Wednesday, May 25, 2022
TOP TECH
  • Home
  • Technology News
  • Artificial Intelligence
  • Computing
  • Gaming & Culture
  • Blockchain
  • Security
  • Space
  • Gadgets
No Result
View All Result
TOP TECH
No Result
View All Result
Photo of the Remarkables mountain range in Queenstown, New Zealand.
Home Security

The Colonial Pipeline ransomware attack a year on: 5 lessons for security teams

by admin
May 8, 2022
in Security
0
The Colonial Pipeline ransomware attack a year on: 5 lessons for security teams
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter


We’re excited to convey Remodel 2022 again in-person July 19 and nearly July 20 – 28. Be part of AI and knowledge leaders for insightful talks and thrilling networking alternatives. Register today!


At the moment marks the one-year anniversary of the Colonial Pipeline ransomware attack, one of many largest cyber attacks in latest historical past, the place a risk actor named DarkSide used a single compromised password to achieve entry to the US’s largest pipeline operator’s inside methods. 

In the course of the assault, whereas the hackers started encrypting the group’s knowledge, Colonial Pipeline responded by taking its methods offline to cease the unfold of the risk, however quickly ceased pipeline operations and ended up paying a ransom of $4.4 million. 

Whereas the Colonial Pipeline assault might have handed, ransomware stays an existential risk to trendy enterprises, and with ransomware attacks on the rise, enterprises should be ready. 

The excellent news is that there are a rising variety of safety controls that organizations can implement to guard themselves from these pervasive threats.

Deploy zero-trust architectures 

Login credentials are one of many key targets of cyber criminals. In consequence, it’s turning into extra essential for safety groups to implement assist for zero-trust authentication, to make it tougher for unauthorized customers to login with compromised credentials. 

“The Colonial Pipeline ransomware assault was yet one more high-profile instance of compromised credentials being leveraged to take advantage of a beforehand believed to be safe infrastructure. In consequence, safety protocols should evolve to maintain tempo with dynamic threats throughout distributed computing environments,” stated CTO and Co-Founding father of Id Entry Administration supplier Plain ID, Gal Helemski. 

Helemski recommend that organizations can stop themselves from falling sufferer to related assaults by implementing a zero-trust structure that extends entry controls previous conventional community entry safety all through the whole lifecycle of the digital journey. 

Implement strong incident detection and response capabilities 

One of many largest elements that determines the general impression of a ransomware breach is the time it takes for the group to reply. The slower the response time, the extra alternative a cyber prison has to find and encrypt essential knowledge property. 

“Colonial was an essential inflection level for private and non-private sector infrastructure safety, however organizations want to stay vigilant to remain a step forward of cyber-attackers,” stated Director of Cybersecurity Evangelism at ransomer detection and restoration platform Egnyte, Neil Jones. 

In observe, meaning creating a complete incident response plan, deploying options with ransomware detection and restoration capabilities, and providing workers cybersecurity consciousness coaching on the best way to implement efficient knowledge safety insurance policies like sturdy passwords and multi-factor authentication. 

Don’t depend on backup and restoration options to guard knowledge 

Many organizations search to defend in opposition to themselves from ransomware threats by counting on knowledge backup and restoration options. Whereas this appears like an efficient protection on paper, ransomware attackers have began to threaten to leak the information they’ve encrypted if the sufferer group doesn’t pay the ransom. 

Quite than counting on encryption-at-rest, which attackers can use compromised credentials to sidestep, Arti Raman, CEO and Founding father of encryption-in-use supplier Titaniam recommends that organizations change to knowledge in-use safety. 

“With encryption-in use knowledge safety, ought to adversaries break by means of perimeter safety infrastructure and entry measures, structured in addition to unstructured knowledge can [and] will [be] undecipherable and unusable to unhealthy actors – making digital blackmail considerably tougher, if not inconceivable,” Raman stated. 

Create a list of your assault floor 

With so many superior risk actors concentrating on trendy organizations with ransomware threats, technical resolution makers and safety groups have to have an entire stock of what methods are uncovered to exterior risk actors and what knowledge they maintain. 

World's Best Mobile app builder that turns your website into a Stunning mobile app in 1 click

“Because the U.S. authorities strikes to bolster nationwide cybersecurity, organizations should take a proactive strategy to safe their very own property, and right here is the place the benefit lies: responsiveness,” stated CEO and co-founder of managed safety companies group,Cyber Security Works, Aaron Sandeen. 

“By conducting an entire system stock both independently or outsource to a vulnerability administration firm, organizations develop their cybersecurity visibility of identified and unknown exploits,” Sandeen stated.  

Whereas the group behind the Colonial Pipeline assault are defunct, Sandeen warns that enterprises will proceed to see a rising variety of exploits, vulnerabilities and APT risk actors keen to take advantage of them, “which is able to want safety leaders offering predictive and creative help in categorizing and eliminating ransomware threats.” 

Deploy id administration options to establish anomalous consumer exercise 

Within the period of distant working and workers utilizing private gadgets to entry enterprise assets, the chance of knowledge theft is bigger than ever earlier than. “Many of the breaches we hear about within the information are a results of companies counting on automated entry management and realizing too late when a consumer has been hijacked. 

“As soon as an account is compromised, identity-based fraud will be extraordinarily troublesome to detect contemplating the superior ways and randomness of various crime teams like LAPUS$ and Conti,” stated CISO of belief platform, Forter, Gunnar Peterson. 

--->>Make 1,000$ A Day - Click Here<<---

Because of this, organizations have to have the power to establish anomalous consumer exercise to allow them to detect account takeover, which Peterson says will be obtained by means of utilizing an AI-driven id administration resolution with anomaly detection. 

VentureBeat’s mission is to be a digital city sq. for technical decision-makers to achieve data about transformative enterprise know-how and transact. Learn more about membership.



Source link

SUBSCRIBE NOW

No spam guarantee.

--->>Make Money Working 30 Minutes A Day - Click Here<<---
--->>Start Changing Your Life Today - Click Here<<---
ShareTweetShare
Photo of the Remarkables mountain range in Queenstown, New Zealand.

Related Posts

AMD unveils Epyc confidential computing on Google cloud
Security

AMD unveils Epyc confidential computing on Google cloud

May 25, 2022
The Surveillance State Is Primed for Criminalized Abortion
Security

The Surveillance State Is Primed for Criminalized Abortion

May 25, 2022
Netskope releases new data loss prevention solution
Security

Netskope releases new data loss prevention solution

May 24, 2022
Open Source Intelligence May Be Changing Old-School War
Security

Open Source Intelligence May Be Changing Old-School War

May 24, 2022
Why AI and autonomous response are crucial for cybersecurity (VB On-Demand)
Security

Key findings from the DBIR: The most common paths to enterprise estates

May 24, 2022
Recovering from ransomware attacks starts with better endpoint security
Security

Recovering from ransomware attacks starts with better endpoint security

May 23, 2022
Next Post
Engineering scares with Glen Schofield

Engineering scares with Glen Schofield

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

DON'T MISS OUT!
Subscribe To Our Newsletter So You Do Not Miss Any Updates Or Special Offers
We promise not to spam you. Unsubscribe at any time.
Invalid email address
Thanks for subscribing!

Recommended

How to build an NFT website

How to build an NFT website

March 28, 2022
Sony is now publishing PC games under PlayStation PC LLC

The most-anticipated games (hopefully) coming in 2022

January 2, 2022
iFixit’s Mac Studio teardown reveals monster cooling system

iFixit’s Mac Studio teardown reveals monster cooling system

March 25, 2022
Watch SpaceX’s all-civilian spaceflight return to Earth starting at 6PM ET

Watch SpaceX’s all-civilian spaceflight return to Earth starting at 6PM ET

September 19, 2021
Meta teases a web version of Horizon Worlds

Meta teases a web version of Horizon Worlds

April 14, 2022
Nvidia CEO: We gave Arm deal our best shot

Nvidia CEO: We gave Arm deal our best shot

February 16, 2022

Recent News

The 2022 Hurricane Forecast Is Here, and It’s Bad

The 2022 Hurricane Forecast Is Here, and It’s Bad

May 25, 2022
The Download: Google’s AI cuteness overload, and America’s fight for gun control

The Download: Google’s AI cuteness overload, and America’s fight for gun control

May 25, 2022
A PC monitor with a 500 Hz refresh rate is coming from Asus

A PC monitor with a 500 Hz refresh rate is coming from Asus

May 25, 2022

Photo of the Remarkables mountain range in Queenstown, New Zealand.

Categories

  • Artificial Intelligence
  • Blockchain
  • Computing
  • Gadgets
  • Gaming & Culture
  • Security
  • Space
  • Technology News
Photo of the Remarkables mountain range in Queenstown, New Zealand.

Find Via Tags

adds Amazon Android app Apple Apples apps automation big Blockchain Business Cloud cybersecurity Data digital Facebook Future game games gaming Google hackers launches Metaverse Microsoft million open platform raises report Review Security series software Star Startup tech TechCrunch trailer Ukraine Windows work world year years
  • Privacy & Policy
  • About Us

© 2021 Top Tech

No Result
View All Result
  • Home
  • Technology News
  • Artificial Intelligence
  • Computing
  • Gaming & Culture
  • Blockchain
  • Security
  • Space
  • Gadgets

© 2021 Top Tech

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.