The Realities of Ransomware. Prevent, Protect, Prepare. | Impact Makers

The Realities of Ransomware. Prevent, Protect, Prepare.

Over the past year, there have been several high-profile ransomware attacks in which the target paid the ransom.

In May, Colonial Pipeline was hacked with ransomware by DarkSide. This left many on the East Coast without gas and caused panicked gas stockpiling. Eventually, Colonial Pipeline paid the hackers $4.4 million and were provided a decryption tool. However, the process took so much time, the pipeline went down anyway.

More recently, JBS USA Holdings Inc. paid $11 million following an attack on their meatpacking plants, though payment was made after their plants were up and running again.

In each scenario, the CEOs have attempted to justify their position for paying the ransom. Yet there is no excuse (regardless of whether or not the money was recovered). Paying the ransom is a short-term gain, long-term loss proposition. There are better ways to deal with ransomware. As cybersecurity professionals, this incident is both alarming and disappointing.

This ought to be a wake-up call for organizations considered to be a part of necessary infrastructure.

What is Ransomware?

According to the Cybersecurity & Infrastructure Security Agency, ransomware is malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption.

Why you should NOT pay the ransom:

There are several key reasons why security professionals universally advise against paying the ransom:

How organizations should address the threat of ransomware

The threat of ransomware is real, and unfortunately it is only becoming more prevalent. At Impact Makers, we advise clients to focus on: Prevention, Protection, and Planning.

Ransomware keeps many cybersecurity professionals and business executives up at night. While it is not something anyone ever wants to deal with, it should not be something that catches anyone off-guard.

Consider the following questions to gauge your organization’s preparedness against the threat of ransomware:

If you answered “No” or “Unsure” to any of the questions above, reach out to our team of cybersecurity consultants to see how Impact Makers can help.