Student’s Name
Professor’s Name
Course
Date
Ransomware
Introduction
In recent years, a concerted attack targeting data for companies, organizations, and government departments has been on the rise (Kok et al., 79). The latter arises from ransomware attacks that have cost many companies billions of dollars in ransom payment and data theft. The continued cyber-attacks have penetrated over one hundred and fifty countries, targeting most essential institutions and government departments (Richardson & Max, 10). For instance, Britain’s National Health Service was once attacked by malware, causing delays in scheduled surgeries. The paper aims at outlining the necessary preparations and response strategies that a police department such as that of Independence Ohio, can undertake before and after attacks by ransomware.
Technologies to help the city prepare to withstand ransomware attack
Use of a licensed antivirus
When antivirus is used, the possibility of detection and identification of potential ransomware threats is made easy. When the antivirus is issued, it allows for ease of avoiding the virus, detecting the attack, and preventing the further spread of the virus (Kok et al., 79). The antivirus also allows for the repair of the file systems that are already attacked by the virus, hence helping in saving resources that could otherwise be lost or used in paying the ransom.
Updated Operating system
One other way of preventing ransomware attacks is through acquiring updated operating systems. In essence, many of the lately manufactured operating systems try to develop systems that are well secured while at the same time incorporating firewall systems that can easily prevent minor cyber-attacks (Brewer, 8). As such, it is necessary for operating systems for the main computers or data storage software to be updated with the latest versions.
Disabling of macro scripts
Since many of the ransomware attacks penetrate through vectors such as software vulnerabilities, phishing emails, and remote desktop protocol compromise, among others (Kok et al., 79). As such, Office Viewer software can be used to open Microsoft Office files, which are transmitted through emails instead of office suite applications.
Apply network segmentation
The ransomware threats can also be prevented through the categorization and separation of data based on their value. Also, the implementation of virtual environments can help in the prevention of internet security breach (Brewer, 9). In addition, physical and logical separation of networks and data remains a logical way of prevents the attacks. Essentially, the application of the principle of least privilege is vital in such instances.
Personal items to help the city withstand ransomware attack
Use of backups systems
In order for the city to withstand a ransomware attack, a backup system must be used. The latter should allow iterations of the backups to be saved where a copy of the backups is encrypted, or files are infected (Brewer, 8). Once the backup system is secured, routine tests for data integrity on the systems must be undertaken.
Keeping systems patched
The department must ensure that all hardware such as computers and mobile devices, software, applications, and operating systems are patched and kept updated. A centralized patch management system becomes one of the best ways to withstand the attack is made possible. Also, implementing application whitelisting coupled with software restriction policies (SRP) helps prevent the execution of programs in common ransomware locations such as temporary folders (Kok et al., 79).
Restricting Internet Access
Unprotected public networks and file sharing connectivity must be avoided at all costs. According to Richardson and Max, proxy servers can be used when accessing the internet from department band personal hardware coupled with the use of ad-blocking software (10). Since most ransomware entry points are social media accounts and emails, their access must be restricted.
Training Requirements
Securing the end-user
- One of the training that is required to secure the end-user includes social engineering and phishing training (Brewer, 6). The latter entails training on avoiding opening attachments or clicking on suspicious links while also avoiding unknown websites.
- Another mode of training should entail establishing a structured reporting plan to ensure that staff are aware of strategies for reporting suspicious activities.
Items for mitigating damage
When responding to a potential ransomware attack, strategies adopted must include:
- Immediate disconnection of the infected systems forms the department network to prevent the propagation of the infection.
- Restoring files from backups that are regularly maintained.
- Take steps to find a malware decryptor to help break down the malware and find the necessary response strategy.
- After an attack, it is necessary to undertake vetting and monitoring third parties with remote access to the organization’s networks and data (Richardson & Max, 10). The latter will help in determining the probable routes of virus propagation while at the same time preventing sustained attacks through disconnection from such third parties.
Conclusion
For better management of cybersecurity systems within a department, adequate preventive measures must be taken. These strategies include the installation of updated software systems and adopting staff training on strategies of identifying and preventing malware infection. As such, a department like the independent Ohio police department can benefit from effective adoption of security measures to help avoid and mitigate ransomware attacks.
Works Cited
Brewer, Ross. “Ransomware attacks: detection, prevention and cure.” Network Security 2016.9 (2016): 5-9.
Kok, S. H., et al. “Prevention of crypto-ransomware using a pre-encryption detection algorithm.” Computers 8.4 (2019): 79.
Richardson, Ronny, and Max M. North. “Ransomware: Evolution, mitigation and prevention.” International Management Review 13.1 (2017): 10.