Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Rebuffing Ransomware: Common Sense Advice from CompTIA

by The Gurus
June 30, 2017
in Editor's News
Share on FacebookShare on Twitter

The Petya ransomware attack – the second major global cyberattack in two months – left a trail of locked computers and compromised networks in some 65 countries around the world.
Like the WannaCry attack in May, Petya this week exposed weaknesses in cybersecurity defenses. It also reinforces the notion that it’s a case of when, not if, your organisation will become the target of an attack. But the high likelihood that an attack is coming doesn’t necessarily mean that dire consequences are inevitable.
“There is no 100-percent foolproof strategy for blocking cyberattacks, short of swearing off computers, email and the Internet,” said Randy Gross, CIO of CompTIA, a non-profit association for the technology industry. “But there are steps that can and should be taken to heighten defenses, starting with making sure that all systems are up to date.”
“Installing vendor patches in a timely manner and having an update plan in place for all client machines is a good start,” advised Robert Rohrman, CompTIA’s senior director of information services infrastructure.
Far too many computers still run outdated operating systems like Windows XP and Server 2003 and simply do not have the proper security protocols in place to prevent ransomware attacks, according to Rohrman. Even devices with newer operating systems can be vulnerable if security patches and software updates are delayed or ignored.
“A globally managed update system for clients and server/hosted resources is the best way to gain visualisation into an enterprise,” Rohrman said. He suggested IT managers have a system or program in place that provides a global view of the in-house systems and security situation so patches and fixes can be installed on multiple computers from one console.
But patching isn’t the only action you can take to defend against ransomware. The regular backup of data, stored off the primary computer, is another critical task.
“You can depend on your own backup more than a vendor patch because you have control over the backup,” explained James Stanger, CompTIA’s senior director for product development.
“Vendors can’t always get you the latest patch in time, which means that your systems could still be susceptible to zero-day attacks,” he continued. “Your system may have all of the updates the vendor has given, but an exploitable problem still exists.”
Stanger added that when you know your data is backed up, you’re less likely to feel pressured to pay a ransom because you already have what the cybercriminal is holding hostage.
Finally, it’s critical for everyone in the organisation – from the receptionist at the front desk to the IT technician in the back office, and from the CEO in the corner office to the account manager on the road – to learn and use good cybersecurity hygiene. Anyone who touches a PC, laptop, smartphone or tablet is a potential target of ransomware or other cyber threats, but threats can be lessened and security awareness heightened through regular education and training.
“Companies consistently repot that human error is the primary cause of security breaches,” said Seth Robinson, senior director, technology analysis, CompTIA. “People don’t know, or are ignoring some of the basic security practices. The encouraging news is that we’re seeing a growing realisation among companies that their workforce needs to be educated about technology in general, and about security, specifically.”
The types of training offered run the gamut, according to the recent CompTIA report “The Evolution of  Security Skills.” In the survey of 350 U.S. businesses, about half said they perform employee security training on an ongoing basis. Also:

  • 58 percent include security instruction as part of their new employee orientation
  • 46 percent conduct random security audits
  • 35 percent use “live fire” hands-on labs

“In a rapidly changing environment, simple one-time efforts such as new employee orientation or posting security policies for review will have low efficacy,” Robinson said. “Organisations are starting to understand that security training is needed for all jobs and that some oversight is needed to develop a security-aware culture.”
“Too often security is perceived as an inconvenience by users,” said Rohrman. “Many people talk a great game in security, but when it comes to taking the additional safeguards that security requires, many users will resist and opt for the easy, convenient way without regard to the potential consequences.”
The cost of a single data breach is estimated at $3.62 million, according to the Ponemon Institute’s “2016 Cost of Data Breach.” Ransomware attacks – which cost companies an estimated $1 billion in 2016 – could approach $5 billion this year, market researcher Cybersecurity Ventures reports.
The clear answer for organisations is to create, implement and enforce robust security practices and policies; and to explain and train those policies to their employees to ensure maximum buy-in and compliance.

Tags: CyberMalwareRansomwaresecurityTechnology
ShareTweet
Previous Post

8Tracks Breach Exposes Millions of Accounts

Next Post

The costs of VPNs: It’s not the printer…it’s the ink

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol