SlideShare a Scribd company logo
1 of 57
Download to read offline
Ransomware Readiness 101
– How prepared are you?
Preparing, detecting, and responding to
ransomware in local government
Agenda - Format
Solving our Information Security Language Problem
This is an interactive presentation.
I want you to come away with something real, something tangible.
Do THIS - Go download the Ransomware Readiness Assessment.
https://wp.me/aaDXKz-xl
We’re going to use this in a little bit…
Housekeeping Item #1
IMPORTANT!
Before I get started…
• The World Health Organization states that over 800,000
people die every year due to suicide. Suicide is the second
leading cause of death in 15-29-year-olds.
• 5 percent of adults (18 or older) experience a mental illness
in any one year
• In the United States, almost half of adults (46.4 percent) will
experience a mental illness during their lifetime.
• In the United States, only 41 percent of the people who had a
mental disorder in the past year received professional health
care or other services.
• https://www.mentalhealthhackers.org/resources-and-links/
ME: Evan Francen, CEO & Founder of FRSecure and SecurityStudio
I do a lot of security stuff…
• Co-inventor of SecurityStudio® (or S²), S²Score, S²Org, S²Vendor,
S²Team, and S²Me
• Made a little, simple, and free ransomware readiness assessment
• 25+ years of “practical” information security experience (started
as a Cisco Engineer in the early 90s)
• Worked as CISO and vCISO for hundreds of companies.
• Developed the FRSecure Mentor Program; six students in 2010,
532 last year, and more than 750 signed up already for this year.
• Advised legal counsel in very public breaches (Target, Blue
Cross/Blue Shield, etc.)
How do we secure America?
AKA: The “Truth”
MANTRA: Information security isn’t about information or security as
much as it is about people. Information security is ALWAYS about people.
UNSECURITY: Information Security Is Failing. Breaches Are Epidemic.
How Can We Fix This Broken Industry?
Published January, 2019
How do we secure America?
UNSECURITY: Information Security Is Failing. Breaches Are Epidemic.
How Can We Fix This Broken Industry?
Published January, 2019
How do we secure America?
Russian friend.
Chinese friend.
FREE STUFF
#1 – Most relevant to today’s discussion.
Go get your Ransomware Readiness Assessment - https://wp.me/aaDXKz-xl
#2 – Go get your free S²Org information security risk assessment
– https://securitystudio.com/
#3 – Go get your free S²Me personal information security risk
assessment – https://s2me.io
#4 – Sign up for the FRSecure CISSP Mentor Program –
https://frsecure.com/cissp-mentor-program/
All free, in exchange for feedback and participation.
Ransomware – How Bad Is It?
Ransomware – How Bad Is It?
It’s pretty bad.
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
• Duplin County (NC)? Still down – attacked 2/3
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
• Duplin County (NC)? Still down – attacked 2/3
• Racine (WI)? Still down – attacked 1/31
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
• Duplin County (NC)? Still down – attacked 2/3
• Racine (WI)? Still down – attacked 1/31
Most of them thought they were fine. Like you and
me, I suppose.
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
• Duplin County (NC)? Still down – attacked 2/3
• Racine (WI)? Still down – attacked 1/31
Most of them thought they were fine. Like you and
me, I suppose.
But, you’ve got “cyber” insurance right? So no big.
Ransomware – How Bad Is It?
It’s pretty bad.
• Everybody knows about Baltimore right? ~$18MM
• Atlanta was almost as bad. ~$17MM
• New Orleans? ~7MM
• Riviera Beach (FL)? $600K (paid the ransom)
• Lake City (FL)? $530K (paid the ransom)
• Tillamook County (OR)? Still down – attacked on 1/22
• Duplin County (NC)? Still down – attacked 2/3
• Racine (WI)? Still down – attacked 1/31
Most of them thought they were fine. Like you and
me, I suppose.
But, you’ve got “cyber” insurance right? So no big.
Ransomware – How Bad Is It?
It’s pretty bad.
Ransomware – How Bad Is It?
It’s pretty bad.
• In the 4th quarter of 2019, FRSecure responded to 19
incidents, and most of them were ransomware.
Ransomware – How Bad Is It?
It’s pretty bad.
• In the 4th quarter of 2019, FRSecure responded to 19
incidents, and most of them were ransomware.
• And are you ready for the next thing?
Ransomware – How Bad Is It?
It’s pretty bad.
• In the 4th quarter of 2019, FRSecure responded to 19
incidents, and most of them were ransomware.
• And are you ready for the next thing?
Ransomware – How Bad Is It?
It’s pretty bad.
• In the 4th quarter of 2019, FRSecure responded to 19
incidents, and most of them were ransomware.
• And are you ready for the next thing?
The next thing(s) are combination
ransomware/extortion attacks.
Ransomware – How Bad Is It?
It’s pretty bad.
Source:
https://www.coveware.com/blog/2020/1/2
2/ransomware-costs-double-in-q4-as-ryuk-
sodinokibi-proliferate
OK, great. Now what?!
Simple (sort of). Get ready.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
• Originally created in 2017
• Nothing has changed.
• Same attack vectors
• Same preventative controls.
• Same detective controls.
• Same responsive controls.
• Same corrective controls.
• No matter what you do, you will not be able to prevent all
bad things from happening. This is NOT the goal anyway.
• The name of the game is risk management (possible) and
NOT risk elimination (impossible).
• Assess the problem before trying to fix the problem.
Free and open source. Released under the
Creative Commons License.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Keyword “simply”.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Keyword “simply”.
Can’t manage what
you can’t measure.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Keyword “simply”.
Can’t manage what
you can’t measure.
INCOMPLETE (until
it’s not)
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Keyword “simply”.
Can’t manage what
you can’t measure.
INCOMPLETE (until
it’s not)
Need a translation for
the “normal” people
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Six tabs containing
sections that correlate
here.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Six tabs containing
sections that correlate
here.
Six Sections:
1. Clients
2. Storage
3. Practices
4. Antivirus
5. Network
6. Servers
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Client Systems
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Client Systems
Key Risk Indicators are
red.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Client Systems
Key Risk Indicators are
red.
Just answer “Yes” or
“No” (25 questions)
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
After all questions are
answered, a score is
calculated.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
After all questions are
answered, a score is
calculated.
If you don’t know the
answers, then this is a
great education tool.
You should know.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Back on the dashboard,
scores have been
updated.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Storage
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
StorageOnly seven questions
here!
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Same thing. Score after
?s are answered and an
updated dashboard.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
10 questions about
“Practices”.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
10 questions about
“Antivirus”.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
13 questions about the
“Network”.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Finally, nine “Server”
questions.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
FINAL RESULTS?!
Back to the Dashboard.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
FINAL RESULTS?!
Back to the Dashboard.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
FINAL RESULTS?!
Back to the Dashboard.
I was sort of hoping for
better than “Poor”.
Give me hope and a dollar, and I’ve
got a dollar. Need action too!
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Quick recap of KRIs.
1. Stay up to date with all software (OS, applications, etc.).
2. Do backups, protect your backups, and (PLEASE) test your
backups often.
3. Establish solid incident response capabilities (policy,
procedures, training, testing, etc.).
4. Default deny is your friend.
5. Restrict permissions/privileges everywhere. Someday,
you’re going to have to get your hands around this.
WISDOM: Plan for the worst, hope for the best.
Quick recap of KRIs.
1. Stay up to date with all software (OS, applications, etc.).
2. Do backups, protect your backups, and (PLEASE) test your
backups often.
3. Establish solid incident response capabilities (policy,
procedures, training, testing, etc.).
4. Default deny is your friend.
5. Restrict permissions/privileges everywhere. Someday,
you’re going to have to get your hands around this.
The Ransomware Readiness Assessment
This won’t get your files or
systems back.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Quick recap of KRIs.
1. Stay up to date with all software (OS, applications, etc.).
2. Do backups, protect your backups, and (PLEASE) test your
backups often.
3. Establish solid incident response capabilities (policy,
procedures, training, testing, etc.).
4. Default deny is your friend.
5. Restrict permissions/privileges everywhere. Someday,
you’re going to have to get your hands around this.
This won’t get your files or
systems back.
But this will.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Quick recap of KRIs.
1. Stay up to date with all software (OS, applications, etc.).
2. Do backups, protect your backups, and (PLEASE) test your
backups often.
3. Establish solid incident response capabilities (policy,
procedures, training, testing, etc.).
4. Default deny is your friend.
5. Restrict permissions/privileges everywhere. Someday,
you’re going to have to get your hands around this.
Multi-factor authentication, especially for (or starting with) externally
accessible systems.
There are ZERO acceptable reasons for not protecting external resources with MFA.
ZERO as in NONE or NO or NADA or NIL or ZILCH.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Takeaways…
1. Don’t just rely on experience or “gut” feel.
2. Plan for a ransomware attack. It’s more likely than you
think.
3. The Ransomware Readiness Assessment is just a guide.
4. The Ransomware Readiness Assessment is a learning tool
for you, your colleagues, and others.
5. Don’t assume anything. (empty spaces always get filled)
That’s it.
The Ransomware Readiness Assessment
WISDOM: Plan for the worst, hope for the best.
Thank you!
Where you can find me…
Personal Website: https://evanfrancen.com
UNSECURITY Podcast (weekly)
Twitter: @evanfrancen
LinkedIn: https://www.linkedin.com/in/evanfrancen/

More Related Content

Similar to Ransomware Readiness 101 - How prepared are you?

Harrisburg BSides Presentation - 100219
Harrisburg BSides Presentation - 100219Harrisburg BSides Presentation - 100219
Harrisburg BSides Presentation - 100219Evan Francen
 
Keynote @ ISC2 Cyber Aware Dallas
Keynote @ ISC2 Cyber Aware DallasKeynote @ ISC2 Cyber Aware Dallas
Keynote @ ISC2 Cyber Aware DallasEvan Francen
 
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and Afraid
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and AfraidAECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and Afraid
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and AfraidPhil Agcaoili
 
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?Devnexus 2017 Cybercrime and the Developer: How do you make a difference?
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?Steve Poole
 
Declaration of Mal(WAR)e
Declaration of Mal(WAR)eDeclaration of Mal(WAR)e
Declaration of Mal(WAR)eNetSPI
 
Holistic Rubric Persuasive Essay - Writefiction581.Web
Holistic Rubric Persuasive Essay - Writefiction581.WebHolistic Rubric Persuasive Essay - Writefiction581.Web
Holistic Rubric Persuasive Essay - Writefiction581.WebKatie Harris
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemEvan Francen
 
Cybercrime and the Developer: How to Start Defending Against the Darker Side
Cybercrime and the Developer: How to Start Defending Against the Darker SideCybercrime and the Developer: How to Start Defending Against the Darker Side
Cybercrime and the Developer: How to Start Defending Against the Darker SideSteve Poole
 
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)Esam Abulkhirat
 
A Tutorial to AI Ethics - Fairness, Bias & Perception
A Tutorial to AI Ethics - Fairness, Bias & Perception A Tutorial to AI Ethics - Fairness, Bias & Perception
A Tutorial to AI Ethics - Fairness, Bias & Perception Dr. Kim (Kyllesbech Larsen)
 
Cyber Risk in Real Estate Sales - Workshop Presentation
Cyber Risk in Real Estate Sales - Workshop PresentationCyber Risk in Real Estate Sales - Workshop Presentation
Cyber Risk in Real Estate Sales - Workshop PresentationBrad Deflin
 
Bcc risk advisory irisscon 2013 - vulnerability management by the numbers a...
Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers a...Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers a...
Bcc risk advisory irisscon 2013 - vulnerability management by the numbers a...Eoin Keary
 
EVOLVE to demand. demand to evolve by Igor Volovich
EVOLVE to demand. demand to evolve by Igor VolovichEVOLVE to demand. demand to evolve by Igor Volovich
EVOLVE to demand. demand to evolve by Igor VolovichEC-Council
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk AssessmentResolver Inc.
 
RIPE 83: How much 'bad traffic' should I be seeing from each economy?
RIPE 83: How much 'bad traffic' should I be seeing from each economy?RIPE 83: How much 'bad traffic' should I be seeing from each economy?
RIPE 83: How much 'bad traffic' should I be seeing from each economy?APNIC
 
Cyber Security Resilience from Metro Louisville Govt.
Cyber Security Resilience from Metro Louisville Govt. Cyber Security Resilience from Metro Louisville Govt.
Cyber Security Resilience from Metro Louisville Govt. Dawn Yankeelov
 
Threat Finance – How financial institutions and governments can choke off fin...
Threat Finance – How financial institutions and governments can choke off fin...Threat Finance – How financial institutions and governments can choke off fin...
Threat Finance – How financial institutions and governments can choke off fin...emermell
 

Similar to Ransomware Readiness 101 - How prepared are you? (20)

Harrisburg BSides Presentation - 100219
Harrisburg BSides Presentation - 100219Harrisburg BSides Presentation - 100219
Harrisburg BSides Presentation - 100219
 
Keynote @ ISC2 Cyber Aware Dallas
Keynote @ ISC2 Cyber Aware DallasKeynote @ ISC2 Cyber Aware Dallas
Keynote @ ISC2 Cyber Aware Dallas
 
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and Afraid
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and AfraidAECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and Afraid
AECF: A Look into Cyber Crime - Doomsday Preppers for the Naked and Afraid
 
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?Devnexus 2017 Cybercrime and the Developer: How do you make a difference?
Devnexus 2017 Cybercrime and the Developer: How do you make a difference?
 
Declaration of Mal(WAR)e
Declaration of Mal(WAR)eDeclaration of Mal(WAR)e
Declaration of Mal(WAR)e
 
Holistic Rubric Persuasive Essay - Writefiction581.Web
Holistic Rubric Persuasive Essay - Writefiction581.WebHolistic Rubric Persuasive Essay - Writefiction581.Web
Holistic Rubric Persuasive Essay - Writefiction581.Web
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language Problem
 
Cybercrime and the Developer: How to Start Defending Against the Darker Side
Cybercrime and the Developer: How to Start Defending Against the Darker SideCybercrime and the Developer: How to Start Defending Against the Darker Side
Cybercrime and the Developer: How to Start Defending Against the Darker Side
 
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)
Cybersecurity Awareness- Libya' 1st Cybersecurity Days Conference (CDC)
 
A Tutorial to AI Ethics - Fairness, Bias & Perception
A Tutorial to AI Ethics - Fairness, Bias & Perception A Tutorial to AI Ethics - Fairness, Bias & Perception
A Tutorial to AI Ethics - Fairness, Bias & Perception
 
Telling the InfoSec Story
Telling the InfoSec StoryTelling the InfoSec Story
Telling the InfoSec Story
 
Cyber Risk in Real Estate Sales - Workshop Presentation
Cyber Risk in Real Estate Sales - Workshop PresentationCyber Risk in Real Estate Sales - Workshop Presentation
Cyber Risk in Real Estate Sales - Workshop Presentation
 
Bcc risk advisory irisscon 2013 - vulnerability management by the numbers a...
Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers a...Bcc risk advisory   irisscon 2013 - vulnerability management by the numbers a...
Bcc risk advisory irisscon 2013 - vulnerability management by the numbers a...
 
EVOLVE to demand. demand to evolve by Igor Volovich
EVOLVE to demand. demand to evolve by Igor VolovichEVOLVE to demand. demand to evolve by Igor Volovich
EVOLVE to demand. demand to evolve by Igor Volovich
 
Data Driven Risk Assessment
Data Driven Risk AssessmentData Driven Risk Assessment
Data Driven Risk Assessment
 
Risk Analysis for Dummies
Risk Analysis for DummiesRisk Analysis for Dummies
Risk Analysis for Dummies
 
R af d
R af dR af d
R af d
 
RIPE 83: How much 'bad traffic' should I be seeing from each economy?
RIPE 83: How much 'bad traffic' should I be seeing from each economy?RIPE 83: How much 'bad traffic' should I be seeing from each economy?
RIPE 83: How much 'bad traffic' should I be seeing from each economy?
 
Cyber Security Resilience from Metro Louisville Govt.
Cyber Security Resilience from Metro Louisville Govt. Cyber Security Resilience from Metro Louisville Govt.
Cyber Security Resilience from Metro Louisville Govt.
 
Threat Finance – How financial institutions and governments can choke off fin...
Threat Finance – How financial institutions and governments can choke off fin...Threat Finance – How financial institutions and governments can choke off fin...
Threat Finance – How financial institutions and governments can choke off fin...
 

More from SecurityStudio

Keynote @ ECMECC School Security Summit
Keynote @ ECMECC School Security SummitKeynote @ ECMECC School Security Summit
Keynote @ ECMECC School Security SummitSecurityStudio
 
People Committed to Solving our Information Security Language Problem
People Committed to Solving our Information Security Language ProblemPeople Committed to Solving our Information Security Language Problem
People Committed to Solving our Information Security Language ProblemSecurityStudio
 
ISSA-OC and Webster University Cybersecurity Seminar Series Presentation
ISSA-OC and Webster University Cybersecurity Seminar Series PresentationISSA-OC and Webster University Cybersecurity Seminar Series Presentation
ISSA-OC and Webster University Cybersecurity Seminar Series PresentationSecurityStudio
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemSecurityStudio
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemSecurityStudio
 

More from SecurityStudio (6)

Keynote @ ECMECC School Security Summit
Keynote @ ECMECC School Security SummitKeynote @ ECMECC School Security Summit
Keynote @ ECMECC School Security Summit
 
People Committed to Solving our Information Security Language Problem
People Committed to Solving our Information Security Language ProblemPeople Committed to Solving our Information Security Language Problem
People Committed to Solving our Information Security Language Problem
 
ISSA-OC and Webster University Cybersecurity Seminar Series Presentation
ISSA-OC and Webster University Cybersecurity Seminar Series PresentationISSA-OC and Webster University Cybersecurity Seminar Series Presentation
ISSA-OC and Webster University Cybersecurity Seminar Series Presentation
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language Problem
 
WANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language ProblemWANTED – People Committed to Solving our Information Security Language Problem
WANTED – People Committed to Solving our Information Security Language Problem
 
How to Secure America
How to Secure AmericaHow to Secure America
How to Secure America
 

Recently uploaded

European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...Energy for One World
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23JSchaus & Associates
 
Digital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsDigital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsBeat Estermann
 
Everyone, everywhere has the right to good mental health.
Everyone, everywhere has the right to good mental health.Everyone, everywhere has the right to good mental health.
Everyone, everywhere has the right to good mental health.Christina Parmionova
 
Canadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfCanadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfAndrew Griffith
 
Focusing on the rights of women and girls
Focusing on the rights of women and girlsFocusing on the rights of women and girls
Focusing on the rights of women and girlsChristina Parmionova
 
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...Christina Parmionova
 
In War and conflict, health workers, facilities and supplies are off limits.
In War and conflict, health workers, facilities and supplies are off limits.In War and conflict, health workers, facilities and supplies are off limits.
In War and conflict, health workers, facilities and supplies are off limits.Christina Parmionova
 
April 7th - World Health Day 2024 - My Health. My Right.
April 7th - World Health Day 2024 - My Health. My Right.April 7th - World Health Day 2024 - My Health. My Right.
April 7th - World Health Day 2024 - My Health. My Right.Christina Parmionova
 
2024 ECOSOC YOUTH FORUM -logistical information - United Nations Economic an...
2024 ECOSOC YOUTH FORUM -logistical information -  United Nations Economic an...2024 ECOSOC YOUTH FORUM -logistical information -  United Nations Economic an...
2024 ECOSOC YOUTH FORUM -logistical information - United Nations Economic an...Christina Parmionova
 
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdf
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdfPPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdf
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdfahcitycouncil
 
PPT Item # 7 - Demolition & Replacement Structure Processes
PPT Item # 7 - Demolition & Replacement Structure ProcessesPPT Item # 7 - Demolition & Replacement Structure Processes
PPT Item # 7 - Demolition & Replacement Structure Processesahcitycouncil
 
2023 Barangay Officials pre assumption PPT.pptx
2023 Barangay Officials pre assumption PPT.pptx2023 Barangay Officials pre assumption PPT.pptx
2023 Barangay Officials pre assumption PPT.pptxMariaFionaDuranMerqu
 
Item # 7 - Demolition & Replacement Structure Processes
Item # 7 - Demolition & Replacement Structure ProcessesItem # 7 - Demolition & Replacement Structure Processes
Item # 7 - Demolition & Replacement Structure Processesahcitycouncil
 
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.Cristal Montañéz
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.Christina Parmionova
 
Build Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsBuild Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsSERUDS INDIA
 
Madison Cat Project Foster Training - Lesson 1
Madison Cat Project Foster Training - Lesson 1Madison Cat Project Foster Training - Lesson 1
Madison Cat Project Foster Training - Lesson 1KelleyWasmund
 
Madison Cat Project - Foster Training: Lesson 1
Madison Cat Project - Foster Training: Lesson 1Madison Cat Project - Foster Training: Lesson 1
Madison Cat Project - Foster Training: Lesson 1KelleyWasmund
 
ISEIDP in Chikkaballapura, Karnataka, India
ISEIDP in Chikkaballapura, Karnataka, IndiaISEIDP in Chikkaballapura, Karnataka, India
ISEIDP in Chikkaballapura, Karnataka, IndiaTrinity Care Foundation
 

Recently uploaded (20)

European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
European Court of Human Rights: Judgment Verein KlimaSeniorinnen Schweiz and ...
 
2024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 232024: The FAR, Federal Acquisition Regulations - Part 23
2024: The FAR, Federal Acquisition Regulations - Part 23
 
Digital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical ImplicationsDigital Transformation of the Heritage Sector and its Practical Implications
Digital Transformation of the Heritage Sector and its Practical Implications
 
Everyone, everywhere has the right to good mental health.
Everyone, everywhere has the right to good mental health.Everyone, everywhere has the right to good mental health.
Everyone, everywhere has the right to good mental health.
 
Canadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdfCanadian Immigration Tracker - Key Slides - February 2024.pdf
Canadian Immigration Tracker - Key Slides - February 2024.pdf
 
Focusing on the rights of women and girls
Focusing on the rights of women and girlsFocusing on the rights of women and girls
Focusing on the rights of women and girls
 
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...
World Health Day 2024 - Zero Discrimination, Affordable treatments, Respectfu...
 
In War and conflict, health workers, facilities and supplies are off limits.
In War and conflict, health workers, facilities and supplies are off limits.In War and conflict, health workers, facilities and supplies are off limits.
In War and conflict, health workers, facilities and supplies are off limits.
 
April 7th - World Health Day 2024 - My Health. My Right.
April 7th - World Health Day 2024 - My Health. My Right.April 7th - World Health Day 2024 - My Health. My Right.
April 7th - World Health Day 2024 - My Health. My Right.
 
2024 ECOSOC YOUTH FORUM -logistical information - United Nations Economic an...
2024 ECOSOC YOUTH FORUM -logistical information -  United Nations Economic an...2024 ECOSOC YOUTH FORUM -logistical information -  United Nations Economic an...
2024 ECOSOC YOUTH FORUM -logistical information - United Nations Economic an...
 
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdf
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdfPPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdf
PPT Item # 4&5 - 415 & 423 Evans Ave. Replat.pdf
 
PPT Item # 7 - Demolition & Replacement Structure Processes
PPT Item # 7 - Demolition & Replacement Structure ProcessesPPT Item # 7 - Demolition & Replacement Structure Processes
PPT Item # 7 - Demolition & Replacement Structure Processes
 
2023 Barangay Officials pre assumption PPT.pptx
2023 Barangay Officials pre assumption PPT.pptx2023 Barangay Officials pre assumption PPT.pptx
2023 Barangay Officials pre assumption PPT.pptx
 
Item # 7 - Demolition & Replacement Structure Processes
Item # 7 - Demolition & Replacement Structure ProcessesItem # 7 - Demolition & Replacement Structure Processes
Item # 7 - Demolition & Replacement Structure Processes
 
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.
Phase 8 Hope For Venezuelan Refugees Soup Meal Program-Periods 4-6.
 
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
ECOSOC YOUTH FORUM 2024 - Side Events Schedule -17 April.
 
Build Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor StudentsBuild Tomorrow’s India Today By Making Charity For Poor Students
Build Tomorrow’s India Today By Making Charity For Poor Students
 
Madison Cat Project Foster Training - Lesson 1
Madison Cat Project Foster Training - Lesson 1Madison Cat Project Foster Training - Lesson 1
Madison Cat Project Foster Training - Lesson 1
 
Madison Cat Project - Foster Training: Lesson 1
Madison Cat Project - Foster Training: Lesson 1Madison Cat Project - Foster Training: Lesson 1
Madison Cat Project - Foster Training: Lesson 1
 
ISEIDP in Chikkaballapura, Karnataka, India
ISEIDP in Chikkaballapura, Karnataka, IndiaISEIDP in Chikkaballapura, Karnataka, India
ISEIDP in Chikkaballapura, Karnataka, India
 

Ransomware Readiness 101 - How prepared are you?

  • 1. Ransomware Readiness 101 – How prepared are you? Preparing, detecting, and responding to ransomware in local government
  • 2. Agenda - Format Solving our Information Security Language Problem
  • 3. This is an interactive presentation. I want you to come away with something real, something tangible. Do THIS - Go download the Ransomware Readiness Assessment. https://wp.me/aaDXKz-xl We’re going to use this in a little bit… Housekeeping Item #1
  • 4. IMPORTANT! Before I get started… • The World Health Organization states that over 800,000 people die every year due to suicide. Suicide is the second leading cause of death in 15-29-year-olds. • 5 percent of adults (18 or older) experience a mental illness in any one year • In the United States, almost half of adults (46.4 percent) will experience a mental illness during their lifetime. • In the United States, only 41 percent of the people who had a mental disorder in the past year received professional health care or other services. • https://www.mentalhealthhackers.org/resources-and-links/
  • 5. ME: Evan Francen, CEO & Founder of FRSecure and SecurityStudio I do a lot of security stuff… • Co-inventor of SecurityStudio® (or S²), S²Score, S²Org, S²Vendor, S²Team, and S²Me • Made a little, simple, and free ransomware readiness assessment • 25+ years of “practical” information security experience (started as a Cisco Engineer in the early 90s) • Worked as CISO and vCISO for hundreds of companies. • Developed the FRSecure Mentor Program; six students in 2010, 532 last year, and more than 750 signed up already for this year. • Advised legal counsel in very public breaches (Target, Blue Cross/Blue Shield, etc.) How do we secure America? AKA: The “Truth” MANTRA: Information security isn’t about information or security as much as it is about people. Information security is ALWAYS about people.
  • 6. UNSECURITY: Information Security Is Failing. Breaches Are Epidemic. How Can We Fix This Broken Industry? Published January, 2019 How do we secure America?
  • 7. UNSECURITY: Information Security Is Failing. Breaches Are Epidemic. How Can We Fix This Broken Industry? Published January, 2019 How do we secure America? Russian friend. Chinese friend.
  • 8. FREE STUFF #1 – Most relevant to today’s discussion. Go get your Ransomware Readiness Assessment - https://wp.me/aaDXKz-xl #2 – Go get your free S²Org information security risk assessment – https://securitystudio.com/ #3 – Go get your free S²Me personal information security risk assessment – https://s2me.io #4 – Sign up for the FRSecure CISSP Mentor Program – https://frsecure.com/cissp-mentor-program/ All free, in exchange for feedback and participation.
  • 9. Ransomware – How Bad Is It?
  • 10. Ransomware – How Bad Is It? It’s pretty bad.
  • 11. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM
  • 12. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM
  • 13. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM
  • 14. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom)
  • 15. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom)
  • 16. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22
  • 17. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22 • Duplin County (NC)? Still down – attacked 2/3
  • 18. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22 • Duplin County (NC)? Still down – attacked 2/3 • Racine (WI)? Still down – attacked 1/31
  • 19. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22 • Duplin County (NC)? Still down – attacked 2/3 • Racine (WI)? Still down – attacked 1/31 Most of them thought they were fine. Like you and me, I suppose.
  • 20. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22 • Duplin County (NC)? Still down – attacked 2/3 • Racine (WI)? Still down – attacked 1/31 Most of them thought they were fine. Like you and me, I suppose. But, you’ve got “cyber” insurance right? So no big.
  • 21. Ransomware – How Bad Is It? It’s pretty bad. • Everybody knows about Baltimore right? ~$18MM • Atlanta was almost as bad. ~$17MM • New Orleans? ~7MM • Riviera Beach (FL)? $600K (paid the ransom) • Lake City (FL)? $530K (paid the ransom) • Tillamook County (OR)? Still down – attacked on 1/22 • Duplin County (NC)? Still down – attacked 2/3 • Racine (WI)? Still down – attacked 1/31 Most of them thought they were fine. Like you and me, I suppose. But, you’ve got “cyber” insurance right? So no big.
  • 22. Ransomware – How Bad Is It? It’s pretty bad.
  • 23. Ransomware – How Bad Is It? It’s pretty bad. • In the 4th quarter of 2019, FRSecure responded to 19 incidents, and most of them were ransomware.
  • 24. Ransomware – How Bad Is It? It’s pretty bad. • In the 4th quarter of 2019, FRSecure responded to 19 incidents, and most of them were ransomware. • And are you ready for the next thing?
  • 25. Ransomware – How Bad Is It? It’s pretty bad. • In the 4th quarter of 2019, FRSecure responded to 19 incidents, and most of them were ransomware. • And are you ready for the next thing?
  • 26. Ransomware – How Bad Is It? It’s pretty bad. • In the 4th quarter of 2019, FRSecure responded to 19 incidents, and most of them were ransomware. • And are you ready for the next thing? The next thing(s) are combination ransomware/extortion attacks.
  • 27. Ransomware – How Bad Is It? It’s pretty bad. Source: https://www.coveware.com/blog/2020/1/2 2/ransomware-costs-double-in-q4-as-ryuk- sodinokibi-proliferate OK, great. Now what?! Simple (sort of). Get ready.
  • 28. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. • Originally created in 2017 • Nothing has changed. • Same attack vectors • Same preventative controls. • Same detective controls. • Same responsive controls. • Same corrective controls. • No matter what you do, you will not be able to prevent all bad things from happening. This is NOT the goal anyway. • The name of the game is risk management (possible) and NOT risk elimination (impossible). • Assess the problem before trying to fix the problem. Free and open source. Released under the Creative Commons License.
