Enhancing security and regulation compliance within the Irish public sector via Privileged Access Management (PAM)
Ransomware is rampant
The threat from ransomware shows no signs of diminishing. The attack reports that make it into the general news or the specialist IT press are just the tip of the iceberg. One group that has been causing alarm with cybersecurity professionals is the Conti gang.
In late September, the US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert about the activities of the Conti gang. CISA and the FBI reported that the Conti gang had mounted over 400 ransomware attacks. These attacks were global in nature and targeted critical infrastructure, showing that the Conti gangs morals were low even by the standards of cybercriminals. Many of the targets for the Conti gang were and remain healthcare providers. The gang is not some abstract threat for the Irish cybersecurity community, as Conti ransomware had a devastating impact on the Irish Healthcare system earlier in 2021.
The Conti ransomware gang operates what is known as a ransomware-as-a-service (RaaS) model. Within this model, they use typical attack methods to gain access to deploy their ransomware. These include phishing and targeted spear-phishing campaigns, exploiting known issues in remote management and remote access software, and other known vulnerabilities.
The threat from the Conti gang to healthcare systems and other public sector organisations is so high that the National Cyber Security Centre in Ireland has issued an advisory alert on the topic. You can download a PDF of the advisory from https://www.ncsc.gov.ie/pdfs/Conti_270921.pdf.
The NCSC Conti Advisory
The NCSC Conti advisory outlines 13 areas where organisations should take cybersecurity measures to reduce the risk from the Conti ransomware. These protections are also applicable for reducing the risk from other attacks and for good cybersecurity in general. We highly recommend that you download the advisory and act on its recommendations.
Two of the areas discussed in the advisory are Access Control and using VPNs to control access to IT systems. Doing both of these provides a massive boost to cybersecurity protection.
Renaissance partner Systancia provides solutions in access control that deliver industry-leading protection. Read on for an overview of these.
Access Control
The NCSC Conti advisory has this to say about Access Control —
Access Control – Constituents should employ a policy of least permission. Only those who need access to a system should have access and the permissions that users have should be just sufficient to carry out their work. Domain administrator and local administrator permissions should be restricted to System Administrators.
Systancia Cleanroom delivers this level of access control (and more) via Privileged Access Management (PAM).
Systems protected with Systancia Cleanroom, use workflows that deliver controlled access each time a user needs to log on. Each session requires that they follow an agreed workflow and authorisation process involving two others who authorise the access. Systancia Cleanroom also implements comprehensive logging and recording of all activities on PAM controlled systems so that an audit trail is available — comprehensive logging is another one of the 13 areas recommended in the NCSC Conti advisory.
Full details of Systancia Cleanroom are available on their website, but here is a summary of the features:
- A password vault - Secure storage of passwords that grant access to the PAM secured systems.
- Recording sessions - Recording of privileged users sessions with later viewing of these sessions in video format available if required.
- Traceability of actions taken - Traceability of privileged users actions in detailed logs in order to be able to identify the activities carried out and who performed them.
- Programming protective actions - Prevent certain activities from being performed on the PAM controlled systems. Such as preventing specific command-line programs from executing or removing access to dangerous UI elements.
- Real-time detection - Real-time detection of abnormal or suspicious behaviour.
- Intrusion detection measures - Intrusion detection as soon as suspicious behaviour occurs and before it is too late to prevent damage or data loss.
- Transparent secure access – Detection of the administrator's connection conditions, and if an external access is detected, it automatically encapsulates the connection flow in an SSL VPN flow. This encapsulation is carried out in a completely transparent way for the user.
The NCSC Conti advisory also recommends using additional authentication security —
Enforce Multi-Factor Authentication (MFA) – Multi-Factor Authentication should be enforced on all user accounts as well as Remote Desktop Protocol (RDP) accounts.
Systancia's Remote Access solution enables MFA security for remote access and more, as part of the Systancia zero trust value chain. We discuss this within the concept of VPN access below.
VPNs For All Users
The NCSC Conti advisory recommends VPN use as follows —
VPNs For All Users – Make sure users access your network through a VPN (Full Tunnel where possible) at all times. Full-Tunnel, always-on VPNs are the preferred options as this provides all home users with access to the organisation network from behind the network stack. The current climate means a significant portion of the workforce are working from home making it increasingly challenging for IT security team to ensure that networks can’t be compromised via a poorly secured user device. Robust VPN services are the most effective measure to providing safe and secure remote access.
VPN access has been a staple in secure remote access for decades. As the threats targeting systems have evolved, so have the VPN like remote access solutions needed to deliver the secure remote access the current threat landscape requires.
One solution that encompasses VPN based remote access security is Zero Trust Network Access (ZTNA). Forrester Research analysts coined the ZTNA term to describe emerging cybersecurity solutions that contained and surpassed the traditional VPN approach.
Zero trust needs secure remote access at its core. ZTNA goes beyond this and assumes that all users are potentially hostile and dangerous, irrespective of how they are accessing systems. No access route gets preferential security clearance. The connection can come over the Internet or from a PC in a central office, but both need to pass the same checks to gain access. Not just once, but for every system and service they try to access throughout the working day.
One such ZTNA solution that provides the security needed today and has the integration into other parts of the security stack is Systancia Workroom. It delivers secure access that goes beyond VPN —
- Uses the least privilege principle - Allows access only to the bare minimum of resources needed in any session and continuously traces all actions taken.
- Checks device compliance - Monitors devices that are connected and looks for abnormal behaviour.
- Implements multi-factor authentication - Uses complex multi-factor authentication procedures that enable strong cybersecurity authentication without being onerous for users.
Conclusion
All organisations in the public sector and beyond should implement the recommendations outlined in the NCSC Conti advisory.
To deliver least-privilege based access and secure remote access that goes beyond what VPN provides, talk to Renaissance today about how the Systancia platform can supercharge your cybersecurity protection against Conti ransomware and other threats.

