eBook | Defending Against Malware Attacks: The Ultimate Guide to Building Your Malware Defense Strategy
This eBook provides a comprehensive guide to defending against malware attacks, covering key threats, prevention strategies, and a 5-step playbook aligned with the NIST Cybersecurity Framework. Learn about malware types, the true cost to businesses, and how Check Point SASE's malware protection can mitigate risks. Download the eBook now to strengthen your defense.

Defending Against Malware Attacks Starts Here The Ultimate Guide to Building Your Malware Defense Strategy
MALWARE PROTECTION 2
The threat of malware persists, with more than 6 billion attacks occurring worldwide in 20232.
Meanwhile the Harvard Business Review (HBR) says, “While IT specialists toil away to create better, smarter, and safer technical systems, there is one risk they can’t program away: humans. Especially as remote work becomes more prevalent and thus access to secure systems becomes more distributed, one wrong click by an employee can often be enough to threaten an entire digital ecosystem.”3
Malware is continually one of the top threats worldwide, as cyber criminals employ increasingly sophisticated tactics and extort growing ransomware payouts1
Today’s IT professionals need to focus on building a more user-centric security design, and onboarding technology that can act before an employee or a customer is infected. After all, the same HBR researchers found that in 85% of cases where employees violated cybersecurity rules, they did so because they felt it would help them or their colleagues to best perform their job. Most employees aren’t acting maliciously, and yet the vast majority aren’t ignorant either. Instead, most workers are making real- time decisions to balance security with productivity and are weighing the cost/benefit of risking one for the other.
1. https://www.businessinsider.com/government-agencies-are-paying-the-most-for-ransomware-attacks-2024-7 2. https://www.statista.com/statistics/873097/malware-attacks-per-year-worldwide/ 3. https://hbr.org/2022/01/research-why-employees-violate-cybersecurity-policies
https://www.businessinsider.com/government-agencies-are-paying-the-most-for-ransomware-attacks-2024-7 https://www.statista.com/statistics/873097/malware-attacks-per-year-worldwide/ https://hbr.org/2022/01/research-why-employees-violate-cybersecurity-policies
MALWARE PROTECTION 3
What is covered by the term malware and how serious is the threat today?
The true cost of malware for today’s businesses, and the challenges of prevention
A 5-step playbook against malware, aligned to the NIST Cybersecurity Framework
Check Point SASE’s Malware Protection and how to manage malware risk
7 Indicators of compromise that could signal a malware attack in your environment
This eBook will look at the growing risk of malware, and the smart route to securing your business environment, covering:
MALWARE PROTECTION 4
Malware is a portmanteau of the words malicious software and is a broad term which covers any software that attempts to gain unauthorized access to computer systems for disruption, damage, or gain. For as long as there has been the internet, there has been malware, and the earliest computer viruses have been documented as far back as the 1980s.4
Over time malware has become increasingly sophisticated. Today more than 450,000 new instances of malware and potentially unwanted applications (PUAs) are discovered each day, with cumulative numbers growing every year, according to AV-Test.5
What Does the Threat of Malware Look Like Today?
4. https://en.wikipedia.org/wiki/Elk_Cloner 5. https://www.av-test.org/en/statistics/malware/
Malware PUA
2008 0
300,000,000
600,000,000
900,000,000
1,200,000,000
1,500,000,000
2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024
Total Amount of Malware and PUA
https://en.wikipedia.org/wiki/Elk_Cloner https://www.businessinsider.com/government-agencies-are-paying-the-most-for-ransomware-attacks-2024-7 https://www.av-test.org/en/statistics/malware/
MALWARE PROTECTION 5
Breaking Down the Term: What’s Covered By The Word Malware? Malware is a broad term that covers a wide range of threats, and many kinds of malware can be used in combination with one another to form blended attacks and, therefore, achieve greater impact against their victims.
There are numerous types of malware attacks, but let’s cover some of the most common: Ransomware
These malware programs encrypt your data and hold it to ransom, asking for a sum of money in order to release your information. Ransomware usually occurs through an employee clicking on a malicious link from an email or a website, although it can also happen via “driveby downloading”, where the user doesn’t need to click anything, only visit an infected website to trigger the malicious download.
