{"id":1760,"date":"2017-06-28T11:23:17","date_gmt":"2017-06-28T15:23:17","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=1760"},"modified":"2017-06-28T11:23:52","modified_gmt":"2017-06-28T15:23:52","slug":"stop-ransomware-wannacry","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/","title":{"rendered":"How to Stop Ransomware Attacks like Petya and WannaCry"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1761\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg\" alt=\"\" width=\"800\" height=\"350\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg 800w, https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note-300x131.jpg 300w, https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note-768x336.jpg 768w, https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note-600x263.jpg 600w, https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note-180x79.jpg 180w, https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note-400x175.jpg 400w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p style=\"text-align: justify\">On Friday, May 19th the world woke up to one of the biggest cyberattacks\u00a0in history. The WannaCry ransomware attack spread like wildfire through vulnerable Windows machines across the globe late last week, infecting over 230,000 machines in 150 countries and blocking users from their data unless they agreed to pay approximately\u00a0$300 in Bitcoin.<\/p>\n<p style=\"text-align: justify\">The attack\u2019s spread finally slowed when security researcher <a href=\"https:\/\/twitter.com\/MalwareTechBlog?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor\" target=\"_blank\" rel=\"noopener noreferrer\">MalwareTech<\/a> accidentally discovered a killswitch for the malware by registering a domain for a DNS sinkhole found in the virus\u2019s code, but by then the damage was already done.<\/p>\n<p style=\"text-align: justify\">Now, another attack is ripping through the world&#8217;s unsecured and unpatched systems using the same exploit as WannaCry. This new malware, known as &#8220;Petya&#8221; has quickly spread throughout the globe, infecting multiple large companies including the advertiser WPP, food company Mondelez, legal firm DLA Piper and Danish shipping and transport firm Maersk,.These attacks, amongst others, has made one thing abundantly clear: ransomware is the number one cyber threat to businesses in 2017 and for the foreseeable future.<\/p>\n<p style=\"text-align: justify\">The situation is serious\u2014hackers have been know to request ransoms up to <a href=\"https:\/\/www.usatoday.com\/story\/tech\/news\/2016\/11\/28\/san-francisco-metro-hack-meant-free-rides-saturday\/94545998\/\">$73,000<\/a> per attack. With numbers like that, it&#8217;s unsurprising that ransomware payments totaled over <a href=\"https:\/\/www.zdnet.com\/article\/the-cost-of-ransomware-attacks-1-billion-this-year\/\">$1 billion in 2016<\/a>, skyrocketing from just\u00a0<a href=\"https:\/\/blog.identityautomation.com\/enterprise\/urgent-97-of-top-companies-experience-data-leaks-iam-must-be-a-priority\">$34M paid in 2015<\/a>.<\/p>\n<p style=\"text-align: justify\">And Bitcoin payoffs aren&#8217;t the only cost of an attack. The cost of disinfecting machines, stabilizing systems and restoring data often dwarfs the initial ransom. What&#8217;s worse, it could be days or even weeks after an attack before your network is fully operational. That makes prevention and preparation for ransomware attacks a worthwhile investment.<\/p>\n<p style=\"text-align: justify\">So what\u2019s the best way to make sure your organization is prepared to fend off ransomware stick-ups?<\/p>\n<p style=\"text-align: justify\">In a pertinent <a href=\"https:\/\/blog.identityautomation.com\/enterprise\/your-action-plan-for-addressing-ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">blog post<\/a> from April, Identity Automation&#8217;s Scott Kortright laid out a few best practices for preventing ransomware infections, and limiting the damage it can do once inside:<\/p>\n<ul style=\"text-align: justify\">\n<li><em><strong>Have a plan.<\/strong> Ransomware is a system of shock and awe. Your attackers are relying on you to panic and give them what they want. For that reason, it\u2019s important to have a plan in place detailing the actions your organization will take in the event of a ransomware attack.<\/em><\/li>\n<li><em><strong>Backup your data. <\/strong>Your data should be backed up on a daily basis. The 3-2-1 principle is a good rule of thumb here: keep at least three copies of your data, back up your data on at least two different storage types (cloud and on-premise, for example), and keep at least one backup copy offsite. You don\u2019t have to pay them to get access to what you still have.<\/em><\/li>\n<li><em><strong>Educate your users. <\/strong>Phishing emails are the most common method of ransomware distribution, so it\u2019s important to teach your users how to identify suspicious emails and links. You can even go the extra mile and spam your user&#8217;s fake phishing emails, which will help you identify your most at-risk users.<\/em><\/li>\n<li><em><strong>Maintain<\/strong> <strong>strong perimeter defenses<\/strong>. Anti-malware and anti-virus (AV) are your first line of defense against ransomware, and good ones will be able to detect and stop many ransomware variants. However, it\u2019s unwise to rely solely on AV defenses, as they can easily be subverted by the newest malware variants.<\/em><\/li>\n<li><em><strong>Block ads<\/strong>. Malvertisements are a standard method of distributing ransomware, and let hackers target based on location, demographics, browsing habits, and more. You can lower your risk of infection by using adblockers to keep ads from being served to your users.<\/em><\/li>\n<li><em><strong>Patch, patch, patch.<\/strong> When it comes to ransomware, every day is patch Tuesday. Out-of-date applications and operating systems are a favorite target of ransomware attacks\u2014there are several variants of ransomware targeting outdated versions of Flash and Silverlight\u2014so keep your apps up to date.<\/em><\/li>\n<\/ul>\n<p style=\"text-align: justify\"><strong>The principle of least privilege access\u00a0<\/strong><\/p>\n<p style=\"text-align: justify\">The tips above will get you on the right path, says Kortright, but it&#8217;s important not to overlook the ways that modern Identity and Access Management (IAM) tools can help prevent and minimize the success of ransomware attacks.<\/p>\n<p style=\"text-align: justify\">One way to see the benefit of IAM is to thing about the principle of least privilege access, says Kortright. That principle recommends that organizations limit access to applications and data to those who need it when they need it.<\/p>\n<p style=\"text-align: justify\">However, for organizations still manually provisioning access requests, that\u2019s easier said than done. In most IT environments, users have more access than they should\u2014especially administrative accounts.<\/p>\n<p style=\"text-align: justify\">&#8220;When manually provisioning access, human error is a fact of life,&#8221; Kortright explains.<\/p>\n<p style=\"text-align: justify\">&#8220;Accidental over-assignment of permissions, access granted to improper data\u2014these things happen, and they make hackers jobs easier. A robust IAM solution will prevent this kind of access creep by ensuring the consistent application of rules and policies across your organization.&#8221;<\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/blog.identityautomation.com\/enterprise\/beyond-compliance-with-privileged-access-management\">Privileged Acce<\/a>s<a href=\"https:\/\/blog.identityautomation.com\/enterprise\/beyond-compliance-with-privileged-access-management\">s Management<\/a> (PAM) capabilities, such as time and location-based access controls, will help implement least privilege and minimize your ransomware attack surface. After all, hackers can\u2019t demand ransom if they can\u2019t get access to your critical systems.<\/p>\n<p style=\"text-align: justify\">In the end, there&#8217;s no silver bullet for stopping Ransomware attacks, says Kortright, but following the best practices above and implementing some advanced identity and access management solutions \u2013 you can put yourself in a much less vulnerable position. It\u2019s your decision, says Kortright: &#8220;Invest in security today, or invest in Bitcoin tomorrow.&#8221;<\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/solutionsreview.com\/backup-disaster-recovery\/how-to-protect-against-ransomware-like-wanna-cry\/\" target=\"_blank\" rel=\"noopener noreferrer\">Check out this link for related tips on backup and disaster recovery.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Friday, May 19th the world woke up to one of the biggest cyberattacks\u00a0in history. The WannaCry ransomware attack spread like wildfire through vulnerable Windows machines across the globe late last week, infecting over 230,000 machines in 150 countries and blocking users from their data unless they agreed to pay approximately\u00a0$300 in Bitcoin. The attack\u2019s [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":1761,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5,6],"tags":[212,404,70,145,529,508,506,507],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to Stop Ransomware Attacks like Petya and WannaCry<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/\",\"name\":\"How to Stop Ransomware Attacks like Petya and WannaCry\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg\",\"datePublished\":\"2017-06-28T15:23:17+00:00\",\"dateModified\":\"2017-06-28T15:23:52+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg\",\"width\":800,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Stop Ransomware Attacks like Petya and WannaCry\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Stop Ransomware Attacks like Petya and WannaCry","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/","url":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/","name":"How to Stop Ransomware Attacks like Petya and WannaCry","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg","datePublished":"2017-06-28T15:23:17+00:00","dateModified":"2017-06-28T15:23:52+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2017\/05\/Ransom-note.jpg","width":800,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/stop-ransomware-wannacry\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"How to Stop Ransomware Attacks like Petya and WannaCry"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1760"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=1760"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/1760\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/1761"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=1760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=1760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=1760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}