Latest News

  • Home /
  • Latest News

Mitigo - Are you resilient to a ransomware attack?

28 June 2022
David Fleming, Chief Technology Officer, Mitigo Cybersecurity

We’ve seen too many business owners having to endure it. The awful realisation that digital criminals are inside your firm, stealing and encrypting confidential personal and business information and using it to blackmail you.

You know for sure that your business is going to be severely damaged, and you’re going to have to explain yourself to the FCA, ICO and your clients.

To help you avoid this, here are our top 10 areas firms need to address to stop ransomware.
 
  1. Anti-Virus (AV) software.
AV is the software application that is designed to stop malicious software getting a foot hold on your devices and to prevent bad actors (hackers) taking control of your systems.

In the end-to-end journey of a successful ransomware attack, AV will have several opportunities to halt progress. Cyber criminals will attempt to switch it off as early in the journey as they can. Make sure it is centrally controlled, configured by a security specialist, kept up to date and on every device as a minimum.
 
  1. Email security filters.
Email platforms have filters that check incoming emails for malicious software, dodgy links and if they came from an untrusted origin.

One of the attackers’ favourite ways into a business is via an email. Setting your platform up correctly can make sure that employees are protected from this route in.
 
  1. Web browsing controls.
These controls are designed to stop or warn users they are about to visit a dangerous or fraudulent website.

To get around the AV software, fraudsters will often take unwitting staff to fraudulent websites. This risk can be minimised by correctly setting the controls in the browser, the AV and the operating system.
 
  1. Security patching.
Software providers like Microsoft or Google (Chrome) issue regular software updates that patch (fix) known vulnerabilities.

Cyber criminals will use bugs in software to compromise your defences and this is often used in ransomware attacks to get control. The simple discipline of updating these patches is probably the most neglected.
 
  1. Least privilege.
Every user on your system is assigned privileges that define what they can control, run, and amend.
 
Ransomware attackers take-over users’ accounts and the more privileges that a user has, the more damage the attacker can do. So an approach of least privilege should be followed.
 
  1. Remote authentication.
When working at a non-work location (e.g. at home) how do you tell business systems who you are and how do they authenticate that?

Username and password are no longer good enough protection for remote connection. Adding another method of authentication would stop a significant proportion of ransomware attacks.
 
  1. Test and scan externally facing assets.
Tests and scans of firewalls, domain addresses, login pages and IP addresses will check for vulnerabilities and gaps in your security defences.

You may not be scanning these, but the criminals are! So you need to find the open ports and poor configuration before they do.
 
  1. Review access management.
This relates to the documents, files, and folders that your system allows individuals to access.

There is a generic setting of “Everyone” in many systems. This means that everyone connected to the system can get to the documents, you do not even have to be authenticated. Access to documents should be defined by role.
 
  1. Alerting and incident response.
The controls and administration of your IT systems have alerts that warn you something is not right.

An incident response plan is a rehearsed set of steps that ensure businesses respond effectively to a cyber incident.

If you prepare these two things correctly you will have a chance of stopping a ransom attack in its tracks.
 
  1. Back-up.
This is the process by which your business takes a copy of the systems, applications, and documents for use in an emergency.

This is rarely configured correctly, which means that scarily few back-ups survive a ransomware attack, with everything ending up encrypted. Get yourself confident that yours would survive.
There is of course more to do, but if you do this top 10 well, it will dramatically reduce your risk. If you do not understand any of the above, please contact us.

Paradigm has partnered with Mitigo to offer cybersecurity risk management services to our members. Take a look at their full service offer here.

For more information contact Mitigo on 0161 8833 626 or email [email protected] 

 

30 December 2024

An evolving industrial landscape: post-election insights from the US


30 December 2024

The outlook for 2025


10 December 2024

Beyond the Budget – Unpacking IHT changes for your clients


4 December 2024

Triple Point Venture VCT - Early bird discount extended


3 December 2024

A Postcard from Boston: Onshoring, AI and the regulation of water


3 December 2024

The second Nucleus UK Retirement Confidence Index


25 November 2024

Investing alongside science to deliver a sustainable world


11 November 2024

Triple Point - What Budget changes to Business Relief mean for clients


4 November 2024

Edwards Lifesciences: shaping the future of cardiac care


28 October 2024

Gene therapy is set to change the face of medicine


22 October 2024

What China’s economic stimulus measures could mean for investors


16 October 2024

Triple Point - Venture VCT announces 2p tax-free dividend


7 October 2024

Triple Point - VCTs: a powerful way to help clients pay less income tax


2 October 2024

The next smart move for your clients


26 September 2024

Puma VCT 13 launches new £50m fundraise


24 September 2024

3 steps advisers can take to close the gender pension gap


19 September 2024

Puma Investments- Launches Puma AIM VCT


18 September 2024

M&G Wealth - Six ways to keep clients invested for long-term success


10 September 2024

M&G Wealth - Dash to cash: why it pays to think longer-term with your client’s money


6 September 2024

Join the Defaqto Future of Advice conference


2 September 2024

Triple Point - Understanding Venture Capital Trusts (VCTs)


28 August 2024

M&G Wealth - Keeping it smooth since 2004


19 August 2024

Prudential - Cost reductions and changes to our Strategic Asset Allocation


15 August 2024

Liontrust - Building a sustainable future with social housing


15 August 2024

Puma Investments - Join our CPD webinar: Closing the gaps: IHT and Estate planning featuring Tony Wickenden


7 August 2024

Liontrust - Plugging into the energy transition


6 August 2024

Defaqto - The Future of Advice - The Defaqto Adviser Conference


26 July 2024

Hello Kitty: A big cat in the investment universe?


24 July 2024

Liontrust – A postcard from Japan: enabling the sustainable transition


18 July 2024

Liontrust - Does a brighter future for housebuilding lie ahead?


16 July 2024

Triple Point – Holistic Estate Planning Strategy for Clients


8 July 2024

Triple Point – Join our CPD webinar: helping investors plan for big life events


1 July 2024

Intergenerational wealth planning for difficult times


24 June 2024

Liontrust Sustainable Investment: Annual Review 2023


19 June 2024

Investing in the energy transition


18 June 2024

Triple Point is partnering with ESG Accord to host a webinar: "A Practical Guide to SDR and Investment Labels for Advisers."


17 June 2024

Latest PruFund monthly investment updates


13 June 2024

Defaqto MPS Comparator: the UK's only accurate MPS performance tool


12 June 2024

Hear about Triple Point Venture VCT - 18th June 2024


6 June 2024

The Nucleus Retirement Confidence Index


24 May 2024

Join us for our Breakfast Briefing with Foresight! June 4th at 9:30am


17 May 2024

Looking forward with optimism


8 May 2024

The retirement income advice red paper


8 May 2024

Liontrust Views: Why smaller can be beautiful for US equities


7 May 2024

CPD Horizon Series: Tax planning for life’s key events


18 April 2024

Liontrust: Opportunities from secular growth trends


15 April 2024

Defaqto Roadshow - The challenges and opportunities of pursuing Income


11 April 2024

Liontrust: US small caps are overlooked and undervalued


4 April 2024

Q1 2024 Rebalance – we think the backdrop is good for stocks


21 March 2024

25 years of ISAs: a quarter of a century of tax-efficient savings and investing


4 March 2024

Stepping out of cash needn’t be daunting


26 February 2024

Managing lifetime wealth – trends in the UK retirement advice industry


23 February 2024

Empowering advice for women in finance


14 February 2024

Tech Matters is here!


5 February 2024

Defaqto upcoming event – Engage webinar 22nd February


1 February 2024

The gender divide in retirement confidence


30 January 2024

SDGs in focus: climate and nature


26 January 2024

Tax year end prep. We’re here to help.