Welcome to Your Operations Solved, for Thursday, April 8th, 2021

I'm your host, Channing Norton, of PC Solutions, and this is the Ninth episode of our show,
Listen to us Tuesday, Wednesday, Thursday, or on our Saturday compilations. If you find the show helpful or informative, please do give it a like on your platform of choice, or share it to someone else who might also like it.

With that out of the way, let's get to today's headline.

New Ransomware Tactics, naming and shaming victims

Recent reports indicate that major ransomware gang CLOP has begun applying additional pressure to its victims by having their customers put pressure on the company which has been hacked. This is allowing CLOP to demand a second ransom from its victims, one to decrypt files, and one to not have their customer data publically leaked. Other ransomware groups are also beginning to employ the tactic. So, what does this mean for your business? Well, in order to discuss this, and why it's so troubling, we first need to understand what ransomware is, and why it's a big concern. Your business relies on computerized data everywhere. Weather its accounting data, order information, emails, business plans, payroll and timeclock data, you need it. Most or all of this information is going to be stored on your network somewhere. Ransomware, also known as CryptoLocking is a type of Virus or Malware that locks this data up in a way that it cannot be recovered by anyone except the criminals who infected you. When I say that NOBODY can recover it, I mean it, assuming the malware is written well, there is literally nothing that the top experts in the field of data recovery or computer security can do to get your information back, given unlimited resources. So, they infect your devices, lock up all of your data, and charge you a ransom, usually in the thousands or tens of thousands of dollars, to get your data back. This happens to organizations of all sizes. I've personally had to deal with the aftermath of this stuff at a church with 4 employees, and a few peoples individual personal devices not affiliated with any organization. For larger cases, countless hospitals have been hit, and even the City of Baltimore was held for ransom in 2019. If you pay, you usually get your data back, but not always, if you don't, it typically gets deleted after a few days. Regardless, you're left with a huge bill, as you'll need to scrub every device on your network and figure out how the malware got in, or you'll just get reinfected a month or two later.

So, this new development is, not only are ransomware groups leaving you high and dry without your data if you don't pay the ransom, but also threatening to make you the victims of an expensive and embarrassing data leak if you don't pay both the normal decryption ransom, but a second ransom. This is terrifying, because, in addition to the loss of customer trust for the threats going out to customers that this causes, data breaches are EXPENSIVE. Let's take the medical space. Assuming that the resulting audit by Health and Human services for a HIPAA breach deems the healthcare practice did everything PERFECTLY, the MINIMUM you will be fined is 119 dollars, which sounds okay, until you realize that's PER RECORD. If your attackers leak say, a patient's name, date of birth, and social security number, for ONE patient, we're already up to 357 dollars. For one patient. If HHS deems you willfully negligent, the fine minimums go up to $11 thousand dollars, per record, or 60 thousand dollars per record. Again, per record. These fines can get up into the millions, fast. Depending on the case, there can even be jail time. Safe to say, most medical practices are not surviving this kind of attack if their patient data gets leaked, even if by some miracle there is NO loss of confidence in their patients losing them business. Outside the medical space, consequences are still bad, with total costs per incident of data breaches in US Small and Medium businesses averaging 1.24 MILLION for the breach and assorted work itself, and an additional 1.9 million per incident in average cost of business disruption and loss of business attributable to the breach. Remember, this is just for the breach, not even the ransom that's already been mentioned. This takes the already terrifying prospect of getting hit by ransomware, and makes it easily a hundred times worse. To top it all off, this is a damned if you do, damned if you don't situation, because paying the ransom is actually a violation of US law in most cases. To be perfectly honest, seeing ransomware combined with a data breach terrifies me.

So, what can we do to protect against this? 
Well, getting ransomwared is NOT an option, for any business, so the only option is multiple layers of protection. We're going to start with the big one, Backups, which is today's solution.

What can a backup do for you, and what does a good one look like?

Well, a backup is keeping a second copy of all your important data, so that if something happens to the first copy, you can load up the second copy and keep going. 

A proper backup should allow you to always have your data in any of the following scenarios

accidental deletion
malicious destruction by an employee
malicious destruction by a third party, like ransomware
damage or destruction of equipment, say from fire or flood
damage to supporting infrastructure required to access the data
Hardware failure

A good backup system will also allow you to restore to multiple points in time so that you can grab files that were deleted long ago, or versions of files that used to exist but got overwritten, and will not be reliant on a human to actually perform the backup. Finally, a good backup should be easily validated and tested, and done so frequently. After all, the only thing worse than not having a backup is THINKING you have a backup, right up until you need it.

Good in theory, but in practice, it's very easy to screw up. Let's look at some things that I have seen in the IT world that are not suitable backups, and talk about where they fail.

  1. Copying important files a second time to a different folder. This protects very little, basically just against a bad edit corrupting the file. If your computer gets Crypto'd, your second copy dies with it. Same deal with a lot of cases of being accidentally deleted, all cases of malicious deletion, or any damage to the equipment. It also relies on humans to update the copies. If you forget, you're out of luck.

  2. Copying important files to an external drive. This is little better than the above. It protects against the hard drive storing the data dying, I suppose, but everything else still applies assuming you keep it plugged into the computer. If you unplug it, it provides a SMALL amount of protection against ransomware, but relies on luck, of not being plugged in during the window between when you get infected and when you notice you get infected, a period that might be weeks, depending on the situation.

  3. Copying files to another computer or server. This will protect against a lot of cases of accidental deletion or malicious destruction by employees, not all of them, but most. Malicious destruction by malware, well, depends on the malware. A lot will only affect one machine. A lot won't stop at one computer and will affect an entire network. But if your facility burns down, your data goes with it, and you'll have no accounting records to show your insurance to have them evaluate what your business was worth. 

  4. Storing all your files in cloud storage like Google Drive or Onedrive. Okay, so this protects against accidental deletion, and, if you are manually copying stuff, most malware as well, it still introduces a human element, which is bad, It also does NOT protect against malicious insiders. You can get rid of the human element if you use sync software like the Onedrive desktop client, or Dropbox, but in doing so, you reintroduce the malware problem, and are still subject to malicious deletion.

  5. Using a local backup server. This is good, but not great on its own. Done RIGHT, which is not easy, it can protect against accidental and malicious insider deletion, most, but not all malware deletion. It even, if set up really well and really carefully, can provide versioning. Where it falls flat is if there's a natural disaster. That fire still burns servers. It also is not as robust against ransomware as it could be, and will be expensive in the long run relative to other, more protective options. A local server can be a PART of a good solution, but cannot on its own be the entire solution.

  6. Using non enterprise grade cloud backup software, like Carbonite. Most direct to cloud backup solutions have insufficient versioning, poor retention time, and take simply too long to recover from.

So, what does a good backup look like? A good backup backs up either direct to the cloud via a system that allows you to control both retention time and versions that are kept, or, better yet to a backup server that then backs up to the cloud. You should have at least 3 copies of your data, on 2 different types of storage, and at least one copy should be kept off site on a different network. If you follow these rules, it is virtually impossible to loose data, and no ransomware can leave you without. Next week, during our Tuesday episode, we will talk about other important tools to safeguard your business against ransomware.

That's our show for today, thank you so much for listening. I will see you then.