Critical Steps to Defeating Ransomware in 2021
The number of ransomware attacks recorded has exploded over the last few years. This is mainly due to the relative ease with which cybercriminals can mount them, and the financial and other rewards that flow from a successful attack. And there are plenty of successful attacks to keep the bad actors interested. Ransomware is easily the most used form of malware attack today. The figures are stark - a 109% increase in attacks in the last year within the USA, with similar growth seen globally. The costs associated with recovery from a successful ransomware attack typically exceed $230,000.
No organisations are immune to ransomware attacks. It’s not just the big-name brands that are attacked. More than half of the known attacks target midsize and small hospitals, government services, schools, food production, law firms, and manufacturing companies. A defence based on obscurity is not a defence at all. Thinking your organisation is too small or low-key to be attacked is a recipe for disaster as it will impact the protections put in place.
The ransomware variants being detected across the IT landscape are getting smarter; they use multiple techniques to bypass security measures that have traditionally been used to protect the network perimeter. These new variants are defeating endpoint security, exploiting VPNs, and compromising backup systems so that falling back on the last good backup isn’t a viable option. It’s not all doom and gloom. Steps can be taken by organisations of any size to monitor for and guard against ransomware attacks. We outline five important steps below.
CyGlass and Renaissance can provide easily deployed cloud-based solutions to protect organisations against existing and emerging ransomware attack methods. Using AI, prebuilt policy packs, and reports, CyGlass helps organisations see risks, stop threats, and prove networks are compliant with industry regulations. AI-driven Smart Alerts provide IT teams with visibility and actionable intelligence to the threats that matter. Affordable and easy to deploy and operate, CyGlass puts enterprise-class threat detection and compliance in the hands of small and medium organisations worldwide.
Contact Renaissance to find out more.
Step 1 - Monitor your backups for anomalous behaviour
Ransomware encrypts your data and then demands a ransom is paid to obtain a key to decrypt systems. Many organisations will wipe infected IT systems and restore them from the last good backup. Cybercriminals know this, so they have started to look for backup systems on networks they have compromised and then turn the backups off before they encrypt the data. They often wait a few days or weeks before activating the encryption, so that the backups are out of date.
If backups suddenly stop working, it is often an indicator of compromise (IOC) that an attack has taken place and the network has been breached. Any anomalous behaviour with backups needs to be investigated immediately.
Step 2 - Ensure endpoint monitoring and protection is current
A large number of successful ransomware attacks gain access via compromised endpoint devices. Endpoint security must be deployed to all devices, kept up to date, and alerts from the devices monitored and actioned immediately.
The number of devices and the data they process is huge. AI machine learning systems are ideally placed to monitor everything and spot anomalies.
Step 3 - Monitor remote access activity
The last year has seen an enforced explosion in the amount of remote working. Cybercriminals have not missed this and have actively sought to exploit it. VPN access systems are visible to automated scanners over the Internet, and once discovered, cybercriminals can probe them for security weaknesses. And use any they find to gain access to deploy ransomware.
All VPN and other remote access technologies should do comprehensive logging of all activity. These logs can be monitored and mined in real time to look for anomalous behaviour, such as changes in data volumes flowing in or out of the network, out-of-hours activity, and connections from unusual locations.
Step 4 - Monitor activity on the internal network
All ransomware has to move files across the network to infect new systems and increasingly, in recent variants, copy data to servers out on the Internet. They copy this data before they encrypt locally, in order to use it to plan new attacks and sell on the dark web.
Ransomware has become very good at evading detection on IT systems. But it can’t evade the detection of unusual network traffic patterns. Monitoring for strange activity on the network and acting on anything seen is vital in defending against ransomware attacks. Again, the use of AI-based monitoring is becoming common.
Step 5 - Monitor everything and respond effectively
It can be difficult for most organisations to devote the resources required to monitor all components of their IT infrastructure continuously. Deploying cloud-based AI monitoring tools can bridge the gap and give small and medium organisations the same protection.
These cloud-based machine learning systems collect network, cloud, and VPN data, then use combined AI and prebuilt ransomware detection/prevention policy packs that give small teams the ability to understand their risk posture for malware attacks and the ability to detect and block these attacks 24x7.


