Step Four: Lateral Movement
As ransomware attackers gain access to more systems, they’re able to cross into connected networks to launch secondary attacks. This could be in a third party’s environment, or maybe through a subsidiary network or business unit. This phase of an attack might last weeks or months, with ransomware groups lingering in shadow environments even beyond an initial identification and remediation or payment cycle.
How to fight back against lateral movement: Organizations have seen success combating lateral movement by following a “zero-trust approach” to network security, meaning employees must have different accounts and log-ins to different programs, business unit networks, and high-stakes internal systems. It is also important to maintain visibility into potential ransomware impacting your third party networks.
Any ransomware attack that is happening and spreading through your vendor network might also be targeting you. With vendor scanning and historical performance data, vendor risk managers can act quickly when ransomware is present in their third party ecosystem, sometimes before a vendor has communicated the breach to them.
Step Five: Infection
In this phase, attackers can move forward with the “data stealing” now that they have mapped out where critical data lives. Ransomware groups will encrypt network files, cloud storage, backup systems, and critical data to prevent organizations from restoring their data and push them towards paying ransom.
How to fight back during infection: Besides the previously mentioned scanning and network monitoring technology to enable your team to act on ransomware indicators as efficiently as possible, the effectiveness of infection can also be mitigated using secure systems for data backup. With multiple types of data backup (using potentially costly solutions) organizations can reduce the effectiveness of a ransomware attack by eliminating the need to pay ransom.
Step Six: Extortion
This is when the ransomware attack usually becomes public knowledge. During extortion, organizations become aware of their compromised data, and how much money the bad actors are demanding in return for it. The compromised organization may face a complete or partial halt in company operations, which increases the pressure to work with the ransomware group.
Attackers often take it a step further, and are targeting organizations with double or triple extortion attacks. Double extortion is when ransom is demanded for the return of an organization’s data or compromised information, plus an additional ransom in exchange for not publishing exfiltrated data on the Dark Web. Some cyber criminals take it even a step further and also target a business’s customer pool directly to demand payment in return for their personal data not being shared on the Dark Web. Triple extortion attacks are a bigger threat for industries like healthcare where there is obvious sensitive patient data to target.
How to fight back during extortion: There is an ongoing debate whether or not to pay ransomware groups during an attack, versus working to resume business operations or restore data in other ways (usually with extensive work from an organization's internal security team). Many security leaders hold the belief that paying ransom only incentivizes groups to conduct future attacks.
If a company decides to pay ransom, it is not guaranteed to get a full return of their data. Ransomware attack groups often are not operating with fully moral standards of deal-making, and are just as likely to leave an organization empty-handed after receiving payment.
When deciding how to fight back during a ransomware negotiation, an organization may find value in cybersecurity insurance plans that cover ransomware attacks. Alas, ransomware isn’t covered in many insurance options, and some security experts warn against insurance as it makes companies even more of a target.
What’s the Best Way to Move Forward?
Clearly, there are a lot of moving parts when it comes to defending against the steps to a ransomware attack. Across the board, security leaders agree that identifying ransomware attacks as soon as possible helps reduce the impact when a ransomware attack happens and spreads.
Gaining a complete view of your network, down to the indicators or ransomware infiltration, might be the best way to combat bad actors.