment, accelerate time-to-visibility and remediation, reduce business interruption losses and minimize cyberattack impact.

Ransomware preparation and cybersecurity awareness has become as necessary as [marketing or sales to businesses](https://www.financedigest.com/how-businesses-can-effectively-pivot-marketing-game-plans-for-christmas-2020.html "How businesses can effectively pivot marketing game plans for Christmas 2020"). It is [important to note that companies](https://www.financedigest.com/is-it-important-to-provide-media-coverage-for-your-company.html "Is it Important To Provide Media Coverage For Your Company?") should also evaluate their long-term cybersecurity goals along with immediate incident actions and responses. Preparing to prevent the next attack by having immaculate cybersecurity hygiene, carrying out ransomware tabletop training exercises and understanding [threat intelligence](https://www.financedigest.com/russian-threat-to-baltic-security-rising-estonian-intelligence-report.html "Russian threat to Baltic security rising – Estonian intelligence report") is as important as the incident response.

Following these steps may be the only [way you can mitigate the bleeding of valuable data](https://www.financedigest.com/three-ways-the-data-cloud-can-keep-financial-services-competitive.html "Three Ways the Data Cloud Can Keep Financial Services Competitive") and company assets. You [need](https://www.financedigest.com/british-pensions-step-up-multi-billion-pound-asset-fire-sale-as-need-for-cash-soars.html "British pensions step up multi-billion-pound asset fire sale as need for cash soars") to fight fire with fire. Don’t [bring a legacy antivirus to a sophisticated](https://www.financedigest.com/bequant-partners-zagtrader-bring-sophistication-traditional-finance-tools-cryptocurrency-market.html "BeQuant partners with ZagTrader to bring the sophistication of traditional finance tools to the cryptocurrency market") ransomware fight. [Investing wisely](https://www.financedigest.com/six-tips-for-saving-money-and-investing-wisely.html "Six Tips For Saving Money And Investing Wisely") and early will ensure that your company makes it through this ransomware pandemic.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

