Don't Let Cyber Criminals Hold You To Ransom

16 March 2024 | Blog | By:

Small Business Guidance

‘Ransomware’ is a particularly disruptive type of malware and is commonly delivered through phishing emails with malicious attachments or malicious embedded links. The victim’s file and or data will be encrypted by the cyber attacker. The result of which, is that the files, data and system that rely on them will be totally unavailable. The cyber attacker will then demand a ransom payment, normally in cryptocurrency, from the victim with the promise of restoring access to their files and data. Remember, that there is no guarantee that the victim’s access to their files and or data will be restored, even after paying the ransom.

What Should You Know ?

Ransomware attacks are fast becoming the most common and lucrative attack methods for cybercriminal. The cyber attackers will target individuals and private sector businesses of any size. We know from media reporting, that all types of business have been targeted and have fallen victim to ransomware attacks.

Awareness of the risks and the potentially damaging impact of ransomware cyber-attacks is key for an organization when deciding on the appropriate measures to put in place to defend against and mitigate the consequences if unfortunately, they do fall victim to a ransomware attack.

You should ensure that you have in place a tried and tested regime of regular backups. Cyber attackers commonly target backups kept online, so you should ensure that you also have backups which are kept offline.

Phishing emails are a common method used by cyber attackers as an entry point for their ransomware attacks. You should provide regular cyber security awareness training to your personnel who have access to your digital resources, so that they don’t fall victim to phishing attacks.

You should ensure that your security software and operating system are up-to-date.

You should implement robust security products to protect your system from all threats, including ransomware threats.

Finally, you should never pay the ransom to cyber attackers, as this will serve to embolden them and may even open you up for further attacks and further ransom demands. You may lose twice if you pay; you may never see your files or data again and it is unlikely you will to get your money back. It is better to have a tried and tested means of recovery in place.

What Should You Do ?

If you have been the victim of a ransomware attack or demand, you should always report it to the RCIPS, as it’s a criminal offence.

Report to RCIPS, call 911

You Don't Need To Lift Weights To Have Strong Passwords

Passwords are still a most common way to secure our online accounts and our organisation’s computer systems and data. If the cyber attacker is able to compromise your organisation’s password, they will have access to your systems and data, so it is important that your passwords are not easy to compromise.

What Should You Know ?

‘Weak’ password is the term used to describe passwords that are short in the length, contain commonly used words, or easy to guess or figure-out. Examples of ‘Weak’ passwords are 1234, 123456, password123, passw0rd, abc123, qwerty, the name of your pet, the name of your school or the like.

For convenience, people generally are in the poor habit of reusing the same password across multiple online personal accounts and their work-place systems. This poor practice, provides the cyber attacker with a ‘helping hand’, if say one of your online passwords is compromised (i.e. because known), the cyber attacker, will always try the already compromised password as part of their way into your other online accounts and work-place systems. The cyber attackers also have tools, such as specialised software programs to automate the task of ‘cracking passwords’.

‘Strong passwords’ are more difficult for cyber attackers to compromise, even with the use of automated tools and software. Typically, a strong password is between 10 and 15 keyboard characters in length, remember, the golden rule, that the longer the password, the more difficult, it will be for the cyber attacker to compromise.

The trouble with ‘strong’ passwords is remembering them, so that you don’t have to write it down. A tip is to think about three words that are meaningful and memorable to you and then include one or two numbers in between that are memorable to you.

What Should You Do?

As part of a regularised programme of staff awareness, staff should be advised that they should never reuse passwords across multiple online accounts and work-place systems. The staff awareness should also include, staff being advised to immediately change their password, if it is suspected that their password has been compromised.

If the work-place systems can enforce a regular change of passwords or a minimum password length, then these features should be enabled by the IT Department or other relevant person.

Where Two-Factor Authentication (2FA) is available, this should always be enabled on online accounts and work-place systems.

The organization should consider implementing appropriate security systems or enable features in existing systems, to monitor and detect any suspicious login attempts and take appropriate action.

Report to RCIPS, call 911

 

Last updated: