2 min read
By now, you’ve no doubt heard of WannaCry, the ransomware attack that impacted over 300,000 victims in more than 100 countries over the past 10 days. While we’ve all focused on effective patching strategies to prevent further infection, an important part of the discussion is how to plan for a successful incident response (IR) to ransomware and other types of attacks.
When dealing with ransomware attacks, the primary goal is to avoid falling victim in the first place. The key is to consistently back up your most critical data. You should also ensure that your backup servers and systems aren’t always connected to the network. That way, a ransomware attack within your environment will have little impact, since you’ll still be able to access your critical data.
That said, an effective backup strategy is simply one part of a larger security and response plan, which should be developed proactively. To successfully combat ransomware and other types of targeted attacks, it’s critical to create an incident response plan, document it and test it regularly to identify gaps and changes within the environment.
Industry newsletter
Stay up to date on the most important—and intriguing—industry trends on AI, automation, data and beyond with the Think newsletter. See the IBM Privacy Statement.
Your subscription will be delivered in English. You will find an unsubscribe link in every newsletter. You can manage your subscriptions or unsubscribe here. Refer to our IBM Privacy Statement for more information.
Organizations that have a documented incident response plan and an IR team, whether it’s internal, external or a combination of both, can respond to a breach more quickly than those who don’t. Organizations that are able to complete an investigation in 30 days or less save an average of USD 1,000,000 over those who don’t.
Furthermore, organizations that document their plans and test them quarterly or biannually are able to more effectively prepare for security incidents and practice their response actions in advance of a real attack. This allows these enterprises to accelerate the process of response and investigation, greatly reducing data exposure and financial losses.
An effective response plan should contain a broad scope of technical and nontechnical actions that need to be conducted by all stakeholders within the environment. This requires leaders to ask questions such as:
Documenting and regularly testing a variety of scenarios helps organizations determine where gaps may exist. Most importantly, this enables security teams to fix vulnerabilities in advance of a breach.
To learn how IBM X-Force can help you with anything regarding cybersecurity including incident response, threat intelligence, or offensive security services schedule a meeting here.
If you are experiencing cybersecurity issues or an incident, contact X-Force to help:
US hotline 1-888-241-9812 | Global hotline (+001) 312-212-8034.
IBM web domains
ibm.com, ibm.org, ibm-zcouncil.com, insights-on-business.com, jazz.net, mobilebusinessinsights.com, promontory.com, proveit.com, ptech.org, s81c.com, securityintelligence.com, skillsbuild.org, softlayer.com, storagecommunity.org, think-exchange.com, thoughtsoncloud.com, alphaevents.webcasts.com, ibm-cloud.github.io, ibmbigdatahub.com, bluemix.net, mybluemix.net, ibm.net, ibmcloud.com, galasa.dev, blueworkslive.com, swiss-quantum.ch, blueworkslive.com, cloudant.com, ibm.ie, ibm.fr, ibm.com.br, ibm.co, ibm.ca, community.watsonanalytics.com, datapower.com, skills.yourlearning.ibm.com, bluewolf.com, carbondesignsystem.com, openliberty.io