Threat

Ransomware

Ransomware is malicious software that encrypts data and demands a ransom for decryption.

Ransomware is malicious software that encrypts data and demands a ransom for decryption. Today, attackers usually also steal the data and threaten to publish it.

How it works

A typical attack starts with stolen credentials, a phishing email or a VPN vulnerability. Attackers then gain admin rights, look for backups and copy data externally. The encryption phase happens last, often at night or during the weekend. The time between initial access and encryption is often only a few days.

A practical example

On a Friday evening, the EDR reports shadow copy deletion on a server. Shortly afterwards, an unknown program starts on multiple systems. The SOC isolates the affected servers and blocks the admin account being used. Encryption is limited to a few systems. Recovery takes hours, not weeks.

What to look out for

  • Backups must be offline or immutable. Test the recovery process regularly.
  • MFA is mandatory for all remote access and administrator accounts.
  • Monitor precursors such as shadow copy deletion and new admin accounts.
  • Determine in advance who decides on a ransom payment and who leads communication.
  • Practise the incident response in a tabletop exercise with management and IT.

Switzerland and regulation

Ransomware is one of the most consequential reported incidents at Swiss companies. If personal data is affected and a high risk for the persons concerned is likely, a report to the FDPIC is required under the revFADP (revised Federal Act on Data Protection). Critical infrastructures must report the attack to the National Cyber Security Centre (NCSC) within 24 hours of discovery under the Information Security Act (ISG).

Typical mistakes

A common mistake is having backups accessible with the same admin accounts as production systems. Attackers can then encrypt or delete the backups as well. A second mistake is a lack of monitoring at weekends, even though many attacks start precisely then.

How we implement it

We detect and contain ransomware precursors around the clock, within your mandate. Ransomware is excluded from the Incident Response covered by our Flat Fee. For this, we recommend the Halcyon add-on: it stops ransomware, secures decryption keys and includes Halcyon's Ransomware Warranty.

How ANOMAL implements this