Skip to main content
عربي
logo

Protecting Against Ransomware

Protecting Against Ransomware

Quick Wins

  • Avoid using similar syntax/pattern in passwords on service/administrator accounts. Obtaining one password by the threat actor will make the process of cracking the rest easy using dictionary attacks.
  • Regularly change all passwords, including passwords to service accounts, while ensuring compliance to strong and complex password policy.
  • Disable Microsoft Office macro scripts, as these macros can be used to deliver ransomware.
  • Restrict the use of PowerShell to specific users. Use Group Policy to specify usage for each user.
  • Improve the user’s awareness of phishing emails and other suspicious activities.
  • Patch and update operating systems and software to the latest available versions regularly.
  • Restrict the use of USB drives or other removable devices.

Intermediate Guidelines

Data Protection

  • Use offline encrypted backups, especially for critical and sensitive data. Regularly test and maintain backups.

Human Resources

  • Have a dedicated security officer or team that is responsible for governance, risk and compliance (GRC).
  • Have adequate resources to manage and operate the implemented systems and security controls.

Endpoint Protection

  • Perform regular vulnerability assessments on all systems, especially those on internet-facing systems. Security vulnerabilities, including weak passwords and misconfigurations, can help threat actors bypass security.
  • Implement the principle of least privilege where users and system services are given privileges needed to complete their tasks. Separate accounts should be used for tasks requiring higher privilege. It is recommended to use Privileged Access Manager and Endpoint Privilege Manager or similar solutions. These limit and control such privileged access across systems and endpoints.
  • Implement Privileged Access Workstations (PAWs), which are dedicated workstations for IT administrators that are used for tasks that require using highly privileged accounts so that other tasks, such as using email or web browsing, are done on other workstations.
  • Enable multi-factor authentication (MFA) for all accounts, especially high privileged accounts.
  • Implement a strict web browsing policy that prevents access to malicious websites.
  • Disable or block inbound and outbound Server Message Block (SMB) protocol, as well as remove or disable outdated versions of SMB.
  • Adversaries often target Domain Controllers (DCs) to spread ransomware network-wide. Therefore, securing domain controllers by restricting access to them is important.

Network Protection

  • Monitor network traffic for anomalies or suspicious activities.
  • Implement network segmentation to separate various business units or IT resources within the organization and maintain separation between IT and operational technology. Network segmentation minimizes the impact of network intrusion and ransomware infections.
  • RDP traffic should be monitored and restricted. Some RDP uses that should be blocked include RDP between servers, RDP from non-admin computers, and RDP directly from the internet. Threat actors often gain access to a network through exposed and poorly secured remote services, which results in a ransomware attack.
  • Control traffic flow between an organization’s network and backup/DR environments. In most cases, the traffic would be only in one direction and during specific times for backup purposes.

Monitoring Requirement

  • Regularly review server logs for suspicious behavior and configure the servers to forward logs to a different server using log event management system. These logs should be monitored and correlated around the clock to address any suspicious events and to have records in case of any incident.

Technology Guidelines

  • Implement an endpoint protection solution, such as an Endpoint Detection and Response (EDR) solution, to prevent infections or detect them early.
  • Implement an email security solution that can detect and block malicious emails and attachments.
  • Implement a Network Access Control (NAC) solution so that devices connected to the network are isolated if they are not compliant to the organization’s security policy. This can reduce the risk of having cyber threats or infections from unauthorized devices connected to the network.