Protect, Mitigate and Recover: Making Your Company Ransomware-Resistant

Pillsbury - Internet & Social Media Law Blog
Contact

Pillsbury - Internet & Social Media Law Blog

As is the case with many types of cybersecurity threats, shielding one’s company from ransomware attacks calls for measures that simultaneously build the strongest protections possible while also adopting mitigation strategies that assume those measures will fail.

Here are some essential steps that can lessen a company’s vulnerability while also enable a more robust recovery in the event an attack succeeds:

  • Strengthen passwords. Require employees to create strong passwords and reset them regularly using a password-management tool.
  • Implement multifactor authentication. MFA is especially important when employees are remotely accessing your company’s system, including email.
  • Segment your data. Build firewalls within your network. Give employees access just to the files and systems they need. Limit the number of system administrators. Make sure the firewalls within Windows OS are set up properly.
  • Keep your software current. Download updates and patches as soon as they’re available.
  • Train your staff. Know how the latest malware will look to them, and make sure they know how to recognize and report it and other phishing scams.
  • Back up data strategically, using multiple methods. Cybersecurity expert Albert Zhichun Li suggests using an “appending-only backup type, which makes it harder for attackers to change/encrypt/delete previously backed-up data.”
  • Practice caution. After verifying the sender, proceed with caution before opening attachments, especially if they are zipped or compressed.
  • Consider using continuous data protection. This backup method can minimize operational disruptions during an attack.
  • Have a plan in place in case your system is attacked anyway. You’ll be glad you did.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Pillsbury - Internet & Social Media Law Blog

Written by:

Pillsbury - Internet & Social Media Law Blog
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Pillsbury - Internet & Social Media Law Blog on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide