{"id":54192,"date":"2023-02-21T07:33:00","date_gmt":"2023-02-20T23:33:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=54192"},"modified":"2023-02-17T05:39:18","modified_gmt":"2023-02-16T21:39:18","slug":"new-ideas-needed-to-protect-against-ransomware-other-malware-it-experts","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/02\/21\/new-ideas-needed-to-protect-against-ransomware-other-malware-it-experts\/","title":{"rendered":"New ideas needed to protect against ransomware, other malware \u2013 IT experts"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong><em>SAN JOSE, CALIFORNIA <\/em>\u2013 Security concerns are evolving, and so should responses. This was stressed by IT experts here at NetEvents, a gathering of technology sector experts and opinion shapers, where it was similarly acknowledged that responses to security issues \u201cshould not neglect the human factor.\u201d<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2.jpg\"><img loading=\"lazy\" decoding=\"async\" width=\"766\" height=\"1024\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2-766x1024.jpg\" alt=\"\" class=\"wp-image-54194\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2-766x1024.jpg 766w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2-224x300.jpg 224w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2-768x1027.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2023\/02\/hacking2.jpg 864w\" sizes=\"auto, (max-width: 766px) 100vw, 766px\" \/><\/a><figcaption class=\"wp-element-caption\">Photo by AltumCode from Unsplash.com<\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">As background, in 2021 alone, ransomware is said to have affected 66% of organizations, higher by 78% over those detected 2020, according to Sophos&#8217;s <em><a href=\"https:\/\/assets.sophos.com\/X24WTUEQ\/at\/4zpw59pnkpxxnhfhgj9bxgj9\/sophos-state-of-ransomware-2022-wp.pdf\">&#8220;The State of Ransomware 2022&#8221;<\/a><\/em> report. And since 2020, there have been more than 130 different ransomware strains detected, according to VirusTotal&#8217;s &#8220;Ransomware in a Global Context&#8221; report, dominated by the GandCrab ransomware family (78.5% of all samples received), and with 95% of all the ransomware samples Windows-based executable files or dynamic link libraries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not surpsigingly, companuies have been spending on this. As of 2022, IBM \u2013 via its <a href=\"https:\/\/www.ibm.com\/reports\/data-breach\">&#8220;Cost of a Data Breach 2022&#8221;<\/a> report \u2013 estimated that an average ransom payment totaled $812,360, though the total cost of a ransomware attack may actually be as high as $4.5 million on average.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Ken Levine, CEO of endpoint security company Xcitium, \u201cHow do we straddle the line between great security and not impacting productivity? That\u2019s the challenge there.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why for him, \u201cWe focus on the notion that the malware is already there. What we focus on is how it doesn\u2019t happen again.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly true since the \u201cnumber of attacks and complexity has been increasing. No surprise,\u201d he said, adding that \u201cthe threat landscape is scary.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why for him, \u201cAssume that everything unknown that comes into a network is bad. One fo the things we rely on is detection; but we can\u2019t detect everything, and we can\u2019t detect fast enough. So assume everything that you haven\u2019t seen before as bad. Add that extra layer of detection to neutralize and prevent the damage.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAs they say: The bad guys have to be right once; we have to be right all the time,\u201d Levine said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Dr. Srinivas Bhattiprolu, global head of advanced consulting services, Nokia Cloud and Network Services, there are three threats that businesses should consider, i.e. 1. expansion of threat, with everything possible to be attacked; 2. third party exposure since \u201cas you open up your whole ecosystem, you\u2019re at risk\u201d; and 3. lack of cyber hygiene since \u201cwe don\u2019t change our passwords.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Bhattiprolu, automation coulkd come in handy. \u201cAutomate. Invest in security, but look at areas where you can automate the best,\u201d he said. \u201cThe number of threats is growing, the complexity is also growing. It\u2019s important to prevent these proactively with the right tools.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But Bhattiprolu admitted that there\u2019s no one-size-fits-all solution. And so for him, while \u201cwe tend to focus on technology, on automation&#8230; it\u2019s also important to talk about the people dimension.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the end, said Matt Lourens from the Office of the CTO of Checkpoint, the \u201cbiggest concern is, we don\u2019t have significant enough prevention methods in place. How do you mitigate, how do you prevent, those are really the questions (that need to be answered).\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He similarly noted that when talking about security \u2013 and even technology \u2013 vendors, \u201cThere\u2019s a lot of marketing hype.\u201d But before caving in, he recommended that the \u201cfirst thing that\u2019s important to do is you need to convince your organization to put security first. Go to a vendor. Look for a security team; get a start to see what your security risks are. That\u2019s an important first step.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security concerns are evolving, and so should responses.<\/p>\n","protected":false},"author":2,"featured_media":54193,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[54,2103,96,2727,1656],"class_list":["post-54192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","tag-security","tag-security-breach","tag-technology","tag-technology-adaption","tag-technology-investment"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=54192"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54192\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/54193"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=54192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=54192"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=54192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}