The Cost of Ransomware
Cybersecurity Ventures predicts that within a decade, there will be a new ransomware attack every 2 seconds. This is the fastest growing type of cybercrime, and its related costs are expected to hit $265 billion each year by 2031.6
6. https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-toreach-250-billion-usd-by-2031/
https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-toreach-250-billion-usd-by-2031/
MALWARE PROTECTION 6
Viruses and Worms These are two different kinds of malware, both of which work by rapidly copying themselves across a network. Once a worm has achieved access to your network, it can spread without the original host file, and without human input. Its goal is to consume system resources, and it can be controlled remotely. However, a virus will need some form of interaction in order to execute, for example a user enabling macros on the malicious file. At this point, the virus will be activated, and it can copy itself, corrupting files or impacting performance, and spreading to additional endpoints.
Trojans A trojan is less a kind of malware, and more a method of entry. It’s an example of a blended malware attack, as discussed earlier. For example, a trojan could be a virus or a worm, but it is distinguished by its method — the way that it disguises itself as a legitimate software application. The user thinks they are downloading a necessary or known software tool or update, and this makes it more likely that they will trust its download and execution. The name “trojan” refers to the way the attack makes its way into your network. Trojans are often delivered via a phishing scam where users are directed to a fake version of a known website and encouraged to download software directly.
MALWARE PROTECTION 7
Spyware Once spyware has established a foothold in your network, it can gather information about your behavior and then forward this to third-parties. For example, keylogging software is spyware where bad actors track your keystrokes to obtain credentials or sensitive data. Spyware does not usually spread to other devices within the network, unlike a virus or a worm, it does not replicate. However, using the stolen credentials, attackers could access the network directly.
Malvertising This form of malware spreads either by clicking on infected adverts or pop-ups on websites, or simply by visiting the compromised website, which will trigger the malware when the website page loads. This can download PUPs (Potentially Unwanted Programs) or other types of malware, such as viruses or worms. Malvertising can be very smart, using your browsing history to determine what kind of advert or fake software would be most likely to encourage you to click, or to visit the infected site in the first place.
MALWARE PROTECTION 8
As malware continues to rise in occurrence, sophistication, and variance, you might wonder - where are the costs coming from?
The most obvious are the direct costs, such as paying the ransom to get encrypted data back. However, some estimates project that these costs are negligible compared to the price of downtime, which is estimated at $300,000 per hour for most enterprises.7
Add to this the cost of employee hours spent working on limiting the spread of an attack, or fees for managed service providers hired to get business up and running
Understanding the Cost of Malware for Today’s Businesses
again, as well as the lost opportunity cost of taking on new clients during the time it takes to restore business as usual, and you can see how malware can take a serious toll.
On top of that, malware can cause devastating reputational damage to a business or brand, directly impacting share value, encouraging employees to look elsewhere, and causing a lasting impression in the minds of the customer.
7. https://ransomware.org/blog/how-downtime-drives-up-the-cost-of-a-ransomware-attack/
MALWARE PROTECTION 9
What makes malware so hard to stop in its tracks? First, we must consider the average organization’s ability to detect an attack in the first place. Dwell time is an industry metric that measures the moment between when a cyberattack occurs and when it is identified. The good news is that average dwell time has decreased from 10 to 8 days, according to recent research. The bad news? Cyber criminals are moving faster and launching more attacks outside of working hours, when fewer security operators are available to respond.8
According to Forbes, shrinking the average dwell time is just one of the many challenges facing security teams. “The environment needs to be set up to favor early detections, the solution needs to be installed and configured correctly,
The Challenges of Preventing Malware
and the security operations team needs to have the correct training and supporting processes to make the most of their tools…Small organizations often lack the resources to hire a dedicated information security resource, let alone a fully equipped team and the security stack they need to adequately protect the environment.” 9
This has been exacerbated by the rise in remote and hybrid work, preventing businesses from being able to adequately track employee exposure to malicious content. According to IBM, the average cost of malware is more than $1M higher when remote work is a factor in the breach.10 When employees are working from home, visibility becomes more difficult, employees tend to act with less caution, and as endpoints and users are distributed, recovery is far slower.
