Ransomware Frontline Report
8. How to Explain Ransomware to Others
8.1 A Three-Minute Explanation Script
Ransomware is less a virus that encrypts PCs than a criminal operation that demands money using a company’s business stoppage and the exposure of its information as leverage. Attackers may get in through email, credentials, exposed devices, or outsourcing-partner connections, and after getting in, they survey administrator privileges, servers, backups, and the cloud. Because data is sometimes taken out before encryption, backups alone are not enough.
The order of defense is: know the assets visible from outside, strengthen identity and administrator privileges, update and monitor endpoints and servers, separate the network and backups, and actually train to bring business operations back. If it happens, we handle identity, data, business partners, business continuity, and legal/PR at the same time — not just the response to an infected PC. Because payment does not guarantee recovery, having recovery capability in normal times is what matters most.
8.2 Five Questions to Explain to Management
- What is the operation that can least afford to stop? If it stops for how many hours, what impact does that have on whom?
- What identities, data, external services, outsourcing partners, and backups does that operation need?
- Is the structure such that all of those could be lost at once through a single administrator identity or a single endpoint?
- If encryption or data theft is suspected this weekend, who stops it, who investigates, and who explains it?
- How many hours would it take to restore one critical business operation, with grounds to believe it is not compromised?
8.3 Five Questions to Explain to Engineers
- Can externally exposed assets and their owners be enumerated as of today?
- Can privileged identities, service identities, emergency identities, and outsourcing-partner identities be distinguished, with authentication and logs checkable?
- Is it impossible to reach backup deletion or modification using the same privileges as production?
- Can logs from identity, endpoints, cloud, network, and backup be correlated on the same time reference?
- Has the recovery procedure ever been executed, by someone other than its author, in an isolated environment, through to business sign-off?