White Paper | Five Security Measures to Keep Your Business Safe from Ransomware
Ransomware attacks continue to rise, costing businesses millions. In this whitepaper, we outline five critical security measures to protect your organization from ransomware. These include stopping phishing, securing emails, and more. Don’t let your business become another victim. Download the whitepaper to learn how to significantly strengthen your security posture and safeguard your company from cyberattacks.

5 SECURIT Y MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE
FROM RANSOMWARE
Y O U D E S E R V E T H E B E S T S E C U R I T Y
25 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Executive Summary • Attacks on businesses of all sizes are increasing in cost and virulence
• Ensuring proper defenses has bever been more important, but it can be difficult to know what to prioritize
• In this whitepaper, we’ll discuss the five security measures businesses can take now to keep safe from ransomware and other attacks
It is a terribly scary cybersecurity environment out there. Not a day goes by without a headline of a new ransomware attack, whether it’s targeting major businesses or local governments.
The threat seems exhausting. And yet it is incredibly real and can’t be put aside. For small to medium businesses, the average attack costs $200,000. For enterprise organizations, attacks cost, on average, nearly $15 million per year. Plus, 60% of small to medium businesses go out of business within six months of being hacked. An attack is not just a nuisance. It’s a threat to existence.
Further, ransomware shows no signs of slowing down. There’s an average of 4,000 ransomware attacks daily. The average ransom request has increased from $5,000 to $200,000. The total cost of ransomware payments doubled year-over-year for the first half of 2020. In all, ransomware grew by over 1,000% from July 2020 and June 2021.
For organizations large and small, the prospect of cyberattacks and ransomware threats is tremendously disconcerting.
What to do? Fortunately, this bleak landscape is not without hope.
In this whitepaper, we’ll discuss the five security measures you can take today that will dramatically increase your security posture, reduce the threat of ransomware and cyberattacks and keep your business going.
Stop Phishing
35 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
MEASURE 1
The number one cause of breaches today is phishing, accounting for 96%. Beyond that, a majority of ransomware attacks begin with email. According to a new report, the biggest vector is SMTP, accounting for 45% of ransomware attacks, followed by IMAP at 26.5%. When combined with POP3 (3.8%), you get the following: 75.3% of ransomware attacks arrive via email. It's also worth noting that 22.3% starts from web browsing. That can mean many things, but it certainly means being sent via messaging apps like Slack and Microsoft Teams.
AsDeloitte notes:
“The motive behind this is that phishing emails are easy to send and lead to a faster return on investment (ROI). Phishing, as part of social engineering schemes, luresvictims into executing actions without realizing the malicious drive. The less aware the targeted user is, the more fruitful the attack. Likewise, in case of targeted attacks, phishing emails are created to look like they come from a trustworthy sender, but link toor contain malicious content that executes as soon as users click it, encrypting their data and asking for the ransom.”
That’s why the most important action a company can take is deploying robust email security protection. It’s worth noting the different methods of securing email,
45 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
One is a Secure Email Gateway. They sit in front of the inbox. Originally designed for on-prem emails, they’ve made a poor transition to the cloud. As the only layer of defense, if an email gets past the gateway, it goes right into the inbox. Here’s how it works:
Beyond that, they are blind to internal messages between cloud users, a significant vector for phishing emails.
Another is an API-based email security solution. It works by remediating malicious emails after it reaches the inbox. This can take, on average, three minutes and three seconds. However, the average user clicks on a phishing link in one minute and twenty-two seconds.
Then there’s Avanan, which is also an API-based vendor, but works differently than the rest. It blocks malicious emails before they reach the inbox, so the user never has a chance to click.
55 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
To fully protect against ransomware, you need to prevent phishing from entering the inbox. To do so, you need the best phishing efficacy. Doing so, as seen above, depends largely on mail flow position. When positioned behind default security but before the inbox, the amount of phishing you catch skyrockets dramatically:
65 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Preventing phishing is the first step and with Avanan it’s simple.
Avanan’s patented technology utilizes cutting-edge AI and machine learning, along with human input from end-users and trained researchers to catch the attacks that Microsoft and other security layers miss.
Our technology deploys in five minutes and is embedded within Office 365 as an additional layer. It scans and prevents malicious emails before they hit the inbox, meaning end-users never see it and, most importantly, never click on it.
Or, to put it simply: When you have Avanan deployed, when you receive an email, you know it’s safe to open and interact with.
75 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Collaboration App/File SharingMEASURE 2 Even before the work-from-home revolution started, we were using collaboration and file-sharing apps with regularity. Since the pandemic started, their usage has only skyrocketed. Teams counts 270 million monthly active Teams users; that's up a tidy 20 million from July 2021. That growth is probably fueled, in some part, by Teams' product designed specifically for small businesses.
While these applications have made work doable while in disparate locations, it does not come without risks. In fact, new research finds that OneDrive accounts for 20% of all malicious downloads; SharePoint accounts for 9%. For malicious Office documents, OneDrive and SharePoint combine for 34% of all downloads in that category.
Further, according to that same research, Google Drive has also become a major vector for malicious files and downloads. In fact, Google Drive accounted for 37% of malicious downloads in 2021, a 28% increase over 2020. Further, G-Drive accounts for 50% of malicious Office document downloads, a 42% increase over 2020.
In these applications, malware is incredibly easy to spread. Starting in December 2021, Avanan observed a new, massive wave of hackers leveraging the comment feature in Google Docs. In this attack, hackers are adding a comment to a Google Doc. The comment mentions the target with an @. By doing so, an email is automatically sent to that person’s inbox. In that email, which comes from Google, the full comment, including the bad links and text, is included. Further, the email address isn’t shown, just the attackers’ name, making this ripe for impersonators.
For example, a hacker can create a free Gmail account, such as <bad.actor@gmail.com>. They can then create a Google Doc, insert a comment and send it to their intended target. For this example, let’s say the intended target has a work address of <vic.tim@company.com>. The end-user will have no idea whether the comment came from <bad.actor@gmail.com> or <bad.actor@company.com>. It will just say “Bad Actor” mentioned you in a comment in the following document. If Bad Actor is a colleague, it will appear trusted. Further, the email contains the full comment, along with links and text. The victim never has to go to the document, as the payload is in the email itself. Finally, the attacker doesn’t even have to share the document--just mentioning the person in the comment is enough.
85 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Consider the .ppam file attack. In this email attack, hackers found a way to leverage a little-known file to wrap executable files. Using .ppam files, a PowerPoint add-on file, hackers can wrap, and thus hide, malicious files. In this case, the file will overwrite the registry settings in Windows, allowing the attacker to take control over the computer, and keep itself active by persistently residing in the computer's memory.
For file-sharing security to be successful, a few things need to happen. All attachments need to be scanned, tested and executed in a sandbox to ensure no malicious content. Every file needs to be scanned for malicious links. Flexible policies should allow you to notify interested parties, such as the admin, if malicious material is quarantined. It should also incorporate DLP, flagging files that contain malware or potentially sensitive information and automatically mitigating them as needed. Further, advanced AI should analyze end-user behavior and cross-correlate them with activities in other SaaS apps, detecting compromised attacks, insider threats and insecure configurations.
The risk applies to collaboration apps.
Consider this attack in Microsoft Teams. In this attack, hackers have attached a malicious Trojan document to a chat thread. When clicked on, the file will eventually take over the user’s computer. Using an executable file, or a file that contains instructions for the system to execute, hackers can install DLL files and allow the program to self-administer and take control over the computer.
By attaching the file to a Teams attack, hackers have found a new way to easily target millions of users.
The first step is accessing Teams. Hackers have a number of ways of doing that. They can compromise a partner organization and listen in on inter-organizational chats. They can compromise an email address and use that to access Teams. They can steal Microsoft 365 credentials through traditional phish methods–usually through fake O365 notifications asking for password information–giving them carte blanche access to Teams and the rest of the Office suite. Given that hackers are quite adept at compromising Microsoft 365 accounts using traditional email phishing methods, they’ve learned that the same credentials work for Teams.
Beyond that, once inside an organization, an attacker usually knows what technology is being used to protect it. That means they will know what malware will bypass existing protections. Compounding this problem is the fact that default Teams protections are lacking, as scanning for malicious links and files is limited. Further, many email security solutions do not offer robust protection for Teams. Hackers, who can access Teams accounts via East-West attacks, or by leveraging the credentials they harvest in other phishing attacks, have carte blanche to launch attacks against millions of unsuspecting users.
95 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Further, end-users have an inherent trust of the platform. For example, an Avanan analysis of hospitals that use Teams found that doctors share patient medical information practically with no limits on the Teams platform. Medical staff generally know the security rules and risk of sharing information via email, but ignore those when it comes to Teams. Further, nearly every user can invite people from other departments and there is often minimal oversight when invitations are sent or received from other companies. Because of the unfamiliarity with the Teams platform, many will just trust and approve the requests. Within an organization, a user can very easily pretend to be someone else, whether it's the CEO, CFO or IT help desk.
Most employees have been trained to second-guess identities in email, but few know how to make sure that the name and photo they see in a Teams conversation are real. It is simple to edit a profile and become most anyone you like.
So when someone attaches a file to a Teams chat, particularly with the innocuous-sounding file name of “User Centric”, many users won’t think twice and will click on it.
To ensure proper security in collaboration apps, every file and link needs to be sandboxed before downloading. DLP tools need to detect leaks of PCI, HIPAA, PII, FERPA and other sensitive data. An anomaly engine should monitor all logins and events for suspicious activities.
Collaboration apps don’t have to be an invitation for collaboration with hackers. With top-notch security, you can collaborate and communicate with confidence.
105 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Create a Ransomware Response PlanMEASURE 3 Being prepared is always essential, and that certainly applies to ransomware. Successfully responding to an attack relies on knowing what to do when it happens. That given, with the rise in ransomware, your response team should already be identified. It often consists of an incident response group with the company, legal counsel, a forensics team and potentially a negotiation team.
It means having a checklist of what to do should it happen.
It also means knowing what happens after the attack has been remediated.
According to the National Institute of Standards and Technology, any response plan needs to have t he following:
Preparation. This means that everyone knows their role and has practiced it. There’s no time to waste when an attack happens.
Detection. This refers to understanding the type of incident that’s happened, the severity of it and what’s been affected.
Containment. Stop the problem before it gets worse and restore what’s been affected.
Post-Mortem. Analyze what procedures failed and how they can be strengthened.
A successful attack can be frightening. But a proper plan that’s been tested and executed successfully in simulations provides re-assurance.
115 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
MEASURE 4
As remote work continues, securing endpoints is becoming ever more important. 68% of organizations have experienced one or more endpoint attacks that resulted in compromised data. In all, 70% of cyber attacks start on the end point. A proper endpoint solution protects all endpoints–laptop, operating system, mobile phone, etc-and will use advanced AI to shut down malware before the damage is done. When done properly, every file received via email or downloaded via the web is emulated in a sandbox or sanitized via Content Disarm & Reconstruction. Instant and full remediation of ransomware behavior should work even when offline. A solution should include anti-malware, access control, sensitive keyword detection, disk encryption and more. More than anything, it should prevent the most imminent endpoint threats, such as ransomware, phishing and malware, while quickly reducing breach impact through autonomous detection and response.
Secure End Points
MEASURE 5
AIf your data is stolen and you can’t install a backup, that’s the ballgame.
That’s why a proper backup plan is essential. A key tenant of cybersecurity is the ‘3-2-1 Rule’. That refers to an organization having: 3 copies of data, stored on two different media types, one of which is offsite.
Beyond that, establishing a retention plan is key. How often an organization backs up its data is an individual choice; regardless, establishing a clear protocol and sticking to it is essential. Data archiving is essential in case your primary storage methods get compromised or infected by ransomware.
Finally, it’s essential to test the backup and restore feature. A good way to do this is testing for five months in the past. Since threat actors will stay in a network for months, this ensures that you can recover any lost data, no matter how long ago it was.
Backup Everything
125 SECURITY MEASURES YOU NEED TO TAKE TO KEEP YOUR BUSINESS SAFE FROM RANSOMWARE
Worldwide Headquarters 5 Ha’Solelim Street, Tel Aviv 67897, Israel | Tel: 972-3-753-4555 | Fax: 972-3-624-1100 | Email: info@checkpoint.com
U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 800-429-4391; 650-628-2000 | Fax: 650-654-4233
www.checkpoint.com
© 2022 Check Point Software Technologies Ltd. All rights reserved.
Summary The threat landscape is unlike any other point in history. As we increase our connectivity to one another, we increase the chance of hackers finding what they’re looking for:
• Email Security
• File/Collaboration Security
• Ransomware Reponse Plan
• Endpoint Protection
• Backup policy
You can never guarantee that you’ll avoid a ransomware attack. But with these, and other, protections in place, the risk is decreased dramatically.