8. https://www.infosecurity-magazine.com/news/attack-dwell-times-faster/ 9. https://www.forbes.com/councils/forbestechcouncil/2021/05/03/why-the-dwell-time-of-cyberattacks-has-not-changed/ 10. https://www.entrepreneur.com/science-technology/data-breaches-cost-1-million-more-when-remote-work-is/463130
https://www.infosecurity-magazine.com/news/attack-dwell-times-faster/ https://www.forbes.com/councils/forbestechcouncil/2021/05/03/why-the-dwell-time-of-cyberattacks-has-not-changed/ https://www.entrepreneur.com/science-technology/data-breaches-cost-1-million-more-when-remote-work-is/463130
MALWARE PROTECTION 10
Configuration changes on files or devices
Poor network performance
Increase in database volume
Anomalous network traffic (outbound)
Users connecting from an unexpected region
Unusual activity from privileged accounts
High number of authentication failures
Would You Recognize a Malware Attack? Indicators of Compromise
MALWARE PROTECTION 11
YOUR 5-STAGE MALWARE ATTACK PLAYBOOK
11. https://www.nist.gov/cyberframework/getting-started/online-learning/five-functions
How can today’s businesses get ahead of the malware challenge?
NIST describes 5 clear functions which make up its Cybersecurity Framework.11 These are, Identify, Protect, Detect, Respond, and Recover.
https://www.nist.gov/cyberframework/getting-started/online-learning/five-functions
MALWARE PROTECTION 12
Identify Identification of the cybersecurity challenges that your business is facing should be taken from two directions. First, from a wide angle view. Simply — what threats are prevalent today? The malware listed above is a good starting point for the risks businesses need to be aware of. The majority of these threats occur through human error such as falling for phishing scams or browsing to an infected website.
Once you know what risks you’re up against - what do you want to protect inside your environment? It’s important to map your assets clearly and get visibility over your IT infrastructure including applications, data, users, and capabilities.
STEP 01 Ask yourself: • What users need which levels of access? • Where do we store our most sensitive data? • What devices are most at risk of malware infection?
Check Point SASE manages and monitors all network edges, including all users and resources, from a unified console allowing you to keep track of all relevant assets in a single place.
MALWARE PROTECTION 13
Protect With the answers to these essential questions, now is the time for preventative action. How will you shore up your environment to protect against the threats you identified during the Identify phase are blocked ahead of time?
Protection is best achieved by a multilayer security approach:
1. Deploy a Secure Web Gateway tool that inspects all web traffic – whether users are connected to the network or not - and alerts or blocks access to known and potentially risky sites. 2. Use a Malware Protection solution to block malicious threats before they infect company endpoints. 3. Implement a Zero Trust strategy for controlling access to all enterprise resources, which will help avoid lateral movement and data breaches, should a corporate asset or user become compromised.
STEP 02 Check Point SASE’s converged security platform, which includes Zero Trust Network Access (ZTNA), Hybrid Secure Web Gateway (which runs either in the cloud or on user devices, providing comprehensive protection), Firewall- as-a-Service, and Browser Security supports all of these capabilities within a single solution. Advanced Malware Protection adds an extra layer of defense, enabling IT teams to defend their employees and corporate networks against ransomware, rootkits, zero-day exploits, and more.
Zero trust? Under this model, users only get access to the they need for their jobs—nothing more. This makes it a lot harder for attackers to reach ‘crown jewel’ applications and information even if they manage to establish access or harvest credentials.
MALWARE PROTECTION 14
Detect With the right solution in place, all web traffic will be scanned for signs of malicious activity. Our Malware Protection solution decrypts and checks all web traffic before allowing the user access. This includes files downloaded by the user, as well as HTML, JavaScript, CSS, and more. If the traffic doesn’t pass as safe–for example if malware is found–the browser won’t be granted access to the requested website, and any files will not be downloaded.
Detecting malware also generates an alert informing the IT team of a potential risk. But detection alone isn’t enough; it also has to be discoverable and requires timely detection.
STEP 03
MALWARE PROTECTION 15
With Check Point SASE, the alert appears in the security events viewer, which is part of our single- pane-of-glass management. This makes it easier for system administrators to see alerts and take proactive steps against potential threats as soon as possible.
Employees, meanwhile, can work as usual, experiencing no impact on performance, while all web traffic is scanned and channeled accurately to ensure best-in-class security. If web traffic is unsafe, they simply get a message on-screen which tells them the website or file contained malware and has been blocked.
Top tip Look for a tool which enables logs to be exported so that incident response teams can use the information for further analysis, and information can be kept for compliance trails or audits where necessary.
