• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to primary sidebar
  • Skip to footer

Before Header

About Us | Articles | Free Resources | Podcast | YouTube Channel

Contact Us Subscribe

Bryghtpath

Business Continuity and Crisis Management Consultants

  • Start
        • Start your Resilience Journey

          Moving your organization – or your career – forward on your resilience journey can be a difficult and scary proposition.  Often, we find that prospective clients aren’t quite sure where to start.

          To help you along your journey, we’ve outlined below four curated collections geared towards momentum-building action and advice perfectly paired with your organization’s current stage of resilience.

        • I want to learn more about Resilience

        • We’re just getting started with our resilience program

        • We’re seeking to optimize & mature our resilience program

        • I’m a Resilience Professional seeking to further develop my skills

  • Company
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
  • Courses & Training
        • Courses & Training

          We’ve created a number of free and premium courses that have helped thousands improve their skills, build more resilient organizations, and lead through organizations through difficult critical moments successfully.

        • Coaching
          • 1-on-1 Coaching Call
          • Private Backchannel
          • Private Coaching Program
        • Free Intro Courses
          • Overview
          • Business Continuity 101
          • Crisis Communications 101
          • Crisis Management 101
        • Premium Courses
          • Overview
          • Custom Training
          • 5-Day Business Continuity Accelerator
          • Communicating in the Critical Moment
          • Crisis Management Academy®️
          • Preparing for Careers in Resilience
  • Expertise
        • Our Expertise
        • Here at Bryghtpath, in our core values, we state that we are humbly confident in our resiliency expertise.

          We write, publish, speak, and train others constantly – striving to share our thought leadership publicly to advance our industry and exercise our curiosity by interacting with other leaders in our practice domains.

        • Ultimate Guide to Business Continuity

        • Ultimate Guide to Crisis Management

        • Case Studies & Results

        • Free Resources & Frameworks
          • Overview - Free Resources
          • Bryghtpath Frameworks
            • Bryghtpath Business Continuity Lifecycle
            • Bryghtpath Crisis Management Framework
            • Bryghtpath Exercise Maturity Model
            • Bryghtpath Global Security Framework
            • Bryghtpath Long-Term Recovery Framework
            • Bryghtpath Professional Reading List
            • Bryghtpath Workplace Violence & Threat Management Toolkit
          • Resiliency Professionals Facebook Group
          • Resource Library
          • Webinars & Videos
          • Whitepapers & Reports
        • Our Thoughts & Insights
          • Articles
          • Lead Through Disruption. Stay Ahead with Bryghtpath.
          • Managing Uncertainty Podcast
          • Media & Professional Appearances
          • YouTube Channel
        • Whitepapers & Reports
          • Global Security Operations Centers & Resilience
          • Managing the Whole Crisis: The Ransomware Challenge
          • Mastering Uncertainty: Strengthening Organizational Resilience
          • Social Activism Campaigns
          • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
        • Our Industry Expertise

          Bryghtpath has extensive experience in a number of industries working with clients of all sizes, geographical locations, and business models. As a team, we possess, deep global operating experience on every continent around the world.

        • Industries Overview

        • Case Studies

        • Start your Journey

        • Education

          Education Icon
        • Finance

          Financial Services 800x800
        • Government

          Government Icon
        • Healthcare

          Healthcare Icon 800x800
        • Hospitality & Leisure

          Hospitality & Leisure Industry Icon 800x800
        • Life Sciences

          Life Sciences 800x800
        • Logistics

          Transportation & Logistics Industry Icon 800x800
        • Manufacturing

          Manufacturing Industry Icon 800x800
        • Non-Profits

          Non-Profit Industry Icon 800x800
        • Retail

          Retail Industry Icon 800x800
        • Tech & Media

          Communications Industry Icon 800x800
        • Utilities

          Power & Utilities Icon
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • Start
  • Company
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
  • Courses & Training
    • Coaching
      • 1-on-1 Coaching Call
      • Private Backchannel
      • Private Coaching Program
    • Free Intro Courses
      • Overview
      • Business Continuity 101
      • Crisis Communications 101
      • Crisis Management 101
    • Premium Courses
      • Overview
      • Custom Training
      • 5-Day Business Continuity Accelerator
      • Communicating in the Critical Moment
      • Crisis Management Academy®️
      • Preparing for Careers in Resilience
  • Expertise
    • Our Expertise
    • Our Thoughts & Insights
      • Articles
      • Lead Through Disruption. Stay Ahead with Bryghtpath.
      • Managing Uncertainty Podcast
      • Media & Professional Appearances
      • YouTube Channel
    • Free Resources & Frameworks
      • Overview – Free Resources
      • Bryghtpath Frameworks
        • Bryghtpath Business Continuity Lifecycle
        • Bryghtpath Crisis Management Framework
        • Bryghtpath Exercise Maturity Model
        • Bryghtpath Global Security Framework
        • Bryghtpath Long-Term Recovery Framework
        • Bryghtpath Professional Reading List
        • Bryghtpath Workplace Violence & Threat Management Toolkit
      • Resiliency Professionals Facebook Group
      • Resource Library
      • Webinars & Videos
      • Whitepapers & Reports
    • Whitepapers & Reports
      • Global Security Operations Centers & Resilience
      • Managing the Whole Crisis: The Ransomware Challenge
      • Mastering Uncertainty: Strengthening Organizational Resilience
      • Social Activism Campaigns
      • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Plan Your Ransomware Attack Response Now

You are here: Home / Cybersecurity / Plan Your Ransomware Attack Response Now

March 15, 2022 By //  by Bryan Strawser

A food processing chain. A fuel pipeline system. A police department. A transportation authority. These are some of the larger targets hit with ransomware attacks in the U.S. so far in 2021. But for every ransomware story in the news, dozens of incidents go unmentioned, either because the company is too small for news outlets to care or because the organization wanted to handle the situation quietly on its own, probably by paying the ransom.

And ransomware pays good money. In 2020, the amounts victims paid to regain use of their data increased more than 300%. It’s not surprising then that the Washington Post claims that the frequency of attacks more than doubled from 2019 to 2020. It seems not a case of if a company will get hit, but when.

The growth of remote work in the last year created the perfect conditions for cyberattacks. Although mobile work—and mobile devices—have increased for almost a decade now, companies still don’t proactively communicate the urgency of hardening home-based information security the way they should. Billions of homeworkers provided multiple entry points through insecure home routers, possibly still running WPS instead of WPA2 or WPA3, and Wi-Fi networks without password protection.

Companies can shore up home-based offices. But they also need to change their attitude to ransomware attacks. Tactically, companies focus cybersecurity efforts on regulatory and framework compliance.

That’s important, but they need to build cybersecurity capabilities to withstand a determined adversary. Recently, a client of ours lost their database and their backups: the ransom group called their backup provider and persuaded them through a social engineering attack to erase their backups. Such initiative yielded the bad guys over $2 million.

Companies also don’t yet fully realize how disruptive a ransomware incident is. You may think that your backup—if you still have one—covers you. But, restoring an entire data center or multiple data centers is not just a 4- or 5-hour job. Depending on the extent of the breach, recovery could take days or even weeks of round-the-clock work.

Ransom attacks also present broader strategic and reputational implications. The problem now extends beyond a mere technical project of decrypting the system. Consider the loss of revenue. What’s the impact to employee morale? How long before customers trust you again?

So, what are company leaders to do?

1. Bolster your backup and recovery processes.

Employ a three-generation backup policy for all critical files: the grandparent is the oldest version, the parent is the second oldest version, and the child is the most recent version. Store at least one version entirely offline and offsite on tape or another movable media that you can quickly recover. In addition, use an immutable storage system so no one can overwrite or delete encrypted files. Finally, ensure that your off site provider uses two-factor authentication (2FA) to withstand a social engineering attack that could delete your backups.

2. Build a ransomware playbook.

Imagine your data incident response. Consider scenarios ahead of time to avoid a steep learning curve in the moment of crisis. Will the leadership and board pay the ransom or not? If they choose to pay, how will they do it?

Another significant consideration is, will management notify the FBI when they discover an attack? Actually, this is the right thing to do. Remember that making a payment in furtherance of criminal activities is a technical violation of U.S. anti-bribery laws. The Office of Foreign Asset Control (OFAC) at the U.S. State Department requires a company that pays to complete some paperwork, which is another good reason to involve the FBI: they can help with the recording process. In addition, anyone involved in paying a ransom may incur some criminal liability if the process isn’t done correctly. Consult your lawyers ahead of time. Again, you need to think about all this before your data gets locked up.

When you complete your robust ransomware response plan, practice it again and again. Make this more than just a technical exercise. Play the complete response from a reputation crisis management standpoint.

3. Take cybersecurity measures to meet an active and present threat.

Your cybersecurity program must do more than keep you in compliance with HIPAA, FISMA, or ISO/IEC 27001—valuable as all those standards are. Weave cybersecurity into the fabric of your company culture. You know the tools already; but you have to use them.

  • Establish firewalls.
  • Install reputable antivirus protection.
  • Disable remote connections.
  • Filter incoming email for the most common troublemakers, the macro-enabled executables, such as .docm and .pptm files.
  • Reveal hidden extensions to show rogue .exe, .zip, and .rar files.
  • Invest in SIEM, security information event management, which can detect anomalies within your network.
  • Implement a safe listing protocol, particularly around sensitive information.
  • Keep up-to-date with patches.

Those steps are the technology side of ransomware protection. Even more important is the people side. Staff are the weakest link but can be the first line of defense. Train all staff regularly on the dangers of malware and ransomware. Let them know how easily bad actors can infect their devices and the whole network. Reiterate what staff should and should not do:

  • Use strong passwords that staff change regularly.
  • Question the legitimacy of emails.
  • Create a social media policy to limit what information spear phishers can gather about employees and executives.
  • Don’t open email attachments from unknown sources.
  • Don’t click links in emails from unknown sources.
  • Don’t open emails in the spam folder from unknown sources.
  • Conduct ethical social engineering tests frequently so everyone keeps their threat awareness sharp.

Usually, ransomware events appear in the news after the fact. But that doesn’t mean you can’t get a look around the corner at potential threats and deterrents. Consider subscribing to the Department of Homeland Security’s Cyber Security and Infrastructure Security Agency (CISA), FBI, NIST, and other cyber intelligence bulletins to understand current thinking. Help your leadership decide now, before an attack, where they stand and what the plan is to manage and survive ransomware and other data incidents.

Want to learn more about Crisis Management?

Our Ultimate Guide to Crisis Management contains everything you need to know about crisis management.

You’ll learn what it is, why it’s important for your organization, how to prepare for a crisis, how to respond when a crisis happens, and how to recover and learn from a crisis after it is over. We’ll also provide some perspective on where to learn more about crisis management.

Ultimate Guide to Crisis Management

Can we help you?

Bryghtpath has built the data incident response plans for major healthcare companies, designed crisis management frameworks & plans, facilitated crisis and cybersecurity exercises, and helped organizations rapidly mature their business continuity capabilities. You can learn more about our approach to Crisis Management in our Ultimate Guide to Crisis Management.

Don’t hesitate to reach out to us today for a call to discuss your challenges and learn how we may be able to help you prepare for the ransomware threat.

 

 

Category: Business Continuity, Crisis Management, Cybersecurity, Disaster RecoveryTag: Backups, Bryan Strawser, bryghtpath, bryghtpath llc, business continuity consultant, crisis communications consultant, crisis management, crisis management consultant, cyber, cybersecurity, disaster recovery, information security, ransomware

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: « Inside Bryghtpath: Who quits a large corporation for a company in Minnesota with a team of four?
Next Post: The Role of HR in Crisis Management »

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Premium Courses

5-Day Business Continuity Accelerator

Communicating in the Critical Moment

Crisis Management Academy®️

Preparing for Careers in Resilience

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model™
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.