In-depth

How can you protect your business from crypto-ransomware?

Here are some easy-to-apply rules to help keep your data - and your business operations - safe

Crypto-ransomware, also known as cryptors, is a specific type of ransomware where the files and data that are stored on the infected device are encrypted into an unreadable form. This means the data can only be decrypted by using the necessary decryption key, which is only released by the criminal after the victim has paid the ransom demand.

Consumers affected by crypto-ransomware are usually faced with demands of 250 to 500, but ransom charges for businesses can be much higher as cybercriminals understand just how valuable data can be. If the ransom goes unpaid, the price will steadily increase until the decryption key is deleted, making it virtually impossible to recover the files. But even if a ransom is paid, there's no guarantee the data will be decrypted.

A recent report from Chubb has revealed that ransomware attacks for 2019 have already outpaced the total number of incidents in 2018. Although any company can be affected by ransomware, professional and financial services are a particularly attractive target. 

"Some ransom demands have grown to the six- and seven-figure range," said Michael Tanenbaum, Head of Chubb Cyber North America. "It is critical for businesses to understand the increased sophistication of ransomware, what procedures and systems need to be in place to mitigate the risk, and what solutions they need to protect themselves should they experience an attack."

A temporary loss of data can disrupt business-critical processes, and could lead to lost sales, reduced productivity and significant costs for system recovery. However, the permanent loss of data can have much more severe consequences, from damaging the company's competitive position to preventing access to intellectual property and design data.

In common with most other types of malware, there are many ways in which a cryptor can find its way onto business computers and other devices. Here are some easy-to-apply rules to help keep your data - and your business operations - safe.

Educate users:

People are often the most vulnerable element in any business. Teach employees about IT security basics, including raising awareness of phishing and spear-phishing attacks. Emphasise the security implications of opening suspicious-looking email attachments, even if it appears to be from a trusted source.

Security awareness training programmes can be a good way of ensuring employees are aware of the latest threats, and to keep security front-of-mind for staff.

Related Resource

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now

Regularly back up data:

The best way to keep business data safe is by backing up systems regularly. With a good backup system, a ransomware attack won't have a catastrophic effect on business continuity.

Almost all businesses will already have data back up policies. However, it's also essential to back up data onto an offline backup system, rather than just copying files to another live' system on a corporate network. Establishing a back up and disconnect' policy will help keep backup files safe from cryptors.

Protect all devices and systems:

Cryptors don't just attack PCs. Business security software must also be able to protect Mac computers, virtual machines and mobile devices. It is also worth ensuring there is sufficient protection installed on the organisation's email system.

But as well as protecting devices and internal systems, it's also important to make sure that third-party applications are updated as well. Hackers can easily leverage a vulnerability in a popular application to breach your network and start infiltrating other systems.

Deploy and maintain security software:

As with all malware prevention, updating and patching early and often is a valuable policy to follow. Updating all applications and operating systems will allow elimination of newly discovered vulnerabilities, and ensuring security applications and anti-malware databases are up-to-date will enable the business to benefit from the latest protection.

Featured Resources

Humility in AI: Building trustworthy and ethical AI systems

How humble AI can help safeguard your business

Download now

Future of video conferencing

Optimising video conferencing features to achieve business goals

Download now

Leadership compass: Privileged Access Management

Securing privileged accounts in a high-risk environment

Download now

Why you need to include the cloud in your disaster recovery plan

Preserving data for business success

Download now

Recommended

Best ransomware removal tools
ransomware

Best ransomware removal tools

17 Nov 2020
IBM: Hackers are targeting COVID-19 vaccine 'cold chain'
Security

IBM: Hackers are targeting COVID-19 vaccine 'cold chain'

3 Dec 2020
New Trickbot variant can interfere with UEFI and BIOS
malware

New Trickbot variant can interfere with UEFI and BIOS

3 Dec 2020
GitHub: Open source vulnerabilities can go undetected for four years
Security

GitHub: Open source vulnerabilities can go undetected for four years

3 Dec 2020

Most Popular

Samsung Galaxy Note might be discontinued in 2021
Mobile Phones

Samsung Galaxy Note might be discontinued in 2021

1 Dec 2020
Black Friday's best antivirus deals
Security

Black Friday's best antivirus deals

27 Nov 2020
350,000 Spotify users hacked in credential stuffing attack
Security

350,000 Spotify users hacked in credential stuffing attack

24 Nov 2020