Skip to main content

What the Hack? May 2022

Page 1

What the Hack? May 2022

www.seconcyber.com


Secon

02

May’s top cyber news. EU passes new law to strengthen cyber security resilience throughout its Member States. This month, the European Union has agreed on measures to promote a high standard of cyber security across the entire region. The new directive is called NIS2 and its goal is to ensure policies around cyber risk, management, and reporting remain consistent throughout the EU, therefore ensuring no one Member State falls behind. NIS2 introduces stricter cyber security requirements for companies, puts accountability for non-compliance with these cyber security rules on top management, and addresses the cyber risks associated with supply chains. The directive will also establish the European Cyber Crises Liaison Organisation Network (EU-CyCLONe), which will help organisations respond to and manage large scale cyber attacks. Additionally, there will be specific obligations for particular sectors, including energy, transport, health, public administration, digital infrastructure, and more. If an organisation does not meet its sector’s cyber security standard, it could be faced with sanctions to ensure cooperation. Margrethe Vestager, Executive Vice-President for a Europe Fit for the Digital Age, said: “This is another important breakthrough of our European digital strategy, this time to ensure that citizens and businesses are protected and trust essential services.” If you’re interested in what else NIS2 covers and how it may affect your organisation, suppliers, or customers, you can read the press release from the European Commission here.

Demand for cyber security professionals continues to grow. The cyber security skills gaps has continued to widen in the last 12 months according to the UK Department for Digital, Culture, Media & Sport (DCMS). The DCMS published its annual cyber security labour market report this month which reveals there were 4,400 new cyber security job postings each month in 2021. This is a 58% increase from 2020 and means the UK has an annual shortfall of 14,000 cyber professionals. This report also revealed that 51% of companies still have a basic skills gap when it comes to completing the core cyber security tasks outlined in Cyber Essentials. 37% of organisations have an internal skills gap when to comes to incident response, yet surprisingly, this proportion of organisations haven’t outourced these duties either. The government released its National Cyber Strategy 2022 at the end of 2021 which outlines what it’s doing to help tackle this problem, but those in the cyber security industry should also be considering what they can do to help address this growing, global problem. If you’re interested in what Secon is doing to help, click here to learn more.


What the Hack? - May 2022

03

On-demand webinar - How to easily discover new vulnerabilities and minimise your attack surface. As we become more dependent on online infrastructure and web applications, our attack surfaces are growing every day. This makes identifying all your critical vulnerabilities increasingly difficult. Thankfully, if you don’t have the internal resources to consistently hunt for vulnerabilities across your entire infrastructure, we’re here to help. In May, we ran a webinar highlighting Secon’s Vulnerability Scanning as a Service, which identifies where your vulnerabilities are and recommends where to prioritise your patching efforts. If you’re interested in learning how this service works and seeing a demo of our Vulnerability Scanning as a Service dashboard, click below to watch the webinar now.

What you’ll learn in this webinar. •

Why it’s imperative to consistently patch and manage your vulnerabilities

•

Why it can be difficult to identify vulnerabilities across your entire environment

•

How Secon can give you visibility across all your vulnerabilities in a single dashboard

•

How our Vulnerability Scanning as a Service makes it easy to decide which vulnerabilities need your immediate attention

•

How our service gives you the ability to demonstrate cyber security best practice for regulatory authorities and auditors

Watch now


Secon

04

How do I recover from a ransomware attack? Insight overview Ransomware attacks are on the rise, and they can greatly cost businesses which is why a good ransomware recovery plan is key. A successful ransomware attack will restrict access to devices and steal important data, with the business having to pay a ransom to get access back or recover stolen data. We understand how important business continuity is and planning for potential disruptions can lead to faster resolutions and peace of mind for everyone involved. In this article, we’re going to discuss what to do when you’ve been breached because good preparation can lower the impact an attack has on the business. Malware prevention is an important part of a robust cyber security system but with ransomware attacks tripling in the last few years, it’s important to get prepared for the possibility of a breach by understanding the steps to ransomware attack recovery. Having the right team and processes in place to recover from a ransomware attack is just as important as prevention. Below, we summarise the first few basic steps to ransomware recovery, but if you’d like to read about why ransomware continues to be a growing threat and the final steps we’d recommend, click here to read the full version of our article ‘How do I recover from a ransomware attack?’

1

Investigate A successful ransomware attack will often be discovered by a staff member who can’t access the documents or device infected. Your cyber security team’s first step is to assume that more than one user could be affected and they should identify infected systems, users who could be infected, what ransomware has been installed and the potential impact of the ransomware. Questions to ask yourself at this stage may include: •

Will this disrupt front-end services and internal systems?

•

Has any business or client information been lost?

•

Is it a network attack, data theft, or a mix of threats?

•

Has the attack put you in violation of contracts?

It’s important that identification happens quickly and is accurate as this will instruct the next steps of ransomware recovery: containment and eradication. Different types of ransomware have varying capabilities, so identifying the correct ransomware is key. While a team is focused on stopping the current attack and recovery, other members of the cyber security team will be focused on root cause analysis to instruct long term solutions such as patching of the vulnerability that led to the attack.

2

Remediate: Contain The goal of containment is to ensure the ransomware does not complete encryption and to stop it from spreading in the same network. This should include immediately isolating any infected devices from your network and shutting down or hibernating any systems that you can’t disconnect from your environment. Next, you should take a system image and memory capture from a sample of infected devices, which allows for analysis to take place knowing that the ransomware can no longer spread. The quarantine process should cut all access for the infected device and systems including access to cloud storage and software, single sign-on access, and system access to business tools. Also, be sure to collect all security logs and preserve evidence that’s highly volatile in nature or has limited retention during this stage. You may want to consider automating parts of your containment process so teams can focus on other areas. Some of the tasks in the containment phase can be time consuming and repetitive, so automation with orchestration tools can save you time and speed up ransomware recovery. If the analysis finds the ransomware came through email, the cyber security team will take measures to restrict incoming messages and may also delete all pending messages across all staff inboxes until the attacker’s IP and addresses have been blocked from the system.


What the Hack? - May 2022

Being prepared for the email system to be down is important in planning alternative all staff communication channels during a crisis such as SMS. In the case of a website compromise, the cyber security team will take measures to block the website from the business network. Containment may impact business operations including staff losing access to networks, customers losing access to websites and frayed relationships with impacted clients.

3

Remediate: Eradicate Eradication of the ransomware can be a lengthy process depending on the severity of the attack as it involves removing the malware from infected systems across the organisation. If it is a single device that has been infected, eradication will be easier than an incident where ransomware has attacked multiple devices across a network. This is because the individual infected devices will need to be assessed and rebuilt, but also potential key machines in the IT infrastructure could also need to be taken offline, assessed, and rebuilt. To make this process easier, we suggest organisations follow a 3-2-1 backup strategy. This involves always keeping three copies of data (one primary and two backups), keeping data on at least two types of storage media, and storing one of these offsite in a place that doesn’t have network connectivity to your environment. Steps to consider at this stage: •

Specify tools and procedures to rebuild infected systems

•

Restore from clean backups

•

Confirm endpoint protection is up to date and enabled

•

Monitor for re-infection and conduct analysis to identify outside-in and inside-out persistence mechanisms

•

Specify what financial, personnel and logistical resources are needed to accomplish full remediation.

To read the next steps of our ransomware recovery strategy, click here to read the full article.

05


Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707

www.seconcyber.com


Turn static files into dynamic content formats.

Create a flipbook
What the Hack? May 2022 by Secon - Issuu