10 steps to recover from a Ransomware Attack?

Introduction

Despite extensive press coverage, many public and private sector leaders have a poor understanding of ransomware. It is not surprising then that most organizations are unprepared to defend against these attacks. Any organization – big or small, for-profit or non-profit – can fall victim to ransomware. Since the start of the pandemic, this malware type has become the number one cyber threat for businesses worldwide! Yet, there is scarcely any information available that is not overly simplified or excessively complicated.

A ransomware attack can be a stressful, potentially existential event and requires the victim organization to make crucial decisions under intense pressure. With no prior experience and fear of losing their data permanently, some organizations may make rash decisions that could hurt them in the long run. This article covers how you need to respond in the event of a ransomware attack and provides you with detailed steps to address the uncertainty you might be facing in such an event.

Keep Calm and do not pay the ransom

Many victim organizations choose to pay the ransom to resolve this issue immediately. It is essential to keep calm in this situation and first analyze the scope and impact of the ransomware attack. The hackers will use tactics to persuade you into making rash decisions, and you must not give in!

Most organizations believe there are only two ways to respond to an attack – pay the ransom or rebuild the entire network. However, there are alternatives between the two options, such as restoring data from unencrypted shadow copies. While many small organizations might believe paying the ransom is the easiest to restore operations, they are unaware of the alternatives and the potential impact of paying the ransom on the future!

We recommend that before deciding to pay the ransom, you conduct a thorough analysis of the attack, find alternative solutions, and then make an informed decision based on the information gathered. Further, it is essential to note that there is no guarantee that paying a ransom will restore your systems and return access to your files.

Isolate affected devices

A ransomware attack takes days or even weeks to be executed. If you are a victim of such an attack, understand that the attacker has been in your network for a few days, slowly encrypting all your files to prevent access. Only when all or most of the files and systems are affected, do they lock you out of your system and declare the dreaded message!

Therefore, you must determine quickly which of your systems are affected and unplug them from the network immediately to curb the spread of the malware. Further, if your files are on auto-sync for Cloud providers such as Google or One Drive, disable it and log out instantly.

Report the Incident

You must report this attack to law enforcement immediately. It enables you to gain perspective from people who have years of experience in handling such incidents. If you are in the United States, you can contact the FBI local field office, IC3, or Secret Service. Further, contact your local or national police to report this incident, as most police now have a cyber division that handles such incidents. For businesses in the UK, they can go to the website Action Fraud to report this attack.

Getting the above stakeholders involved at the earliest will be beneficial in handling this unprecedented situation. If you have a cyber insurance policy, you must contact the insurance company immediately. Insurance companies have dedicated resources for incident response, especially ransomware, and will guide you in handling this situation efficiently.

Identify the Ransomware type

To effectively respond to an attack, we must first determine the type of ransomware that has affected your system. Fortunately, the ID Ransomware website allows you to identify ransomware quickly. Upload the ransom message and a sample of encrypted files. Within seconds, you will generate details about the infection and whether the file can be decrypted without paying the ransom.

No More Ransomware

Before you decide to pay the ransom, you can check the version of the ransomware on this free internet resource called No More Ransomware. This online resource is available for free and has decryption keys to the most used malware circulating the market. By uploading an encrypted file, the website will tell you the type of ransomware and provide you with the decryption key (if available).

Most ransomware attackers are looking to make quick money and use old ransomware that has long been decrypted. As most victims are unaware of this resource, they quickly pay the money without analyzing the different options available.

Conduct Cost-Benefit Assessment

Before deciding to pay the ransom, conduct a cost-benefit analysis of paying the ransom against restoring the backup files. Remember, some costs might not be obvious to the victims. Charges like breach notification costs will be incurred whether you make the payment or not. A careful analysis could show that paying the ransom may, in fact, not be the cheaper option.

Understanding the need for cost-benefit analysis, the government is currently developing a framework that will help small businesses make an informed decision on paying the ransom.

Verify your back-ups

The best solution against such attacks is to have regular, encrypted, and offline back-ups of your files. Restoring your systems from that backup will be easy. Verify that your backup is accessible and restorable. You must only access your backups from a device that has not been affected and is disconnected from the internet. This practice will prevent your offline backups from getting infected by ransomware.

If you do not have backups, you can skip this step.

Remove the ransomware

Run a full current antivirus scan on all suspected computers and devices to detect and remove the ransomware payload. Ensure you also scan devices that synchronize data or are part of the mapped network drives. You can utilize the Windows Defender for this task or even the more dedicated ransomware removal Malicious Software Removal Tool (MSRT). Remember to only restore backups after eradicating the ransomware.

Recover your files

Now that you have removed the ransomware, you can restore your systems from your backups—only attempt restoration of your systems after a proper removal of the malware. In Windows, you can use File History to try to recover your local files and folder.

However, some ransomware will also encrypt or delete backup versions, so you can’t use File History. Therefore, we recommend always have multiple backups with one that is entirely offline and air-gapped.

Make the payment

Deciding to pay the ransom should be the absolute last resort for an organization. While most security experts strongly recommend against paying the ransom (and for good measure), you must be the one to make the final decision as a business owner.

Paying a ransom does not guarantee restoration of access to your resources. At the very least, it won’t be easy to restore access even after the payment. Further, paying the ransom does not mean that your company will not be targeted again. Most importantly, paying the ransom supports and validates illegal criminal activity that will affect many more people in the future. Sophos found that only 26% of ransomware victims had their data returned after paying the ransom.

Instead, security experts encourage organizations to notify criminal authorities to restore their services immediately without paying the ransom. However, if you decide to pay the ransom, the payment most likely will be demanded through cryptocurrency. The payment process will look something like the diagram shown below.

Go public with complete transparency

Whether you decide to pay the ransom or restore your systems from a backup, you must take out a press release that describes the ransomware attack in detail and discusses the actions you took to restore your systems to their normal states.

A precise, transparent press release will help your business gain credibility amongst the industry, law enforcement, and customers and help other organizations facing similar issues deal with such an incident more efficiently. Your law enforcement and cyber insurance company contacts will guide you on the proper method to release a press statement.

Conclusion

Ransomware continues to wreak havoc this year. Not a month goes by where we do not hear about successful hacks against big and small organizations. No one is safe from ransomware, and we must prepare our defenses to prevent falling victim to this type of attack.

Luckily, consistent multiple backups mixed with regular software updates and robust anti-virus solutions are the best (and freely available) solutions to prevent a ransomware attack. If you still become a ransomware victim, follow the steps in this article to explore alternatives to paying the ransom. No matter your choice – to pay or not to pay – ensure that you increase your organization’s security to prevent any further ransomware attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *