Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why advanced threat protections are the key to outsmarting the next ransomware attack

by The Gurus
August 4, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

The most prevalent cybersecurity concern in 2017 is undeniably ransomware, this year has seen it reassert itself into the public eye in a big way. The WannaCry attack in May was one of the largest ransomware attacks ever, affecting more than 300,000 computers running Microsoft Windows worldwide. What’s more the attack hit a huge range of public and private organisations.
It’s the old adage – fail to prepare and be prepared to fail, and people simply were not prepared for this attack. WannaCry demonstrated that far too many organisations do not have an effective security protocol in place, or don’t take it seriously until it is too late. This particular ransomware took advantage of a vulnerability that had been patched two months earlier in March, but many users had not updated their machines.
To further highlight the issue, when the Petya ransomworm launched just a few weeks later, using the exact same attack vectors, tens of thousands of organisations were still affected. Some are still feeling the consequences.
Cybercriminals are constantly on the lookout for an easy target and coming up with new ways to infiltrate them, with such a clear path in it’s no wonder someone took advantage of it. And organisations aren’t helping, simply because they are not taking care of the basics of patching and updating.
So, what are the options for protection? Well, the most important and arguably easiest protection is to keep your cyber hygiene in check. Keeping operating systems up to date and regularly applying security patches will ensure that weak point in a system is fixed before it can be taken advantage of maliciously. What’s more without these basic processes in place any additional security will be hampered. Additional layers of security need to work with a valid and up to date IT infrastructure to mitigate threats.
Basic hygiene is a must, but preparation is key and new advanced threat protection measures can turn the tables on the cybercriminals.
Sandboxing is a popular security measure that isolates code into a virtual environment where it can be executed and tested before entering the network. Anything detected as malicious will not be allowed to proceed. Unfortunately, some malicious code has developed to a point where it can detect the sandbox and disguise itself until it is cleared onto the network. To stay a step ahead of the cybercriminals, security must now detect malicious code that is actively disguising itself.
This is what advanced threat protection is all about, preparing for the next generation of ransomware attack by proactively detecting certain signatures and behaviours that would suggest a malicious executable. Signature detection traditionally monitors for an exact match of a known malicious code. However, with thousands of variations of the same code able to sneak past these systems newer pattern recognition systems make for a stronger defence.
For example, pattern recognition technology can distinguish over 50,000 code variations within a malware family, and stop them from infecting the network. With this level of coverage malicious code is far less likely to sneak through.
However, recognising code is one thing, it is also incredibly important to deeply analyse and detect code that is searching to see if it is in a sandbox environment. By spotting malicious code in this way it’s possible to render evasion technology irrelevant. A global threat network can provide further advantages, by identifying threats early and sharing that knowledge the spread of malicious software can be halted far more quickly.
If malicious code is not detected by these preliminary measures it is then executed in a sandboxed environment. If at this point it is found it can be shared with other local infrastructure to protect against the spread of the software and similar attacks.
Sandboxes are a powerful tool, but that makes them resource intensive and time-consuming. This is why it is often combined with other tools like firewalls, secure email gateways and endpoint security to minimise resource strain and keep network speeds high.
Ransomware attacks will only become more prolific as Ransomware as a Service (RaaS) gains traction on the dark web, allowing people to simply buy and execute someone else’s malware. On top of increasing the volume of attacks, ransomware is also becoming more sophisticated. Cybercriminals are constantly updating and releasing new iterations of their code in the hopes that it will outsmart security features. With that in mind, it is important that IT professionals take a proactive approach to security to anticipate tactics that hackers might use, perform effective threat analysis, and implement proper security measures to minimise impact.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Pentagon tests tablet access to secret classified documents

Next Post

Mitigating ransomware in the healthcare sector

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol