Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Gatekeeping and Treatment of Others Rants

Ransomware, Are You Ready?

Posted on June 17, 2021 By Michael Kavka No Comments on Ransomware, Are You Ready?

Developing a Ransomware plan is much like anything else. Sounds simple, protect against malware. The reality though is much different, and it starts with a properly educated security team to come up with a comprehensive and cohesive plan.

You need to know how your network is laid out. A flat network (which you find in a lot of Small Businesses) needs extra consideration if it is going to stay flat. If you are segmented, how are you segmented.? Do you have any pull with the network team to adjust ACLs, Firewall rules and topology to a more secure setup?

Do you know what your company’s crown jewels are? What data is the most valuable, what data is ok to be without for a period? This helps you direct what needs the best protection when you need to decide what gets budgeted for (hopefully everything) or if you must be selective due to costs.

Do you have offline or immutable backups? Are they stored in a different location (say the cloud or a cold storage physical spot)? Do you have a fully functioning copy of your Domain Controller that is kept offline except for an occasional sync with the other DCs? That cold DC could get you back up and running much faster than without one.

Have you tested your backups? Have you tested a full bare metal restore of your servers? Do you know what order to bring the servers back online in? Are you sure that you are not just opening yourself up to another attack because your backups have the threat actors backed up in them?

Do you have buy in from all the departments involved and from the higher ups? Have you multiplied the time to restore by 3 to account for issues with restoring functionality?

This is just a quick list of some things to think about. Truth be told, even if you pay the ransom and get everything back, you must figure you are ready to be compromised a second time. Better to get the data and figure everything is going to be a loss in the long run so plan on rebuilding everything while using the old servers to keep things running.

Ransomware is a tough topic, and one that is foremost on the executive mind currently. How long until it drifts into the background like so many other issues do when a new tactic comes along. This is the change to build that defense, which can aid in other defenses. Just make sure you are covering everything.

 

General, Security Tags:Ransomware

Post navigation

Previous Post: Gatekeeping and Treatment of Others
Next Post: Device vs. User

Related Posts

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • Defender, KQL and Lockbit Microsoft
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Are you sure it is the execs? Ramblings

More Related Articles

Security is Reactionary, No Matter What Security
New Year, New Post, from the start General
Defender, KQL and Lockbit Microsoft
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Are you sure it is the execs? Ramblings

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • "Objective by the Sea" v2.0 September 24, 2026
  • Burned by Fire(fox) (Part II) September 24, 2026
  • Burned by Fire(fox) (Part I) September 24, 2026
  • Getting Root with Benign AppStore Apps September 24, 2026
  • Burned by Fire(fox) (Part III) September 24, 2026
  • Mac Adware, à la Python September 24, 2026
  • The 'S' in Zoom, Stands for Security September 24, 2026
  • [0day] Abusing XLM Macros in SYLK Files September 24, 2026
  • Pass the AppleJeus September 24, 2026
  • Mass Surveillance, is an (un)Complicated Business September 24, 2026
  • Lazarus Group Goes 'Fileless' September 24, 2026
  • The Mac Malware of 2019 September 24, 2026

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • "Objective by the Sea" v2.0 September 24, 2026
  • Burned by Fire(fox) (Part II) September 24, 2026
  • Burned by Fire(fox) (Part I) September 24, 2026
  • Getting Root with Benign AppStore Apps September 24, 2026
  • Burned by Fire(fox) (Part III) September 24, 2026
  • Mac Adware, à la Python September 24, 2026
  • The 'S' in Zoom, Stands for Security September 24, 2026
  • [0day] Abusing XLM Macros in SYLK Files September 24, 2026
  • Pass the AppleJeus September 24, 2026
  • Mass Surveillance, is an (un)Complicated Business September 24, 2026
  • Lazarus Group Goes 'Fileless' September 24, 2026
  • The Mac Malware of 2019 September 24, 2026
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Gatekeeping and Treatment of Others Rants

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.