Ransomware Attacks: Prevention Is Better Than Cure
14th March 2024

Ransomware Attacks: Prevention Is Better Than Cure
In this month’s blog we look at what we call a ‘HYPOS’ short for a Hypothetical Operational Situation that could easily occur in your business if you’re not prepared or aware.
Please don’t stop reading on the basis of ‘it will not happen to us’, awareness is so important.
I’ve personally spoken with four potential clients in the last month that have been affected both by the fact their incumbent supplier was not proactive enough and their own lack of understanding of what is required to protect their business and staff from risk.
This has left them in a situation where they have had to spend there way out of an issue and still now don’t completely understand what happened. The impact to their business over the last few months has been beyond measurable in both lost time and financial waste.
I won’t disclose the loophole that the ransomware exploited as that’s not fair to them or their supplier but I will highlight some of the most common area’s that are still not given enough proactive attention.
Here’s how they do it – anatomy of a ransomware attack
Your VPN is not as secure as you think!!
As recently as 4th March 2024 Cisco Issued a Patch for High-Severity VPN Hijacking Bug in Secure Client
A laptop showing a screen with ‘VPN’ on itVPN’s can’t prevent cookie tracking, viruses, or malware, and it can’t protect against phishing scams. Data leaks could occur. But most pivotally, a VPN is only as secure as the company that runs it. A VPN provider that uses out-of-date protocols, leaks IPs, and logs your data isn’t one you can trust.
They Attack Through Email
Attacks often start with a malicious phishing email intended to trick the recipient into disclosing login credentials. Attackers may also purchase stolen credentials on the dark web.
They attack your websites and apps
Using stolen credentials or other means, attackers hit your websites and applications to access your business data. Once they have access to your sensitive data, they often exfiltrate the data to ask for additional funds to prevent it from being released publicly.
Hacking your Wi-Fi network
Weak passwords, outdated firmware models, and missed software updates in your router’s settings leave your network vulnerable. Gaining control of personal devices that are connected to a weakened network can be as simple as hacking into the Wi-Fi network itself.
How ransomware attacks actually happen
A recent report by IBM X-Force analyzed the evidence from multiple ransomware attack investigations that occurred between 2019 and 2021. In each investigation, access to the victim network was obtained through an initial access broker (initial access brokers are cybercriminals who specialize in breaching companies and then selling the access to ransomware attackers). The emphasis of the research was to better understand the duration of the activities during the various stages of a ransomware attack.
The findings of this research revealed the average duration of an enterprise ransomware attack (time between initial access and ransomware deployment) reduced 94.34% between 2019 and 2021. This is a substantial reduction and while ransomware attack lifecycle time decreased significantly, the research did not reveal substantial changes in the tools, techniques and procedures used by threat actors.
Additionally, X-Force analyzed victim organizations’ ability to prevent, detect, and respond to ransomware attacks prior to the deployment of the ransomware and found that ransomware attacks have continually been successful against organizations who have not implemented effective measures to combat the threat of ransomware.
Instead, the evidence revealed the time in transferring access from the access broker to an interactive session to carry out the ransomware attack has decreased significantly, and ransomware operators have become more efficient in gaining privileged access to Active Directory and deploying the ransomware. Understanding the speed and efficiency of ransomware attacks enables organizations to develop a detection and response strategy that is specifically designed to address the ransomware threat.
A report showing graphsIn November 2021, X-Force released research detailing how most ransomware attacks occur in a predictable five-stage pattern: Initial Access, Post-Exploitation Foothold, Reconnaissance/Credential Harvesting/Lateral Movement, Data Collection and Exfiltration, and Ransomware Deployment.
While no two ransomware incidents are identical, by analyzing the evidence across all ransomware-related investigations where initial access was obtained via an IAB, X-Force identified four core objectives that enabled the ransomware operators to advance through the 5 stages of a ransomware attack:
- Establish interactive access
- Move laterally
- Obtain privileged access to
- Active Directory
- Deploy ransomware at scale
While data theft does occur in most ransomware attacks, evidence of data theft and the duration of data theft activities are limited in many investigations. X-Force was unable to draw any concrete conclusions on the time ransomware operators spent on this stage of the attack.
Business Effects
A Northamptonshire based business did not survive a cyberattack and went into administration with the loss of 730 jobs late last year so the risk is very real. Kettering logistics firm enters administration with 730 jobs lost – BBC News
You should engage with your IT partner to ensure you are being proactive in terms of security planning and understanding the options you have available. I’m still amazed by the number of business owners who haven’t reviewed their security posture.
The future of security with AI
The increasing speed, scale, and sophistication of recent cyberattacks demands a new approach to security. Traditional tools are no longer enough to keep pace with the threats posed by cybercriminals. In just two years, the number of password attacks detected by Microsoft has risen from 579 per second to more than 4,000 per second.1 According to Cybersecurity Ventures, the global cost of cybercrime is expected to reach $10.5 trillion by 2025, up from $3 trillion in 2015.2 On average, organizations use 80 security tools to manage their environment, resulting in security teams facing data deluge, alert fatigue, and limited visibility across security solutions. Security teams face an asymmetric challenge: they must protect everything, while cyberattackers only need to find one weak point. And security teams must do this while facing regulatory complexity, a global talent shortage, and rampant fragmentation.
One of the advantages for security teams is their view of the data field—they know how the infrastructure, user posture, and applications, are set up before a cyberattack begins. To further tip the scale in favor of cyberdefenders, Microsoft Security offers a very large-scale data advantage—65 trillion daily signals, expertise of global threat intelligence, monitoring more than 300 cyberthreat groups, and insights on cyberattacker behaviors from more than 1 million customers and more than 15,000 partners.1
Microsoft Copilot brandingMicrosoft’s new generative AI solution—Microsoft Security Copilot—combined with their massive data advantage and end-to-end security, all built on the principles of Zero Trust, creates a flywheel of protection to change the asymmetry of the digital threat landscape and favour security teams in this new era of security.
Microsoft offers a wide range of services to protect your business as much as possible. Please feel free to contact our teams today to discuss how we can help. sales@digital-origin.co.uk











