Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Combatting ransomware: a holistic approach

How can businesses finally protect themselves from this ever more sophisticated threat?

by Nicolas Casimir
July 19, 2021
in Insight
Share on FacebookShare on Twitter

Although cybercrime as a whole has seen a rise during the pandemic, arguably ransomware has been one of the more successful and lucrative attack types. According to the World Economic Forum 2020 Global Risk Report, ransomware was the third most common, and second most damaging type of malware attack recorded last year, with payouts averaging a hefty $1.45M per incident. Our own research report, the State of Encrypted Attacks Report 2020, found that there had been a 500 per cent rise in ransomware compared to 2019.

It’s clear then that ransomware didn’t reach its zenith with WannaCry back in 2017 but remains a disruptive and profitable threat to business operations. The question, however, remains: how can businesses finally protect themselves from this ever more sophisticated threat?

Where are the gaps?

Although cybercriminals are increasingly executing more complex and targeted attacks, truth be told, we may be giving too much credit to the brilliance and sophistication of the ransomware hacker. Cybercriminals by their nature are opportunistic, and many of the techniques used to successfully disseminate malware are actually very simple. It rather is the holes left by IT departments, such as failing to update security policies, or using available tools adequately, that are letting ransomware attackers into the network.

Similarly, and this might sound odd from someone in a senior position at a cybersecurity company, but businesses sometimes rely too much on the technology, and not enough on process, personnel and their skills. There is no such thing as a security tool that requires a minimum amount of attention. Even when an organisation is choosing the built-in MS defender included with Windows 10 to ensure endpoint protection, different strategies should still be evaluated, such as scanning and update scheduling, and how to monitor the AntiVirus status.

Plenty of cybersecurity tools can detect threats, and flag them to security professionals, but remediation and mitigation needs to be handled through a robust operational process that can really dig into those logs, identify the most serious threats and remediate them appropriately. Too often we see security teams are not given enough time to get to grips with the new tools at their disposal, becoming overwhelmed by the number of alerts and not having a robust triage system to help them deal with them in an efficient manner.

Security hygiene is the best defence

Better operational practices, rather than technology, is really the key issue for a lot of businesses affected by ransomware. IT teams in particular need to improve their security hygiene to keep pace as ransomware varieties change. First and foremost, security teams need to ensure their patching and vulnerability management is up to date, as well as performing access reviews.

Additionally, teams should consider the least privilege principle for raising their security posture. This is essentially ensuring that staff can only access the applications they need to perform their duties,      instead of opening up the whole network for them. Implementing a strategy that prevents lateral movement can prevent attackers from traversing the entire network if they have successfully established an initial foothold.

A keen understanding and appreciation of how attackers can gain access is needed if an organisation is to put in place measures to ensure only authorised users obtain access to the necessary applications.

The internet can provide attackers all the knowledge they need about a company’s infrastructure to launch an attack, and organisations need to review how much information on their infrastructure they’re presenting online. Many will publish far more than they should, often completely oblivious to the fact that they’re doing so. A hastily thrown together development environment can act as a gateway for attackers to gain access to critical data, or a misconfigured server could be leaking data.

Even security defences themselves can provide unintended insights. A firewall or a VPN Gateway, for example, may provide information, which could be used to identify potential attack vectors.

Consider Zero Trust

Unlike more traditional security approaches, zero trust network access (ZTNA) can reduce a company’s vulnerability to attack by significantly reducing the attack surface. Zero trust starts with validating user identity combined with business policy enforcement based on contextual data from user, device, app and content to deliver authorised direct access to applications and resources. This means that no entity (user or application) is inherently trusted, removes application assets from public visibility and significantly reduces the surface for attackers.

Digital transformation and the move to remote work has fundamentally changed the way modern businesses operate. The necessarily rapid pace of change left IT departments with precious little time to fully consider new security architectures and the shifting threat landscape, now dominated by ransomware and DDoS. Now the dust has settled somewhat – and remote working is here to stay for many – security teams need to look at implementing new security models to meet these challenges. Adopting a holistic approach to the requirements of networks, applications, and security is the first step in increasing organisations’ defence against ransomware and wider cyber threats.

 

Contributed by Nicolas Casimir, CISO, Zscaler EMEA

ShareTweet
Previous Post

The new ransomware threat: triple extortion

Next Post

Netflix password crackdown: why users should be arguing for stronger measures

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol