In-depth

Four steps you can take to lower the risk of a ransomware attack

With the ever-increasing frequency in attacks, it's likely many of us will be targeted by ransomware

Because it's relatively inexpensive to develop and launch ransomware and a single item of crypto-malware can generate massive revenue the volume of this type of attack is increasing.

When it comes to dealing with the risk of a ransomware attack, you can choose either to cross your fingers and hope for the best, or take active steps to mitigate the risks of being attacked and the possible consequences.

With the ever-increasing frequency in attacks, it's likely that many of us will be targeted at some stage, so here are some steps you can take to both reduce the likelihood of being affected by ransomware, and lessen the impact should the worst happen.

Back up data regularly

Almost all businesses will already have data back up policies. However, it's essential to back up data onto an offline backup subsystem rather than just copying files to another live' system on your corporate network, otherwise ransomware will be able to affect your backup files. A back up and disconnect' policy is worth considering, so that data isn't being copied onto a permanently connected file server.

Advertisement
Advertisement - Article continues below

Personal users tend to back up on a more infrequent basis, so it's important to establish a regular backup routine across all devices. It's currently impossible to decipher files properly encrypted by modern crypto-malware, so the only way to save your data from a successful ransomware attack is through regular file backups.

Use a reliable security solution

There are a wide range of antivirus solutions available for both business and personal use; see our recommendations for the best antivirus tools available this year.

For businesses, an anti-ransomware solution that's able to protect shared folders should also be considered. Some solutions leave hosts inside the security perimeter unprotected, meaning that any cryptor penetrating via email or a vulnerable browser will also affect shared folders on corporate servers. Under this scenario, only server-side security software can defend the data.

Whichever tool you choose, it should be turned on at all times, with as many security layers enabled as possible.

Always keep software updated on all the devices you use

Ransomware doesn't just affect PCs. Security software needs to be able to protect Mac computers, virtual machines and mobile devices, as well as email systems. Keeping this software up to date is a vital part of remaining secure, as updates are regularly released to combat new strains of malware.

Although it can be tempting to skip app and security updates and install them later, it's easy to forget and updates for some apps contain vital patches against vulnerabilities which could be exploited by cyber criminals. Resist the temptation to ignore the update warnings to ensure device apps are as up-to-date as possible.

Educate employees and IT teams

People are often the most vulnerable element. Businesses should teach their employees about IT security basics, including raising awareness of phishing and spear-phishing and the security implications of opening any email attachment that looks suspicious.

There's no such thing as being over-careful; even if an email looks like it's from a trusted source, it's worth checking with a simple phone call to the sender if there are unexpected attachments or links present.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/29204/how-can-you-protect-your-business-from-crypto-ransomware
Security

How can you protect your business from crypto-ransomware?

4 Nov 2019
Visit/malware/33080/hackers-abuse-linkedin-dms-to-plant-malware
malware

Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/antivirus/28144/best-antivirus
antivirus

Best antivirus for Windows 10

3 Sep 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019