  • 29. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best.
  • 30. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Keyword “simply”.
  • 31. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Keyword “simply”. Can’t manage what you can’t measure.
  • 32. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Keyword “simply”. Can’t manage what you can’t measure. INCOMPLETE (until it’s not)
  • 33. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Keyword “simply”. Can’t manage what you can’t measure. INCOMPLETE (until it’s not) Need a translation for the “normal” people
  • 34. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Six tabs containing sections that correlate here.
  • 35. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Six tabs containing sections that correlate here. Six Sections: 1. Clients 2. Storage 3. Practices 4. Antivirus 5. Network 6. Servers
  • 36. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Client Systems
  • 37. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Client Systems Key Risk Indicators are red.
  • 38. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Client Systems Key Risk Indicators are red. Just answer “Yes” or “No” (25 questions)
  • 39. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. After all questions are answered, a score is calculated.
  • 40. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. After all questions are answered, a score is calculated. If you don’t know the answers, then this is a great education tool. You should know.
  • 41. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Back on the dashboard, scores have been updated.
  • 42. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Storage
  • 43. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. StorageOnly seven questions here!
  • 44. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Same thing. Score after ?s are answered and an updated dashboard.
  • 45. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. 10 questions about “Practices”.
  • 46. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. 10 questions about “Antivirus”.
  • 47. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. 13 questions about the “Network”.
  • 48. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Finally, nine “Server” questions.
  • 49. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. FINAL RESULTS?! Back to the Dashboard.
  • 50. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. FINAL RESULTS?! Back to the Dashboard.
  • 51. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. FINAL RESULTS?! Back to the Dashboard. I was sort of hoping for better than “Poor”. Give me hope and a dollar, and I’ve got a dollar. Need action too!
  • 52. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Quick recap of KRIs. 1. Stay up to date with all software (OS, applications, etc.). 2. Do backups, protect your backups, and (PLEASE) test your backups often. 3. Establish solid incident response capabilities (policy, procedures, training, testing, etc.). 4. Default deny is your friend. 5. Restrict permissions/privileges everywhere. Someday, you’re going to have to get your hands around this.
  • 53. WISDOM: Plan for the worst, hope for the best. Quick recap of KRIs. 1. Stay up to date with all software (OS, applications, etc.). 2. Do backups, protect your backups, and (PLEASE) test your backups often. 3. Establish solid incident response capabilities (policy, procedures, training, testing, etc.). 4. Default deny is your friend. 5. Restrict permissions/privileges everywhere. Someday, you’re going to have to get your hands around this. The Ransomware Readiness Assessment This won’t get your files or systems back.
  • 54. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Quick recap of KRIs. 1. Stay up to date with all software (OS, applications, etc.). 2. Do backups, protect your backups, and (PLEASE) test your backups often. 3. Establish solid incident response capabilities (policy, procedures, training, testing, etc.). 4. Default deny is your friend. 5. Restrict permissions/privileges everywhere. Someday, you’re going to have to get your hands around this. This won’t get your files or systems back. But this will.
  • 55. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Quick recap of KRIs. 1. Stay up to date with all software (OS, applications, etc.). 2. Do backups, protect your backups, and (PLEASE) test your backups often. 3. Establish solid incident response capabilities (policy, procedures, training, testing, etc.). 4. Default deny is your friend. 5. Restrict permissions/privileges everywhere. Someday, you’re going to have to get your hands around this. Multi-factor authentication, especially for (or starting with) externally accessible systems. There are ZERO acceptable reasons for not protecting external resources with MFA. ZERO as in NONE or NO or NADA or NIL or ZILCH.
  • 56. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Takeaways… 1. Don’t just rely on experience or “gut” feel. 2. Plan for a ransomware attack. It’s more likely than you think. 3. The Ransomware Readiness Assessment is just a guide. 4. The Ransomware Readiness Assessment is a learning tool for you, your colleagues, and others. 5. Don’t assume anything. (empty spaces always get filled) That’s it.
  • 57. The Ransomware Readiness Assessment WISDOM: Plan for the worst, hope for the best. Thank you! Where you can find me… Personal Website: https://evanfrancen.com UNSECURITY Podcast (weekly) Twitter: @evanfrancen LinkedIn: https://www.linkedin.com/in/evanfrancen/