Ransomware Frontline Report

Key Points of This Report

V2 | English | Full Report

Ransomware has changed from a problem of attackers “selling a decryption key” to one of “pricing both an organization’s stoppage and the exposure of its information.” Countermeasures must therefore also be integrated — answering the following questions — rather than treating antivirus, backup, and employee training as separate items.

  • Who can get in, through which route, and with which privileges?
  • With that privilege, which management plane and which critical operations can be reached?
  • At what point can this be observed as anomalous, and who stops it?
  • Even in the worst case, what can be restored, in what order, on a safe basis?
  • What can be explained to customers, outsourcing partners, regulators, and investigative authorities, and when?

The chapters that follow examine these five questions in the order of history, the structure of current attacks, defense, response, case studies, and the future.