cxo voice
  • Home
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • News
  • Press Release
    • Submit Press Release
No Result
View All Result
  • Home
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • News
  • Press Release
    • Submit Press Release
No Result
View All Result
Leaders Talk and Latest Tech News | CXO VOICE
No Result
View All Result
Home News Cyber Security

Demystifying ransomware – the cyber pandemic

Sharda Tickoo by Sharda Tickoo
June 22, 2020
ransomware - the cyber pandemic

Image: Sharda Tickoo

With an evolving digital landscape and the rapid proliferation of sophisticated cyberattacks, security can no longer be relegated as an afterthought by organizations. The world continues to witness numerous cyberattacks – from Wannacry to the latest Maze attack, with each attack being more unique and complex than the preceding one, and making businesses succumb to huge losses. What’s common between these attacks, you may ask – they are all ‘ransomware’. This ‘cyber pandemic’, as we would like to call it due to its inherent nature of spreading far and wide, has spread its wings across countries leading to concerns around the security of data.

Its enormity can be gauged from the fact that almost 62% of organizations globally have experienced a ransomware attack in the past year, as reported by an industry survey by CyberEdge. And, which will likely continue to do so in the foreseeable future, with newer and stealthier attacks underway.

A case in point is the recent Maze ransomware, which created headlines the world over. What’s unique about this ransomware is that it not only encrypts the data but steals it, and with the threat actors threatening to publish the data, which makes it exponentially more devastating. On why organizations should look at ransomware as the proverbial ‘elephant in the room’ and not just shelve the topic aside, let’s delve a bit in into demystifying few of the aspects, which include – ransomware transmission; whether it’s ever a good idea to pay up a ransom, and if ‘prevention’ might be the best ‘vaccine’ in dealing with it.

Infectious modes of transmission

How lethal is ransomware, and why do many of the cyber experts still consider it to be the numero-uno cyber threat even today? All the findings and the industry data validate this fact, with one such finding by Cybersecurity Ventures, a global cybersecurity research firm predicting that – ‘globally, businesses in 2021 will fall victim to a ransomware attack every 11 seconds, down from every 14 seconds in 2019.’ Its proliferation has further been accentuated because of the COVID-19 outbreak, as more and more employees continue to work remotely, and there is less protection due to remote access. It is likely that the users are more susceptible to falling prey to COVID-19 themed malicious emails.

What’s the modus operandi of a ransomware attack and its transmission? Phishing emails are the most common way through which ransomware penetrate an organization – as attachments masquerading as a file which victims tend to trust. However, there are several other vectors through which ransomware can also permeate, which includes endpoints, cloud workloads, networks, web gateways, files, mobile phones and even instances seen across Linux servers. 

Typically, ransomware encrypts data using different file formats or extensions with different Advanced Encryption Standard (AES) keys, and hence decryption becomes almost impossible.

ADVERTISEMENT

‘Ransom’ in ransomware – not a good thing

This is a perennial question, whether to comply with the demands of the ransomware actor or not. It’s important for an organization that has been breached to understand the attackers’ unseen motive, which in many cases is to get a quick return on investment. According to a joint study by PwC India and Data Security Council of India (DSCI), the data breach cost in India has gone up by 8% in 2 years, which is alarming. We notice that many-a-times organizations are ready to pay a ransom to speed up the recovery of their data and systems. However, it’s important to note that paying it does not guarantee that the users will get the decryption key or unlock tool required to regain access to the infected system or hostage files and may only further encourage threat actors to attack organizations. As long as the ransom scheme, or the ‘cyber heist’ as we like to call it, continues to be profitable, cybercriminals will continue to leverage it on vulnerable targets. 

Prevention and Remediation – Keys to defend

In the current parlance, to deal with ransomware an occasional intake of medicine won’t suffice, and a ‘vaccine’ is the order of the day. This is where ‘prevention’ could be the panacea or much needed vaccine that organizations should prescribe to rather than looking at knee-jerk reactive approach to ransomware attacks, which is the current practice. 

Despite the prevalent ideals of digital transformation, lack of basic security hygiene, legacy systems with outdated operating systems and unpatched vulnerabilities are still a reality. As per Gartner’s analysis of clients’ ransomware preparedness, globally, over 90% of ransomware attacks are preventable. There is no silver bullet when it comes to stopping ransomware. As part of a layered defense strategy against ransomware, organizations should have multiple security controls in place across email, endpoints, networks, and servers. Since these are correlated, centralized security visibility across all these layers from a single console helps to reduce IT complexity and to stay on top of the ransomware threat.

Let’s observe some of the best practices that organizations and users can adopt to strengthen their defenses against ransomware and mitigate risks:

  1. Back up important files using the 3-2-1 rule—create 3 backup copies on 2 different media with 1 backup in a separate location.
  2. Enable virtual patching, especially for operating systems that are no longer supported by the vendor.
  3. Ensure emails are safeguarded with sandboxing technology and anti-spam solution, and there is an advance scanning & detection technology in place for mail endpoint & network traffic.
  4. Implement multi-factor authentication and least privilege access policies to prevent abuse of tools that can be accessed via admin credentials, like RDP, PowerShell and developer tools.
  5. Regularly update software, programs, and applications to protect against the latest vulnerabilities.
  6. Increase awareness of how ransomware spreads, i.e., through spammed emails and attachments.
  7. Avoid opening unverified emails or clicking links embedded in them.

The hard question that CISOs, CTOs, CIOs and all the security and IT managers should ask themselves is that, in the eventuality of a newer ransomware threat, are they really prepared well enough to deal with it.


  • Security While Working Remotely [Interview]
  • Combating cyber threats: 10 security tips in the COVID-19 era
  • Security in the Cloud Remains Challenged by Complexity and Shadow IT: IBM

Sharda Tickoo

Sharda Tickoo

Sharda Tickoo, Director – Technical, Trend Micro India

Related Posts

Lenovo Next-Gen AI-Powered Desktops and Monitors
Technology

Transforming Workspaces: Lenovo Launches Next-Gen AI-Driven Desktops and Monitors

May 15, 2025
AWS Humain
Business

AWS and HUMAIN Announce $5 Billion AI Zone to Drive Innovation and Digital Transformation

May 14, 2025
Telstra and Accenture Launch Silicon Valley Hub to Rapidly Advance Benefits of AI for Telstra Customers
Press Release

Telstra and Accenture Launch Silicon Valley Hub to Rapidly Advance Benefits of AI for Telstra Customers

May 14, 2025
HCLTech SAP Configurator
Technology

HCLTech Launches SAP Configurator Accelerator Kit to Streamline S/4HANA Rollouts

May 14, 2025
TCS Dhofar
Business

TCS Partners with Dhofar Insurance to Transform its Core Insurance Platform

May 14, 2025
Tech Mahindra
People

Tech Mahindra Appoints New Leaders to Drive Growth in Key Global Markets

May 14, 2025
LTIMindtree
Business

LTIMindtree Secures $450 Million Multi-Year Deal with Global Agribusiness Leader

May 12, 2025
Amazon to Invest Over $4 Billion to Launch Infrastructure Region in Chile
Press Release

Amazon to Invest Over $4 Billion to Launch Infrastructure Region in Chile

May 9, 2025
Load More
Please login to join discussion
ADVERTISEMENT

Latest Updates

Lenovo Next-Gen AI-Powered Desktops and Monitors

Transforming Workspaces: Lenovo Launches Next-Gen AI-Driven Desktops and Monitors

by Deepa Sharma
21 hours ago

AWS Humain

AWS and HUMAIN Announce $5 Billion AI Zone to Drive Innovation and Digital Transformation

by News Desk
2 days ago

Telstra and Accenture Launch Silicon Valley Hub to Rapidly Advance Benefits of AI for Telstra Customers

Telstra and Accenture Launch Silicon Valley Hub to Rapidly Advance Benefits of AI for Telstra Customers

by News Desk
2 days ago

HCLTech SAP Configurator

HCLTech Launches SAP Configurator Accelerator Kit to Streamline S/4HANA Rollouts

by Deepa Sharma
2 days ago

TCS Dhofar

TCS Partners with Dhofar Insurance to Transform its Core Insurance Platform

by News Desk
2 days ago

Tech Mahindra

Tech Mahindra Appoints New Leaders to Drive Growth in Key Global Markets

by News Desk
2 days ago

Expert Views

Molly Sands AI
AI

AI RIP: 5 Things Knowledge Workers Will Say ‘Sayonara’ to in the Next Decade

March 8, 2025
multi cloud
Cloud

Multi-Cloud Made Simple: Strategies for Smart Business Management

March 5, 2025
Soft Skills
Opinion

Soft Skills and Technical Know-How: A Winning Combination in the Tech Industry

March 4, 2025
Digital Freedom
Cyber Security

Your Data, Their Gold: The Silent Battle for Digital Freedom

February 25, 2025
LLM in India
AI

Why A Homegrown LLM Is the Next Big Leap for India

February 22, 2025

Get Latest Update

Subscribe to our mailing list to receives newsletter direct to your inbox!

ADVERTISEMENT

Leaders Interviews

Steve Wilson, GenAI Cybersecurity LLMs
Cyber Security

How effective is GenAI in cybersecurity? The role of LLMs and AI in security solutions. [Interview with Steve Wilson]

-
Interview on Counterfeit products with Nikhil Narayan
Leaders Talk

Advancements in ML & AI made it possible to detect counterfeit products in real-time, says Nikhil Narayan

-
Newgenone bridges the gap between business users and IT teams with its low code capability: Varun Goswami
Leaders Talk

Newgenone bridges the gap between business users and IT teams with its low code capability: Varun Goswami

-
AI chatbots, Prasanna-Kumar
Leaders Talk

Can AI chatbots enhance customer experience and reduce the cost of serving customers?

-

Entrepreneur

Samsung Electronics appoints its first female president

Inspiring Women Entrepreneurs in India (2022)

Technology Adoption For Entrepreneurs

Volunteering management is the need of the Hour

CXOVoice.com is a leading online publication for CXOs, entrepreneurs, senior leaders, developers, and industry professionals. Our coverage spans key sectors, including IT, technology, banking, finance, cybersecurity, engineering, and automobiles.

Connect with us

Easy Links

  • Cryptocurrency
  • Event
  • Blockchain
  • Press Release
  • Resources & Downloads

Write Us

[email protected]
  • Home
  • About Us
  • Contact Us
  • Advertise
  • Privacy & Policy
  • Feedback

Copyright © 2025 CXOVoice - All Right Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

Our Spring Sale Has Started

You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/

No Result
View All Result
  • Home
  • Technology
    • AI
    • Cloud
    • Telecom
    • Data Center
    • BPM
    • Blockchain
  • Finance
    • Banking
  • Cyber Security
  • View Points
  • Leaders Talk
  • News
  • Press Release
    • Submit Press Release

Copyright © 2025 CXOVoice - All Right Reserved