When it comes to el ransomware, it’s a matter of when, not if, an organization will be impacted. Effective cyber recovery requires a focus on protecting your assets and data, intelligence to understand when threats are present and what data is affected, and the ability to restore extremely large amounts of data as quickly as possible. Here are some commons questions about how to prepare for el ransomware.
What are some best practices to implement ransomware prevention?
Las empresas deben seguir estos pasos fundamentales para proteger a sus empleados y sus equipos frente al ransomware y otras conductas maliciosas:
- Instala actualizaciones y parches de software de forma periódica, tanto en los ordenadores individuales como en los equipos informáticos.
- Realiza copias de seguridad periódicas de todos los datos, siguiendo el método 3-2-1:
- Haz tres copias de los datos,
- En dos tipos de soportes distintos,
- And 1 of those copies should be offsite and immutable, so it can’t be modified or deleted.
- Limit user access to systems to reduce the risk of accidental or intentional modifications.
CommvaultCloud offers capabilities including role-based access control, auditing, integration with customer-owned authentication technologies like SAML, and encryption of all intra-service communications and data during transmission to securely handle customer data.
Additionally, all backup data is compressed, deduplicated, and encrypted by default from the source, on the network, and at rest. Compression and deduplication also obfuscate data, providing additional security if the backup storage is compromised. Learn more about the Aspectos de la resiliencia cibernética frente al ransomware, de la A a la Z.
What are some everyday prevention measures for IT to deliver to our employees to prevent attacks?
Las empresas deberían informar a sus empleados sobre los riesgos del ransomware y sobre qué aspectos deben tener en cuenta en los correos electrónicos y mensajes de texto no solicitados. La formación en línea puede resultar muy eficaz para ilustrar estos ejemplos.
A nivel personal, aprende a detectar los signos de alerta y toma las precauciones necesarias:
- Utiliza la autenticación multifactorial para verificar tu identidad al iniciar sesión.
- Aplica medidas adecuadas de seguridad para el correo electrónico y los dispositivos finales con el fin de detectar y bloquear el malware o los intentos de phishing.
- Revisa con atención los enlaces pasando el cursor por encima de ellos sin hacer clic, para comprobar que la URL es segura.
These are just the basics, and it’s important for each of us to do our part to protect ourselves and our organizations from being affected by an attack.
How can we proactively detect ransomware incidents within our organization?
To identify ransomware proactively, you should implement threat detection tools as part of your environment’s defenses. Commvault turns the tables on attackers, applying advanced forensics and generative AI to accelerate threat detection and response. We start with our Zero-Trust Architecture, with key features such as multi-factor authentication, multi-person authorization, SAML, privilege access management, and role-based access controls. Commvault® Cloud includes intelligent monitoring and risk identification to deceive and flag threats early in the attack lifecycle, along with cyber deception for early warning into ransomware and malicious intent. Gain insights into trends and user behaviors to detect anomalies before they spread.
Can we detect ransomware attacks beyond the endpoint?
With endpoint protection, businesses can implement comprehensive data backup and recovery protection for data at the edge. But it’s important to obtain insights throughout your SaaS and hybrid cloud environments. Without protection for SaaS data, applications, and endpoints, the risk of data loss or attacks such as corruption, accidental deletion, and malicious attack is substantial.
Be prepared to block ransomware with early detection and rapid response initiatives. Commvault provides intuitive tools and advanced insights so you can spot risks in real-time and limit exposure to ongoing cyberthreats. With our hardened, multi-layered approach to ransomware readiness, you’ll have robust controls to help prevent threats and enable data to be recoverable from a cyberattack. Using immutable, air-gapped data copies, advanced anomaly detection, and built-in encryption, Commvault Cloud gives you the tools to safeguard critical data across apps, endpoints, and hybrid cloud environments.
What do I do if I believe my system has been infected by ransomware?
Aísla el problema para evitar que se extienda aún más y comienza el análisis forense lo antes posible. Lo ideal es habilitar un lugar limpio y seguro para evaluar la situación y minimizar el impacto en la organización.
Commvault Cloud® Cleanroom™ Recovery offers a cost-effective and flexible way to create a secure, isolated environment to recover your organization’s data and applications when a breach occurs. Cleanroom Recovery can be used to conduct forensic analysis of known infected systems and identify the root cause of an attack. It also can help reduce downtime and accelerate recovery with a streamlined process for testing, analyzing, and restoring both data and applications to get back to a production-capable environment.
How long does the recovery process take?
One análisis found that 24 days was the average reported time to recover from a cyberattack in the United States in 2022. Recovering from a cyberattack typically requires forensic investigation and remediation to be completed first, which can delay the actual recovery of data and restoration of normal business activity. It’s important to verify that data is free from infection before it is released back into the production environment.
Cyber readiness requires a broader outlook on system and data recoverability across all your infrastructure and processes. The ability to respond and recover quickly depends on being prepared with an incident response plan and the appropriate platform that incorporates data protection, threat detection and prevention, and isolated environments for safe restoration. This shift is essential in today’s threat landscape, emphasizing recovery as well as protection and integrity.
To reduce the amount of time it takes to recuperarse de un ataque de ransomware, you’ll need to define your cyber resilience strategy. When you establish a thorough recovery plan, regularly test to verify that the plan works, and have confidence that you can successfully deploy it when needed, you’ll be able to respond to an attack and recover from it much faster.
Commvault’s Cloudburst™ Recuperación capability can help you improve business continuity by using infrastructure-as-code to automate rapid and frictionless recovery of data, enabling mass recovery from cloud storage at scale with the highest speed possible. Through the breadth of the Commvault Cloud offerings, you can leverage unlimited scale, sophisticated layered security, and simple management to keep your organization protected now and in the future.
How do I best evaluate my current ransomware prevention strategy?
Earlier this year, Commvault colaboró con GigaOm to conduct a survey on cyber recovery readiness and resilience with 1,000 security and IT leaders. This collaborative study offers a worldwide view into the challenges of cyber readiness postures and identifies effective strategies that you can use to enhance your recovery readiness plans.
To make things more actionable, we identified these 5 practices and capabilities that have an outsized impact on resilience. We call them the cyber readiness maturity markers, and as you can expect, the more you have, the more mature and prepared you are to respond to a ransomware incident.
Let’s step through each of these:
Herramientas de seguridad que permiten la alerta temprana sobre riesgos, incluidos los riesgos internos.
En primer lugar, las herramientas de seguridad de alerta temprana son tecnologías y sistemas diseñados para detectar posibles amenazas cibernéticas antes de que puedan causar un daño significativo. Estas herramientas tienen como objetivo identificar los riesgos en la fase más temprana posible, lo que permite a las organizaciones responder de forma proactiva en lugar de reactiva. Entre los ejemplos se incluyen los sistemas de detección de intrusiones, la tecnología de engaño, los sistemas de prevención de intrusiones, la gestión de información y eventos de seguridad, el análisis del comportamiento de usuarios y entidades, y la detección y respuesta en terminales.
Se dispone de un sitio oscuro o un sistema secundario cuya limpieza está comprobada.
Second, it’s important to maintain an isolated, pre-configured, or dynamic recovery environment (such as a cleanroom) that remains unaffected by cyber incidents at the primary site. This secondary site can be quickly activated for continuous business and data integrity in a cyberattack or major failure. It enhances cyber resiliency by providing a secure failover option, minimizing downtime and complexities of failover.
Un entorno aislado para almacenar una copia inmutable de los datos.
Third, you should maintain a separate, air gapped (that is, immutable and indelible) copy of your data – secured behind a third party’s infrastructure. The data remains unchanged and protected from cyber threats, including ransomware and malicious insider actions. It enhances data integrity and availability, providing a reliable recovery option in case of data corruption or loss.
Se han definido manuales de procedimientos, funciones y procesos para la respuesta ante incidentes.
En cuarto lugar, se trata de una capacidad fundamental para dar una respuesta estructurada y eficaz ante los incidentes cibernéticos. Los manuales de procedimientos probados ofrecen instrucciones paso a paso para gestionar diversos tipos de incidentes, lo que reduce la confusión y el tiempo de respuesta. Es fundamental contar con funciones y procesos claramente definidos para que cada miembro del equipo conozca sus responsabilidades, lo que favorece la coordinación de esfuerzos. Esta preparación agiliza la recuperación y ayuda a mantener la continuidad operativa durante y después de los incidentes cibernéticos.
Medidas concretas para demostrar el grado de Readiness para la recuperación cibernética y el nivel de riesgo.
And last, but not least, establish metrics and tests that demonstrate your organization’s ability to recover from cyber incidents and assess associated risks. These measures, such as regular recovery drills and risk assessments, provide insight into the effectiveness of your recovery plans and identify potential vulnerabilities. They are essential for cyber resiliency.
Are you ready to build your cyber recovery plan?
This is how you can be ready to recover from ransomware. Being ready for recovery means your teams have the confidence and the ability to quickly recover all data and applications across your environment, including physical servers, virtual machines, and your various cloud platforms. If you’re interested in seeing the full Cyber Recovery Readiness Report, you can descargar el PDF.
Ready to learn more about the Commvault Cloud platform? Solicita una demostración to see it in action and discover how you can respond to ransomware.