MALWARE PROTECTION 16
Respond So far, we’ve seen how Malware Protection does the hard work on your behalf by checking all traffic for signs of malicious intent, while smart web filtering rules help avoid potentially dangerous websites. But now it’s time to talk about how to respond in the event of malware detection.
There are numerous steps that could be required to respond to a potential threat and many of them will depend on specific circumstances. Malware designed to extract information may require all users to replace their passwords, for example. If the threat was a cryptoworm (ransomware that spreads through the network as a worm such as WannaCry), then any devices accessing offline backups would have to be thoroughly checked.
STEP 04 While the list of potential measures is large, there are a few basic tactics that should be part of most responses. The first step is to limit the damage by isolating infected endpoints from the network to avoid further infection. It’s also important to quarantine any infected files.
Next, take a wider, network-level approach by ensuring that all managed devices meet company security standards before accessing the network.
Check Point SASE’s Device Posture Check (DPC) feature can verify that managed devices are meeting security standards before and during connection to resources. Those that fail verification are either blocked from connecting or disconnected from the network.
MALWARE PROTECTION 17
Recover While studies show that recovery from a malware attack can take months or even years, when you’ve followed steps one through four, recovery will be shorter and less painful. With advanced Malware Protection in place, you’re reducing the potential damage a malware infection can generate.
If the worst occurs and a hacker does make it through your defenses, or you’re hit by a more complex attack method such as fileless malware, your environment is segmented, limiting the propagation of the malware.
With Check Point SASE, critical assets are ring-fenced away from access, and wider resources are protected by network segmentation and user-based rules.
The damage will be limited to a single segment, which in many cases could be one endpoint or device.
STEP 05 But what do you do with the endpoints or servers that are damaged? First, if applicable, it’s important to restore backups via offline disks or cloud-based backups that were unaffected by the attack. Then it’s important to ensure that your network is sound with no further signs of infection.
It’s also important to create an incident response (IR) that reviews how the malware infection happened in the first place, and how it can be prevented from happening again. Perhaps a new security tool is required, or even an additional one, or maybe it’s simply a question of further employee education or tightening up authentication policies.
Finally, it’s on to dealing with the public, be it the wider public or your customer base, and taking steps to limit damage to the brand itself.
MALWARE PROTECTION 18
Detect Block any attempted attacks in real-time
Respond View continuous activity tracking and web logs
Identify Recognize where the risk lies in any environment
Recover Contain damage ahead of time, ensuring quick MTTR
Protect Segment the network according to zero trust
With Check Point SASE, You Can:
MALWARE PROTECTION 19
Check Point SASE features the industry’s only hybrid SWG, providing Advanced Malware Protection that supports each stage of the cybersecurity framework whether users are connected to the corporate network or not. It scans all user browsing and blocks suspicious traffic in real-time. This enables you to achieve a powerful defense against malicious content to secure users and the network.
Malware Protection requires no configuration and covers all users. It prevents malware from infecting your network at the delivery stage by intercepting malicious files, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. Our multi-layered detection includes: • Signatures: Comprehensive and continuously updated
database of malware signatures for up-to-date protection. • Heuristics: Algorithmic analysis to discover patterns and
behaviors of hidden or unknown malware. • Emulation: Virtual code processing to detect malicious behavior. • Machine Learning: Advanced machine learning
accelerates detection, and offers protection from complex threats including APTs, zero-day attacks, and ransomware.
At each stage of the cybersecurity framework, Check Point shows up for your business.
The Web Filtering feature helps you control access to website categories based on defined users and user groups. You can decide which websites should be blocked, warned against, or allowed. By blocking access and exposure to suspicious websites, you can ensure end users don’t expose the business to threats such as phishing scams and malvertising attacks.
At the same time, creating tight zero-trust policies allows admins to better protect their data and critical assets. Even if the worst occurs, attacks will never make it past their initial foothold, and lateral movement would be greatly limited.
Finally, malware activity logs give you full visibility into how attackers are threatening your network, and how end users are utilizing the web. This allows you to understand the greatest risks for your business, isolate high-risk employee groups, and work on shoring up security and compliance overall.
Ready to learn more and see how Check Point SASE can help protect your network? Schedule a demo today!
https://www.perimeter81.com/demo?utm_content=EBK&utm_medium=PDF&utm_campaign=malware_prot_ebook