When it comes to ransomware, it’s a matter of when, not if, an organization will be impacted. Effective cyber recovery requires a focus on protecting your assets and data, intelligence to understand when threats are present and what data is affected, and the ability to restore extremely large amounts of data as quickly as possible. Here are some commons questions about how to prepare for ransomware.
What are some best practices to implement ransomware prevention?
Unternehmen sollten die folgenden wesentlichen Maßnahmen ergreifen, um ihre Mitarbeiter und ihre Geräte vor Ransomware und böswilligen Handlungen zu schützen:
- Installieren Sie regelmäßig Software-Updates und Patches, sowohl auf einzelnen Computern als auch auf IT-Geräten.
- Führen Sie regelmäßig Sicherungen aller Daten durch und befolgen Sie dabei das 3-2-1-Prinzip:
- Erstellen Sie 3 Kopien der Daten,
- auf zwei verschiedenen Datenträgern,
- And 1 of those copies should be offsite and immutable, so it can’t be modified or deleted.
- Limit user access to systems to reduce the risk of accidental or intentional modifications.
Cloud offers capabilities including role-based access control, auditing, integration with customer-owned authentication technologies like SAML, and encryption of all intra-service communications and data during transmission to securely handle customer data.
Additionally, all backup data is compressed, deduplicated, and encrypted by default from the source, on the network, and at rest. Compression and deduplication also obfuscate data, providing additional security if the backup storage is compromised. Learn more about the Aspekte der Cyber-Resilienz gegen Ransomware von A bis Z.
What are some everyday prevention measures for IT to deliver to our employees to prevent attacks?
Unternehmen sollten ihre Mitarbeiter über die Risiken von Ransomware aufklären und ihnen vermitteln, worauf sie bei unaufgeforderten E-Mails und SMS achten müssen. Online-Schulungen können sehr effektiv sein, um Beispiele zu veranschaulichen.
Auf persönlicher Ebene sollten Sie wissen, worauf Sie achten müssen, und Vorsichtsmaßnahmen treffen:
- Verwenden Sie die Multi-Faktor-Authentifizierung, um Ihre Identität bei der Anmeldung zu bestätigen.
- Setzen Sie geeignete E-Mail- und Endgerätesicherheitsmaßnahmen ein, um Malware oder Phishing-Versuche abzuwehren.
- Überprüfen Sie Links sorgfältig, indem Sie mit der Maus darüberfahren, ohne darauf zu klicken, um sicherzustellen, dass die URL sicher ist.
These are just the basics, and it’s important for each of us to do our part to protect ourselves and our organizations from being affected by an attack.
How can we proactively detect ransomware incidents within our organization?
To identify ransomware proactively, you should implement threat detection tools as part of your environment’s defenses. Commvault turns the tables on attackers, applying advanced forensics and generative AI to accelerate threat detection and response. We start with our Zero-Trust Architecture, with key features such as multi-factor authentication, multi-person authorization, SAML, privilege access management, and role-based access controls. Commvault® Cloud includes intelligent monitoring and risk identification to deceive and flag threats early in the attack lifecycle, along with cyber deception for early warning into ransomware and malicious intent. Gain insights into trends and user behaviors to detect anomalies before they spread.
Can we detect ransomware attacks beyond the endpoint?
With endpoint protection, businesses can implement comprehensive data backup and recovery protection for data at the edge. But it’s important to obtain insights throughout your SaaS and hybrid cloud environments. Without protection for SaaS data, applications, and endpoints, the risk of data loss or attacks such as corruption, accidental deletion, and malicious attack is substantial.
Be prepared to block ransomware with early detection and rapid response initiatives. Commvault provides intuitive tools and advanced insights so you can spot risks in real-time and limit exposure to ongoing cyberthreats. With our hardened, multi-layered approach to ransomware readiness, you’ll have robust controls to help prevent threats and enable data to be recoverable from a cyberattack. Using immutable, air-gapped data copies, advanced anomaly detection, and built-in encryption, Commvault Cloud gives you the tools to safeguard critical data across apps, endpoints, and hybrid cloud environments.
What do I do if I believe my system has been infected by ransomware?
Isolieren Sie das Problem, um eine weitere Ausbreitung zu verhindern, und beginnen Sie so schnell wie möglich mit der forensischen Analyse. Idealerweise richten Sie einen sauberen und sicheren Ort ein, um die Situation zu bewerten und die Auswirkungen auf das Unternehmen so gering wie möglich zu halten.
Commvault Cloud® Cleanroom™ Recovery offers a cost-effective and flexible way to create a secure, isolated environment to recover your organization’s data and applications when a breach occurs. Cleanroom Recovery can be used to conduct forensic analysis of known infected systems and identify the root cause of an attack. It also can help reduce downtime and accelerate recovery with a streamlined process for testing, analyzing, and restoring both data and applications to get back to a production-capable environment.
How long does the recovery process take?
One Analyse found that 24 days was the average reported time to recover from a cyberattack in the United States in 2022. Recovering from a cyberattack typically requires forensic investigation and remediation to be completed first, which can delay the actual recovery of data and restoration of normal business activity. It’s important to verify that data is free from infection before it is released back into the production environment.
Cyber readiness requires a broader outlook on system and data recoverability across all your infrastructure and processes. The ability to respond and recover quickly depends on being prepared with an incident response plan and the appropriate platform that incorporates data protection, threat detection and prevention, and isolated environments for safe restoration. This shift is essential in today’s threat landscape, emphasizing recovery as well as protection and integrity.
To reduce the amount of time it takes to nach einem Ransomware-Angriff, you’ll need to define your cyber resilience strategy. When you establish a thorough recovery plan, regularly test to verify that the plan works, and have confidence that you can successfully deploy it when needed, you’ll be able to respond to an attack and recover from it much faster.
Commvault’s Cloudburst™ Recovery capability can help you improve business continuity by using infrastructure-as-code to automate rapid and frictionless recovery of data, enabling mass recovery from cloud storage at scale with the highest speed possible. Through the breadth of the Commvault Cloud offerings, you can leverage unlimited scale, sophisticated layered security, and simple management to keep your organization protected now and in the future.
How do I best evaluate my current ransomware prevention strategy?
Earlier this year, Commvault gemeinsam mit GigaOm to conduct a survey on cyber recovery readiness and resilience with 1,000 security and IT leaders. This collaborative study offers a worldwide view into the challenges of cyber readiness postures and identifies effective strategies that you can use to enhance your recovery readiness plans.
To make things more actionable, we identified these 5 practices and capabilities that have an outsized impact on resilience. We call them the cyber readiness maturity markers, and as you can expect, the more you have, the more mature and prepared you are to respond to a ransomware incident.
Let’s step through each of these:
Sicherheitstools, die eine frühzeitige Warnung vor Risiken, einschließlich Insiderrisiken, ermöglichen
Zunächst einmal handelt es sich bei Sicherheitswerkzeugen zur Frühwarnung um Technologien und Systeme, die darauf ausgelegt sind, potenzielle Cyberbedrohungen zu erkennen, bevor diese erheblichen Schaden anrichten können. Diese Werkzeuge zielen darauf ab, Risiken so früh wie möglich zu identifizieren, damit Unternehmen proaktiv statt reaktiv reagieren können. Beispiele hierfür sind Intrusion-Detection-Systeme, Täuschungstechnologien, Intrusion-Prevention-Systeme, Sicherheitsinformations- und Ereignismanagement, Verhaltensanalysen von Benutzern und Entitäten sowie Endpunkt-Erkennung und -Reaktion.
Ein bekanntermaßen sauberer dunkler Standort oder ein sekundäres System vor Ort
Second, it’s important to maintain an isolated, pre-configured, or dynamic recovery environment (such as a cleanroom) that remains unaffected by cyber incidents at the primary site. This secondary site can be quickly activated for continuous business and data integrity in a cyberattack or major failure. It enhances cyber resiliency by providing a secure failover option, minimizing downtime and complexities of failover.
Eine isolierte Umgebung zur Speicherung einer unveränderlichen Kopie der Daten
Third, you should maintain a separate, air gapped (that is, immutable and indelible) copy of your data – secured behind a third party’s infrastructure. The data remains unchanged and protected from cyber threats, including ransomware and malicious insider actions. It enhances data integrity and availability, providing a reliable recovery option in case of data corruption or loss.
Definierte Runbooks, Rollen und Prozesse für die Reaktion auf Vorfälle
Viertens handelt es sich hierbei um eine entscheidende Fähigkeit für eine strukturierte und effiziente Reaktion auf Cybervorfälle. Erprobte Runbooks enthalten Schritt-für-Schritt-Anleitungen für den Umgang mit verschiedenen Arten von Vorfällen, wodurch Verwirrung vermieden und die Reaktionszeit verkürzt wird. Klar definierte Rollen und Prozesse sind von entscheidender Bedeutung, damit jedes Teammitglied seine Aufgaben kennt und so ein koordiniertes Vorgehen gefördert wird. Diese Vorsorge beschleunigt die Recovery und trägt dazu bei, die Betriebskontinuität während und nach Cybervorfällen aufrechtzuerhalten.
Spezifische Maßnahmen zum Nachweis der Bereitschaft und des Risikos zur Wiederherstellung des Cyberspace
And last, but not least, establish metrics and tests that demonstrate your organization’s ability to recover from cyber incidents and assess associated risks. These measures, such as regular recovery drills and risk assessments, provide insight into the effectiveness of your recovery plans and identify potential vulnerabilities. They are essential for cyber resiliency.
Are you ready to build your cyber recovery plan?
This is how you can be ready to recover from ransomware. Being ready for recovery means your teams have the confidence and the ability to quickly recover all data and applications across your environment, including physical servers, virtual machines, and your various cloud platforms. If you’re interested in seeing the full Cyber Recovery Readiness Report, you can die PDF-Datei herunterladen.
Ready to learn more about the Commvault Cloud platform? Demo anfordern to see it in action and discover how you can respond to ransomware.