Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Defending against the fastest growing threat of 2016 – Ransomware

by The Gurus
February 10, 2017
in This Week's Gurus
ransomware
Share on FacebookShare on Twitter

Carbon Black data shows that ransomware instances grew by more than 50% in 2016 compared to 2015. In fact, ransomware emerged as the fastest-growing malware across all industries in 2016, with major increases seen at technology companies, energy and utility companies and banking organisations. As a result, we do not expect ransomware to slow down anytime soon, and seeing as its on track to be a $1 billion crime in 2017, it is still paying significant dividends for attackers.
Not only this, but ransomware is quickly evolving in sophistication as well. Payloads are increasingly infecting hundreds of machines at once. This was witnessed just last month when a string of ransomware attacks on MongoDB databases left roughly 27,000 servers compromised, with the attackers demanding significant financial reward in exchange for the stolen data.
Cybersecurity news was dominated in 2016 by the go-to ransomware family for attackers, Locky. Only released last year, Locky ransomware is typically delivered via a phishing email that prompts a targeted victim to enable malicious macros via Microsoft Word. These macros then run a file that delivers an encryption Trojan, preventing the victim from accessing their files. Following the file encryption, the victim receives a message with instructions on how to pay a Bitcoin ransom to decrypt the files.
Having gained notoriety in February 2016, data shows that Locky was used in one out of four ransomware-based attacks last year and has evolved several times since then. Most recently, attackers have been using Facebook instant messaging to spread Locky ransomware.
When it comes to ransomware, prevention is the most effective defence. So how can organisations protect themselves against ransomware?

  1. Back up data regularly. Verify the integrity of those backups and test the restoration process to ensure its working. In addition to this secure your offline backups. If you’re infected a backup may be the only way to recover your data. Ensure backups are not connected permanently to the computers and networks they are backing up.
  2. Block access. Configure firewalls to block access to known malicious IP addresses and logically separate networks. This will help prevent the spread of malware. If every user and server is on the same network, newer variants can spread.
  3. Train your employees. Implement an awareness and training programme. End users are targets, so everyone in your organisation must be aware of the threat of ransomware and how it’s delivered.
  4. Scan all incoming and outgoing emails. Scanning ensures threats are detected and executable files are prevented from reaching end users. Furthermore, enable strong spam filters to prevent phishing emails from reaching end users and authenticate inbound email using technologies such as Sender Policy Framework (SPF), Domain Message Authentication Reporting and Conformance (DMARC), and DomainKeys Identified Mail (DKIM) to prevent spoofing.
  5. Block ads. Ransomware is often distributed through malicious ads served when visiting certain sites. Blocking ads or preventing users from accessing certain sites can reduce that risk.
  6. Only assign administrative access unless needed. If a user only needs to read specific files, the user should not have write access to them.
  7. Leverage next-generation antivirus (NGAV) technology to inspect files and identify malicious behavior to block malware and malware-less attacks that exploit memory and scripting languages.
  8. Categorise data based on organisational value and implement physical and logical separation of networks and data for different organisational units.

While ransomware continues to generate headlines, it is still only a piece of the overall malware scope. Even with its rapid growth, ransomware still only accounts for 2% of total malware seen in 2016.
With ransomware attacks not showing any sign of depleting, it is also essential that organisations looking to defend against ransomware in 2017 are well versed in the prevention methods presented above.
 
Written by Eric O’Neill, National Security Strategist, Carbon Black

ShareTweet
Previous Post

Imperva profile – Spencer Young: Ransomware is a war businesses must fight

Next Post

UK firm launches new identity app to help reduce online fraud

Recent News

Frontline Workers Twice as Likely to Use Unapproved AI

Frontline Workers Twice as Likely to Use Unapproved AI

June 4, 2026
Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol