Cyber Security can seem to be a bit daunting to a big organisation, never mind small businesses. With a deluge in attacks that is only growing by the day and tactics mutating like a super-virus, it can be confusing as to where to start and what to do first. For some businesses, the reality of how little they know about their own security only comes to bear when they are attacked and for many, this is increasingly frequently when ransomware drops into your mailbox.
As cited in a recent presentation by Europol, Ransomware is a growing threat internationally as it has been for a number of years. However now, its growth is augmented by dark net ‘Crime-as-a-Service’ where ransomware campaigns can be bought and serviced by the ‘service provider’ from as little as $15 per month. It’s cheap and effective and the Return on Investment for the criminal is huge when you consider the size of the lists they buy (also on the dark net) and how much they can reap from a single company. Other key trends and threats include:
It may be a surprise then, if you’re sitting in your office in rural Hertfordshire, that Europol has resources that can help. Of course, I’m not suggesting that you call the head of Europol as your screens freeze, the security services get that privilege.
What does Europol do? Well, they work with security services, not just across Europe but with partner countries (such as the US…and soon to be the UK) globally. This means they can help investigate and co-ordinate campaigns against criminals online. In the past year alone, they have shut down a number of dark net marketplaces, XEDIC being one and helped bring down the world’s biggest DDoS for hire website. What they learn, goes into information which is shared among partner countries for the continued, co-ordinated defence against cyber-crime at a nation-state, business and, as a result, individual citizen level. Much of this information is continually being fed into a free resource for businesses of any size to use.
But first off…
If you are the unfortunate recipient of a ransomware attack that has been clicked on, don’t panic! It’s tempting to pay the ransom but take a breath and look at your options. In a recent cyber security presentation we attended, the message from the Head of Strategy at the European Cybercrime Centre was, ‘Don’t pay the ransom’. If you do, you simply become a key target for repeated future attacks because they know their tactics work. And yes, they are that sophisticated that they know who has clicked or opened an email and adjust their campaigns accordingly.
Go to www.nomoreransom.org for more info.