Proper ransomware preparation
Ransomware attacks are devastating to an enterprise. Not many incidents short of a natural disaster have the impact that a ransomware attack has. While an APT-style network intrusion that aims to gain access to confidential data is severe, they often do not leave the entire network encrypted, especially if they are attempting to maintain a level of stealth so that the intrusion goes undetected.
In preparing for a ransomware attack, organizations should focus on two specific areas. The first is to make the network and endpoints resilient to the impact of a ransomware attack. This approach functions under the assumption that the threat actor may gain access to a system, but that proper preparation will leave them with little in terms of tools or methods to carry their attack any further from an initial foothold. The second preparation step is to ensure that the CSIRT is familiar with the TTPs of ransomware threat actors and is ready to meet the challenge...