When is it too late to protect against Ransomware?
Ransomware is the most severe cybersecurity threat facing organisations of all sizes. Attacks continue to come from criminal gangs such as Conti, Blackmatter (a rebranding of the Darkside and REvil ransomware gangs), and many others. There are no signs that the number of ransomware attacks will diminish any time soon.
Protecting Against Ransomware
Protecting against ransomware is vital for all organisations. There are no single magic solutions that you can deploy to protect networks, devices, data, and users. Protection against ransomware, and other cybersecurity threats, requires a range of defences and operational IT activities. These include well-tested backups, strong perimeter firewalls, endpoint protection and response (EDR) software, strong identity management, privileged access management on critical systems, effective staff awareness cybersecurity training, rapid deployment of system security updates, and good IT Security Information and Event Management (SIEM) systems that tie aspects of the security protection together to provide the overall picture and allow rapid responses. Note that this is not an exhaustive list of the defences and activities required to deliver robust cybersecurity protection.
Bullwall RC Provides the Ultimate Safety Net
The cybersecurity threat landscape is constantly changing, and cybercriminals continue to find and develop new ways to bypass cybersecurity protections. The protections listed above should all be in place and kept up to date, but it’s best to assume that at some point someone will make a mistake or criminals will find a new way to bypass security. When that happens, you need to have a solution to detect it quickly and prevent the infection from spreading.
Bullwall RC is a solution that monitors your on-premise and cloud-based file stores for the tell-tale signs of ransomware encryption activity. It detects such activity in milliseconds, and infected devices get isolated from the network and immediately shut down. The Bullwall RC management console shows infected devices so you can troubleshoot how the ransomware got onto the network. You can also see exactly which files on networks stores were encrypted before the device was isolated and shut down. This allows you to see which files on network stores will need restoring from backups. The best practice for the device is to wipe it and reimage it from standard deployment images and restore data from backups.
It’s worth emphasising that Bullwall RC is not trying to replace other cybersecurity defences deployed in an organisation. No, it’s providing a safety net that doesn’t rely on detecting specific ransomware types but instead detects file encryption activity and stops it from spreading from infected devices. Because of this, RC can prevent new ransomware types that have found a way past other security software because it detects the destructive encryption that all ransomware uses. However, the best approach is to stop ransomware from infecting systems and to have Bullwall RC as the last line of protection just in case.
Agentless Protection
Bullwall RC is an agentless solution. The devices do not need an agent or client deployed to deliver the protection, nor does it look for specific ransomware signatures. A single Bullwall RC server gets deployed in a virtual machine that monitors the network traffic and file stores for encryption activity. This server instance initiates client shutdowns over the network when ransomware encryption activity is detected. Irrespective of what type of ransomware is active, it’s the encryption that is detected and stopped.
Protects Your Cloud Files as Well
Most organisations have files in the cloud using Microsoft 365, Google Cloud, and other public cloud providers and web apps. Bullwall RC also provides detection for encryption activity in cloud-based file stores. Plus protection using the same shutdown mechanism to isolate any end-user devices initiating ransomware encryption activity.
Hardware Ransomware Entry Points are also Covered
Infected USB devices are a common way for ransomware to infect a device. This attack method is not limited to infected USB storage devices but includes ‘smart’ USB cables that have ransomware stored within them. Cybercriminals will often sell these cables cheaply or give them away for free to get people to plug them into their computers (use your awareness training to highlight this!) Bullwall RC instantly detects when ransomware gets introduced via a hardware device and isolates the infected machines.
Bullwall RC Overview Video
Bullwall has a 6.5-minute overview video on their YouTube channel that quickly demonstrates the features mentioned above: encryption detection, shut down, cloud protection, and hardware-based entry points. You can view the video at https://www.youtube.com/watch?v=VAjmpbkwFWI
Connect with Progress Bullwall Experts at Cyber Expo
Experts from Bullwall will be attending Cyber Expo & Conference Ireland 2022. They will be present in the Expo Hall, where you can chat with them about their platform. They will also be part of the expert presentations and panel discussions within the Always on Computing and the Cyber in Healthcare conference streams. The Cyber Expo & Conference Ireland is on the 28th of April 2022 in The Leopardstown Pavilion at Leopardstown Racecourse, and you can register to attend via this Eventbrite page.
Conclusion
The ransomware threat is not going away any time soon. Robust cybersecurity protections at multiple points and layers with an IT infrastructure should be in place to deliver protection. Bullwall RC provides a safety net that detects and stops any malware that initiates file encryption on your file stores.
If you would like to chat with an expert about Bullwall RC, then contact Renaissance. Also, sign up for the Cyber Expo & Conference, where you can talk to the Bullwall team and many other cybersecurity experts in person.

