Cyber Security

Is WannaCry a Wake Up Call?

Is WannaCry a Wake Up Call?

Over the weekend deadly WannaCry virus, the biggest attack of its kind ever recorded, swept the globe which has resulted in sleepless nights for many IT and security professionals in over 150 countries. With the ransom clock steadily ticking choices had to be made... to pay or not to pay?

As the attack begins to slow, big questions have certainly been raised. This is a resounding reminder of the importance of cyber security in organisations of ALL sizes and in ALL industries. Ransomware is not new and it is no longer being carried out by amateurs, it is gaining momentum year on year with attacks and ransoms becoming larger and more destructive.

One way to protect your data is to back up frequently. Keep current backups of your most sensitive data offline. Coincidentally this is Business Continuity week, and after the events at the weekend there is no better time to formulate a robust incident response programme, to carry you through a period of disruption if it were ever to happen in the future. Consider these three questions...

 

1. What do you do in the lead up to a crisis?

2. How do you respond to a crisis?

3. How can you effectively recover from a crisis?

 

To protect against ransomware and other attacks it is vital that networks are patched. You have probably heard the phrase ‘patch early and patch often’… this is the essence of an effective patch management plan.

Patching is the process of uncovering vulnerabilities within a computer, system or network. Simple antivirus software will not protect against all forms of malware; therefore, a multi-layer approach is required for full network protection.

Patching works to cover up the ‘holes’ in which a hacker can gain unsolicited access to data. Vulnerability patching remedies 65% of potential hacking sources, covering around 99% of security critical apps. Patching aims to increase the efficiency, usability and performance of a system or network... a solid technical infrastructure is crucial!

 

See 4 steps below for your organisation to follow to maintain secure networks…

 

1.   Be Proactive

A good way to kick-start your patching process would be to identify the inconsistencies of your devices. E.g. not updating software that can leave your network open to potential threats. Initiating an effective cyber security management plan with frequent monitoring is essential for optimum security. IT and security professionals must be aware of the risks involved and should prepare contingency plans for unforeseen breaches.

 

2.   Formulate a Robust Testing Strategy

Not all patches are compatible for software and devices. Therefore, it is important to eliminate those which don’t match up appropriately and to keep those that do. Before deployment it is best practice to run tests to be sure that your patch(s) will work accordingly with your system(s). After thorough testing has been carried out, inefficiencies will be evident and failures can be rectified as a result.

 

3.   Tailor your Patch Deployments according to the needs of your Business

A monitoring process will allow checks to be made on a regular basis. This is a task that can often be overlooked by IT professionals within organisations due to other tasks taking priority. However, it is essential that a schedule is drawn up and adhered by to save your organisation time and expense.

 

4.   Construct a suitable Remediation Plan

Regular reporting is essential to view what works well, patch reports can help determine the success of patch management programmes. Results found from these reports can also help determine an effective remediation plan for an organisation.