# Ransomware in 2021 – the importance of a layered defence
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-09-08
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: The Evolution of Ransomware: A Growing Threat
Meta Description: Learn the crucial steps to defend against ransomware attacks and minimise disruption with a layered defence strategy, reducing your risk and potential
URL: https://financedigest.com/ransomware-in-2021-the-importance-of-a-layered-defencehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/attackmy0ekspd-1736837916760-compressed.jpg)

_By_ **_Adrian Moir,_** _principal technology evangelist, Quest_

Ransomware has been a topic of conversation for several years, but it’s been incredible to watch how this phenomenon has grown and shifted to where it is today.

In the US earlier this year we saw the issue reach epic proportions, with attacks against the Colonial Pipeline and JBS provoke an international political response and cause disruptions which were felt personally by millions of everyday citizens.

Here in the UK we had an early taste of the potential [human cost of ransomware as far back](https://www.financedigest.com/putting-the-human-touch-back-into-banking-magazine.html "“Putting the human touch back into banking”-Magazine") as 2017 with the WannaCry attack. Its most high profile victim was the NHS, and estimates put the number of cancelled hospital appointments at [over 19,000](https://www.itpro.co.uk/wannacry/32103/wannacry-cost-the-nhs-92-million-report-estimates). But ransomware has evolved since then – the size of the ransoms has [pushed the issue up the board’s agenda](https://www.financedigest.com/why-the-covid-19-pandemic-is-pushing-forward-the-esg-agenda.html "Why the COVID-19 pandemic is pushing forward the ESG agenda") and the attacks themselves have become much darker, manipulative and disruptive that before.

It used to be much simpler to deal with the ransomware strains and tactics of old: have a [business continuity](https://www.financedigest.com/crafting-a-business-continuity-cybersecurity-plan.html "Crafting a Business Continuity Cybersecurity Plan") strategy in place, good backups, and effective recovery processes in place, and you won’t have to pay any hackers a penny. These days though more and more businesses are [paying the ransom due to the increased sophistication and targeted nature](https://www.financedigest.com/best-paying-jobs-in-natural-gas-distribution.html "Best paying jobs in natural gas distribution") of the attacks. Even though the figures can sometimes be in the millions of dollars, [organisations wonder if cyber](https://www.financedigest.com/cyber-threats-for-finance-organisations-to-watch-in-2023.html "Cyber threats for finance organisations to watch in 2023") liability insurance is their best bet, or if simply paying the ransom is going to be the cheaper option due to the multiple angles of extortion that attackers can take.

Unfortunately with the current wave of ransomware, there is no silver bullet or answer of what you must do in these situations, but what is clear is that defence is still vitally important – once you’re hit with ransomware, there’s no [way around](https://www.financedigest.com/5-time-efficient-ways-to-travel-around-the-philippines.html "5 Time-Efficient Ways to Travel Around the Philippines") the fact that this is a dire situation – it will cost you money in some way, it will disrupt your services and could affect your company’s reputation.

An ounce of prevention is worth a pound of cure. It’s an inconvenient truth that most [ransomware attacks](https://www.financedigest.com/preventing-an-operationally-crippling-ransomware-attack-do-you-know-where-your-risk-exposure-lies.html "PREVENTING AN OPERATIONALLY CRIPPLING RANSOMWARE ATTACK – DO YOU KNOW WHERE YOUR RISK EXPOSURE LIES?"), whilst sophisticated in their targeting and planning, involve some form of basic security hygiene failings. Cybersecurity and business [leaders need](https://www.financedigest.com/leaders-recognise-the-importance-of-green-transport-at-cop27-but-we-need-data.html "Leaders recognise the importance of green transport at COP27, but we need data") to be opting for a layered defence, which reduces your attack surface, allows you to minimise disruption if possible, and may even bring down your cyber liability insurance premiums, if that’s the route you want to take.

**The 5 layers of ransomware protection:**

1. **End-user training:** It’s imperative to educate and train your userbase and let them know the risks. Educate them on the ways that ransomware [enters an organisation](https://www.financedigest.com/how-fs-organisations-can-enter-the-new-age-in-digital-banking.html "How FS Organisations Can Enter The New Age in Digital Banking") (i.e. downloads, files, fake websites, file sharing sites, phishing attacks to gain user details and credentials). [End users should also be made aware of physical opportunities](https://www.financedigest.com/with-the-end-of-easy-money-there-are-still-serious-opportunities-in-africa.html "With the end of ‘easy money’ there are still serious opportunities in Africa") for ransomware to enter the organisation. For example, there are known [cases of infected](https://www.financedigest.com/global-covid-19-cases-hit-250-million-eastern-europe-infections-at-record-levels.html "Global COVID-19 cases hit 250 million, eastern Europe infections at record levels") USB keys being left in car parks, office lobbies, etc. and being picked up by unsuspecting users who plug them into a laptop.
2. **Patching:** Keep your systems up to date. Don’t rely on remembering, or spreadsheets. [Automate the process](https://www.quest.com/products/kace-systems-management-appliance/patch-management-security.aspx). [Don’t leave](https://www.financedigest.com/finding-it-hard-to-recruit-good-it-security-managers-dont-leave-yourself-vulnerable-to-attack.html "Finding it hard to recruit good IT security managers? Don’t leave yourself vulnerable to attack") it to chance. Patch all machines, clients and servers.
3. **Not just Windows:** Don’t assume that this is just a “Windows thing.” Linux still has its threats, so keeping Linux servers updated is just as important.
4. **Network monitoring:** Make sure you monitor anything that looks like traffic interception. Re-routing, spoof apps and traffic re-direction are the starting point to gaining access to the wider organisational infrastructure with ‘Man in the Middle’ (MITM) attacks. A [successful attack on your Active Directory is like handing over the keys](https://www.financedigest.com/mvp-for-startups-the-key-to-success.html "MVP for startups: the key to success") to the castle to your worst enemy.
5. **Data protection:** Backing up your data seems obvious, right? Well, these are still servers, and they’re still running an [operating system](https://www.financedigest.com/robot-operating-system-market-is-witnessing-a-sustainable-growth-due-to-increase-in-demand-scrutinized-in-the-new-analysis.html "Robot Operating System Market is witnessing a Sustainable Growth Due to Increase in Demand Scrutinized in the New Analysis"), and it makes them just as vulnerable. Moreover, backup products that use network [shares to store backup data are at a higher](https://www.financedigest.com/european-shares-edge-higher-on-healthcare-lift-weak-china-data-stokes-worries.html "European shares edge higher on healthcare lift, weak China data stokes worries") risk, since network shares are a target for most ransomware.

**What about when Data Protection isn’t enough?**

All [things considered](https://www.financedigest.com/car-hire-for-smes-things-to-consider.html "Car hire for SMEs: Things to consider"), creating a layered defence is the only reasonable outcome that must be employed. Simply relying on a [data protection solution](https://www.financedigest.com/aon-introduces-new-cyber-solution-in-response-to-eu-regulation-on-data-protection.html "Aon introduces new cyber solution in response to EU regulation on data protection") as a prevention measure is not enough.

[Data protection](https://www.quest.com/solutions/data-protection/) is a reactive technology. You react to a need that requires [data to be recovered](https://www.financedigest.com/how-to-recover-deleted-files-using-easeus-data-recovery-wizard.html "How to Recover Deleted Files Using EaseUS Data Recovery Wizard?"). Data protection is carried out on a regular basis, or should be, to [mitigate against data](https://www.financedigest.com/how-financial-services-firms-can-mitigate-against-their-top-data-security-threats.html "How Financial Services Firms Can Mitigate Against Their Top Data Security Threats") loss. But this is only [effective if the solution provides methods to prevent loss of the backup data](https://www.financedigest.com/can-banks-compete-in-the-digitisation-race-without-effective-data-integrity.html "Can banks compete in the digitisation race without effective data integrity?") itself.

Consider for a moment what a backup solution must achieve: It must [move all your data from point A to point B as fast](https://www.financedigest.com/microsoft-unveils-ai-office-copilot-in-fast-moving-race-with-google.html "Microsoft unveils AI office copilot in fast-moving race with Google") as physics will allow. At least that’s what most people will look for. This necessitates that it has access to all of the [organisation’s important data](https://www.financedigest.com/tackling-the-complexity-of-data-within-financial-organisations.html "Tackling the complexity of data within financial organisations"), applications, network, production storage, etc. In fact, it has more access than most corporate users, except for domain administrators!

Yet, we still see [data protection solutions that are poorly secured](https://www.financedigest.com/assurance-v-security-reassessing-responsibility-for-data-assurance.html "Assurance v Security: Reassessing Responsibility for Data Assurance") with default usernames and passwords. Or these [data protection solutions use open shares](https://www.financedigest.com/chipmakers-weigh-on-european-shares-focus-on-u-s-jobs-data.html "Chipmakers weigh on European shares; focus on U.S. jobs data") that are just that: wide open. We’ve all done it. Selecting ‘Everyone’ as a permissions option is the easy [way to make something work](https://www.financedigest.com/five-ways-to-keep-your-head-above-water-while-working-from-home.html "Five ways to keep your head above water while working from home"), but that also creates one of the easiest entry points for ransomware.

**Preparing for the next chapter**

Following the recent spate of attacks, the [debate continues around](https://www.financedigest.com/uks-kwarteng-mini-budget-was-essential-in-resetting-debate-around-growth.html "UK’s Kwarteng: Mini budget was essential in resetting debate around growth") ‘what to do’ about the great ransomware problem. From suggestions of banning ransom payments, legislation on mandatory breach reporting, the role of cyber insurance amongst many other factors, there really is no [way to truly win, the best way is to try not to play the game](https://www.financedigest.com/is-regtechs-rise-one-way-tackle-the-international-regulatory-game-of-risk.html "Is Regtech’s rise one way tackle the international regulatory game of Risk?") in the first place. Although the big attacks make the headlines, the majority of ransomware attacks are smaller, they happen every day, and can be prevented or mitigated through a layered defence. We will no doubt see further evolutions in this great ransomware saga, but defence in layers will never go out of fashion.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

