Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Gatekeeping and Treatment of Others Rants
  • Are you sure it is the execs? Ramblings

Ransomware, Are You Ready?

Posted on June 17, 2021 By Michael Kavka No Comments on Ransomware, Are You Ready?

Developing a Ransomware plan is much like anything else. Sounds simple, protect against malware. The reality though is much different, and it starts with a properly educated security team to come up with a comprehensive and cohesive plan.

You need to know how your network is laid out. A flat network (which you find in a lot of Small Businesses) needs extra consideration if it is going to stay flat. If you are segmented, how are you segmented.? Do you have any pull with the network team to adjust ACLs, Firewall rules and topology to a more secure setup?

Do you know what your company’s crown jewels are? What data is the most valuable, what data is ok to be without for a period? This helps you direct what needs the best protection when you need to decide what gets budgeted for (hopefully everything) or if you must be selective due to costs.

Do you have offline or immutable backups? Are they stored in a different location (say the cloud or a cold storage physical spot)? Do you have a fully functioning copy of your Domain Controller that is kept offline except for an occasional sync with the other DCs? That cold DC could get you back up and running much faster than without one.

Have you tested your backups? Have you tested a full bare metal restore of your servers? Do you know what order to bring the servers back online in? Are you sure that you are not just opening yourself up to another attack because your backups have the threat actors backed up in them?

Do you have buy in from all the departments involved and from the higher ups? Have you multiplied the time to restore by 3 to account for issues with restoring functionality?

This is just a quick list of some things to think about. Truth be told, even if you pay the ransom and get everything back, you must figure you are ready to be compromised a second time. Better to get the data and figure everything is going to be a loss in the long run so plan on rebuilding everything while using the old servers to keep things running.

Ransomware is a tough topic, and one that is foremost on the executive mind currently. How long until it drifts into the background like so many other issues do when a new tactic comes along. This is the change to build that defense, which can aid in other defenses. Just make sure you are covering everything.

 

General, Security Tags:Ransomware

Post navigation

Previous Post: Gatekeeping and Treatment of Others
Next Post: Device vs. User

Related Posts

  • New Year, New Post, from the start General
  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Are you sure it is the execs? Ramblings
  • The one about banking passwords… Rants

More Related Articles

New Year, New Post, from the start General
Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Are you sure it is the execs? Ramblings
The one about banking passwords… Rants

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

Active Directory Android Antivirus Apple Beta Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches Rants SBS SBS 2008 Security Security Patches Server SMB Software Support Surface TechEd Tweets Ubuntu Verizon Virus Vista vulnerabilities Windows Windows 7 Windows 8 XP

RSS Taggart Institute Intel Feed

  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Gatekeeping and Treatment of Others Rants
  • Are you sure it is the execs? Ramblings

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.