Think 3,2,1 to protect your business against ransomware

Rick Vanover, Senior Director of Product Strategy, Veeam discusses how to protect your business against ransomware in a cyber world….
Veeam

Share this article:

rick vanover

Rick Vanover, Senior Director of Product Strategy, Veeam discusses how to protect your business against ransomware in a cyber world.

The war on ransomware is real. In the past few years, this form of attack has become a valid threat to businesses. We have seen huge attacks that have rendered multinational organizations, even governments, vulnerable and unable to continue mission-critical operations. In 2017, WannaCry brought hospital IT departments across Europe to a standstill, with over 200,000 computers across affected, demonstrating the destructive potential of ransomware.

While WannaCry and Petya are still the most notable ransomware attacks, this form of cyber-attack is still on the rise, according to Europol’s 2019 Internet Organized Crime Threat Assessment (IOCTA) report. Organizations need to acknowledge this threat and take steps to prepare, defend and be ready to remediate. This is a critical step to avoid an unplanned and likely ineffective response later during a ransomware incident. A strong, multi-layered defense and strategy to address ransomware is composed of three key elements: education, implementation and remediation. Furthermore, having an ultra-resilient approach to backing up, recovering and restoring data is vital to protect business continuity in the event of an event.

Educating the business

There are two major audiences that should be targeted from an education perspective: IT staff and organizational users. It’s important to target both groups as threats can be introduced from both personas.

The main points of entry into a business for ransomware is through Remote Desktop Protocol (RDP) or other remote access mechanisms, phishing and software updates. Put simply, in most cases cyber-attackers are not made to work as hard as they should to fetch big prizes. Knowing that these are the three main mechanisms is a huge help in focusing the scope of where to invest the most effort to be resilient from an attack vector perspective.

Most IT administrators use RDP for their daily work, with many RDP servers directly connected on the Internet. The reality is that Internet-connected RDP needs to stop. IT administrators can get creative on special IP addresses, redirecting RDP ports, complex passwords and more; but the data doesn’t lie that over half of ransomware comes in via RDP. This tells us that exposing RDP servers to the Internet does not align with a forward-thinking ransomware resiliency strategy.

The other frequent mode of entry is via phish mail. We’ve all seen email that doesn’t look right. The right thing to do is delete that item. Not every user handles these situations the same way, however. There are popular tools to assess the threat risk of phish success for an organization such as Gophish and KnowBe4. Combined with training to help employees identify phishing emails or link, self-assessment tools can be an effective mode of first-line defense.

The third area that comes into play is the risk of exploiting vulnerabilities. Keeping systems up to date is an age-old IT responsibility that is more important than ever. While this is not a glamourous task, it can quickly seem a good investment should a ransomware incident exploit a known and patched vulnerability. Be mindful to keep current with updates to critical categories of IT assets: operating systems, applications, databases and device firmware. A number of ransomware strains, including WannaCry and Petya have been based on previously discovered vulnerabilities that have since been corrected.

Implement and remediate

Even organizations that follow best practice to prevent exposure to ransomware are at risk. While education is a critical step, organizations must prepare for the worst-case scenario. If there’s one takeaway for IT and business leaders, it is to have a form of ultra-resilient backup storage.

At Veeam, we advocate the 3-2-1 rule as a general data management strategy. The 3-2-1 rule recommends that there should be at least three copies of important data, on at least two different types of media, with at least one of these copies being off-site. The best part is that this rule does not demand any particular type of hardware and is versatile enough to address nearly any failure scenario.

The ‘one’ copy in the 3-2-1 strategy has to be ultra-resilient. By this, we mean air-gapped, offline or immutable. There are different forms of media which this copy of data can be stored in an ultra-resilient manner. These include tape media, immutable backups in S3 or S3-compatible object storage, air-gapped and offline media, or software as a service for backup and Disaster Recovery (DR).

In spite of these education and implementation techniques, organizations must still be prepared to remediate a threat if introduced. At Veeam, our approach is simple. Do not pay the ransom. The only option is to restore data. Additionally, organizations need to plan their response when a threat is discovered. The first action is to contact support. Veeam customers have access to a special team with specific operations to guide them through the process of restoring data in ransomware incidents. Do not put your backups at risk as they are critical to your ability to recover.

In disasters of any type, communication becomes one of the first challenges to overcome. Have a plan for how to communicate to the right individuals out-of-band. This would include group text lists, phone numbers or other mechanisms that are commonly used to align communications across an extended team. In this contact book you also need security, incident response and identity management experts – internal or external.

There are also conversations to have around decision authority. Businesses must decide who makes the call to restore or to fail over before an incident takes place. Once a decision to restore has been made, organizations need to implement additional safety checks before putting systems back online. A decision also has to be made as to whether an entire virtual machine (VM) recovery is the best course of action, or if a file-level recovery makes more sense. Finally, the restoration process itself must be secure, running full anti-virus and anti-malware scans across all systems as well as forcing users to change their passwords post-recovery.

While the threat of ransomware is real, with the right preparation organizations can increase resiliency against an incident to minimize the risk of data loss, financial loss, and reputational damage. A multi-layered approach is key. Educate your IT teams and employe

es to minimize risk and maximize prevention. However, implement solutions to ensure data is secure and backed up. Finally, be prepared to remediate data systems through full backup and DR capabilities should your previous lines of defense fail.

 

Share this article on Twitter or LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Scroll to Top