ransomware - the channel company€¦ · ransomware survey results 91% of it support providers...

46
Ransomware: DANGER AHEAD BRIAN WEAVER Vice President of Sales

Upload: others

Post on 28-Sep-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware: DANGER AHEAD

BRIAN WEAVERVice President of Sales

Page 2: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

What is Ransomware?

Encrypts files so you can’t use them

Encrypts all network shares

Demands money (in bitcoin) in order to gain access to your files

Page 3: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware is exponentially growing and spreading

Page 4: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware incidents are skyrocketing…

➢Over 4 million variants

➢Over $ 1 Billion paid to “unlock” data

➢Department of Homeland Security answer ??

➢Payment in Bitcoin, as it is untraceable

➢More sophisticated phishing techniques used

➢It isn’t a matter of “if” but “when” your company will be hit… will you be ready for it????

Page 5: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

What does Ransomware Look Like?

Page 6: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 7: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Watch Your Back!

Don’t Become a Victim of a Hack!

Page 8: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

8

Page 9: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

WE’LL JUST RESTOREFROM OURBACKUP SOLUTION

Page 10: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

NETWORK DOWNFORTWO DAYS

(FRIDAY & SATURDAY AFTER THANKSGIVING)

Page 11: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

SFMTAPROVIDES735,000 RIDES A DAY($1 – 2.25 PER RIDER)

Page 12: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

TOTALREVENUELOST

$1.5 – 3.3 MILLION!!

Page 13: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 14: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 15: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 16: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 17: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 18: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 19: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

WannaCry

Page 20: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

The next Epidemic…

Page 21: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

US Dept. of Homeland Security Alert

Page 22: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware Survey Results

✓ 91% of IT support providers surveyed have dealt with ransomware in the past 2 years

✓ 43% have dealt with 6 or more instances of ransomware in the past 12 months

✓ 94% of ransomware victims had Anti-Virus/Anti-Malware in place

✓ Only 15% of ransomware victims had basic cyber security training for their employees before the attack

Page 23: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

INVERSE TECHNOLOGIESRaaS Made Easy!

A Social Experiment…..

Page 24: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

How Can I Safeguard My Company?

✓ Training: At least once/year, company wide & all new employees

✓ Make Certain Firewalls & Endpoint Security is up to date

✓ Keep up on the latest phishing methods & communicate them to all associates

✓ Look for unusual IT activity, executables running

Page 25: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

What Happens When the Safeguards Fail?Early Detection is Key!

➢Ransomware leaves a footprint

➢Notification when a likely ransomware attack is occurring

➢ Identify the last clean backup for quick restore

Page 26: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

What to Do If You Are Infected with Ransomware

✓ Have a Cyber Incident Response Plan in Place

✓ Don’t pay the ransom!

✓ Contact your IT Support provider

✓ Restore from a backup

Page 27: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Traditional Backup vs. Business Continuity

What isn’t CONTINUITY?

➢Cloud Only

➢Local Only

- Including Tape

➢File Based BackupDESKTOPS

PHYSICALSERVERS

CLOUDSERVERS

Page 28: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

What is “CONTINUITY”?

Continuity is:

✓Hybrid cloud-based backup

✓ Image-based backup

✓Delivers superior

➢ RTO (how much downtime)

➢ RPO (how much data are you willing to lose)

✓Eliminates downtime (Virtualization)

Page 29: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 30: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 31: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 32: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware Trends in 2017

Page 33: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Targeted attacks on business more frequent (up 3x)

Page 34: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Spear phishing: using social media, mass exploits down 65%

Page 35: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

New Ransomware variants dramatic growth (up 30x over 2016)

Page 36: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Ransomware-as-a-Service debut (Cerber affiliate program) 40%

Page 37: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Once attacked, majority of firms are infected (71%)

Page 38: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Beyond data encryption (threat to release data publically)

Page 39: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Delayed encryption (getting into more systems, vendor, customers, etc)

Page 40: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 41: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

1100 MSPs surveyed from around the world about Ransomware

$75 billion in Downtime per year

Page 42: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 43: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more
Page 44: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Best Practices Elements for a BC/DR Solution:

Redundancy of back-up, no single point of failure (local & cloud – with multiple DC’s)

Fast Recovery Time Objective (RTO), dictates an image-based capability

Image-based for multiple operating environments (windows & linux)

Ability to run infrastructure from the Cloud environment, time enough for a physical infrastructure recovery

Continual confirmation that backups are happening as planned

Page 45: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

Best Practices Elements for a BC/DR Solution:

Detection/alerting of “ransomware in progress” to potentially head off encryption before it happens

Ability for capacity for future growth in storage/disk space needed

Short Recovery Point (RPO)Technology that is not dependent on a string of prior backups all needing to be clean

No limit on Cloud Storage, enabling retention of historical data as long as needed

Page 46: Ransomware - The Channel Company€¦ · Ransomware Survey Results 91% of IT support providers surveyed have dealt with ransomware in the past 2 years 43% have dealt with 6 or more

BRIAN WEAVERVice President of Sales

[email protected]