<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ransomware - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/ransomware-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/ransomware-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 02 Apr 2026 06:36:55 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>ransomware - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/ransomware-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </title>
		<link>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/#respond</comments>
		
		<dc:creator><![CDATA[Axel Petersen]]></dc:creator>
		<pubDate>Thu, 02 Apr 2026 06:36:52 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cybercriminality]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=29548</guid>

					<description><![CDATA[<p>In 2025, ransomware attacks remained a persistent threat and increasingly targeted backup systems (21% of attacks targeted backups in 2021, compared with 90% in 2025 [1] ). Protecting backups,&#160;now also subject to strengthened regulatory requirements such as NIS 2,&#160;has therefore...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/">Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-contrast="auto">In 2025, ransomware attacks remained a persistent threat and increasingly targeted backup systems (21% of attacks targeted backups in 2021, compared with 90% in 2025 [</span><span data-contrast="auto">1] </span><span data-contrast="auto">). Protecting backups,&nbsp;now also subject to strengthened regulatory requirements such as NIS 2,&nbsp;has therefore become a top priority in addressing this threat.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:360}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">This article presents four complementary approaches to strengthening end-to-end backup security:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ol>
<li><strong>Continuously ensuring the availability of usable backups&nbsp;</strong></li>
<li><strong>Strengthening the security of the backup infrastructure against attacker takeover&nbsp;</strong></li>
<li><strong>Protecting backups against logical destruction&nbsp;</strong></li>
<li><strong>Identifying&nbsp;residual risks&nbsp;in light of&nbsp;the measures implemented&nbsp;</strong></li>
</ol>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">This article is published in two parts: the first focuses on approaches 1 and 2, followed by a second publication covering approaches 3 and 4.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The recommendations presented do not replace those set out in ANSSI guidelines, which define the fundamental principles of backup [</span><span data-contrast="auto">2]</span><span data-contrast="auto">&nbsp;practices.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2}"> <img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-29535" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image.png" alt="Renforcer la sécurisation des sauvegardes par 4 approches" width="579" height="519" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image.png 579w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image-213x191.png 213w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/03/image-44x39.png 44w" sizes="(max-width: 579px) 100vw, 579px" /></span></p>
<p style="text-align: center;"><em>Figure 1: Strengthening Backup Security Through Four Approaches&nbsp;</em></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559685&quot;:720}">&nbsp;</span></p>
<h1><b><span data-contrast="none">1. Continuously ensuring the availability of usable backups</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559685&quot;:1080,&quot;335559740&quot;:259,&quot;335559991&quot;:360}">&nbsp;</span></h1>
<p style="text-align: justify;"><span data-contrast="auto">To guarantee the availability of usable backups, it is essential to apply fundamental best practices.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Ensuring backup completeness and consistency</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">In the context of a ransomware attack, the primary&nbsp;objective&nbsp;of backups is to provide a reliable data source enabling the reconstruction of the information system. Backups are truly effective only if they&nbsp;contain&nbsp;all the elements&nbsp;required&nbsp;for full recovery. This notably includes&nbsp;businesscritical&nbsp;data, configurations of business applications and systems, installation sources, as well as critical operational data such as password vaults, licenses, and operational documentation.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Backup completeness alone is not sufficient. The need for data&nbsp;consistency&nbsp;points across backups originating from different sources (e.g., a document management system (DMS) database and its associated files) must also be&nbsp;taken into account. Conducting a preliminary analysis helps&nbsp;facilitate&nbsp;data resynchronization across different repositories during the recovery phase.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">In addition, it is necessary to&nbsp;maintain&nbsp;backups of the&nbsp;infrastructure itself&nbsp;to enable identical reconstruction. These backups must include the backup catalog, software installation sources, encryption keys, and all other required secrets. A copy of configuration parameters should be stored in a separate location,&nbsp;such as an offline environment,&nbsp;distinct from the primary infrastructure,&nbsp;in order to&nbsp;limit the risk of a shared compromise.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<p style="text-align: justify;"><i><span data-contrast="none">According to the Cyber Benchmark conducted by Wavestone across more than 170 assessed organizations, approximately </span></i><b><i><span data-contrast="none">90%</span></i></b><i><span data-contrast="none">&nbsp;of the&nbsp;organizations&nbsp;observed&nbsp;perform&nbsp;regular&nbsp;data backups.</span></i>&nbsp;<br><i><span data-contrast="none">Among&nbsp;organizations&nbsp;that&nbsp;perform&nbsp;regular&nbsp;backups:</span></i><span data-ccp-props="{&quot;335559685&quot;:0}">&nbsp;</span></p>
<ul>
<li><i><span data-contrast="none">Approximately&nbsp;</span></i><b><i><span data-contrast="none">65%</span></i></b><i><span data-contrast="none">&nbsp;conduct&nbsp;</span></i><b><i><span data-contrast="none">restoration&nbsp;tests</span></i></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
<li><i><span data-contrast="none">Approximately&nbsp;</span></i><b><i><span data-contrast="none">20%</span></i></b><i><span data-contrast="none">&nbsp;perform&nbsp;</span></i><b><i><span data-contrast="none">business data&nbsp;consistency&nbsp;checks</span></i></b><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">In this context, various controls must be defined and implemented on a regular basis.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Testing Backup Reliability Through Regular Controls</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">A first&nbsp;level of control aims to ensure that backups are effectively performed and remain usable. This can be based on the application of daily verification procedures relying on evidence such as reports, logs, and alerts. These checks may be manual or (semi)&nbsp;automated. However, an&nbsp;additional&nbsp;human review&nbsp;remains&nbsp;necessary to ensure that indicators and alerts are not misleading,&nbsp;particularly&nbsp;in the event that&nbsp;monitoring&nbsp;and control mechanisms have been compromised or disabled by an attacker.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">This first level also includes periodic restoration tests, carried out on representative scopes,&nbsp;in order to&nbsp;verify,&nbsp;where possible with the involvement of application or business subject-matter experts,&nbsp;the integrity and completeness of the data&nbsp;required&nbsp;for business recovery.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The second level consists&nbsp;in&nbsp;ensuring that first-level checks are properly applied. It relies on independent controls or formalized processes. Dashboards may be used to centralize confidence-level indicators by correlating the results of daily operational checks with restoration test outcomes.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Once the reliability of backups has been&nbsp;established, restoration processes should be&nbsp;optimized&nbsp;by regularly testing them and ensuring their effectiveness.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Industrializing Restoration Processes to Optimize Recovery Time&nbsp;in the Event of&nbsp;a Compromise</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">To reduce recovery time following a compromise, it is essential to industrialize restoration&nbsp;processes at&nbsp;scale&nbsp;in order to&nbsp;support mass recoveries. This requires preparing these processes in advance, testing them regularly, and adapting them to different destruction scenarios.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">As the restoration phase of an information system may extend over several weeks,&nbsp;or even several months,&nbsp;it is necessary to increase backup retention periods for the data to be restored,&nbsp;in order to&nbsp;prevent their loss through overwriting or premature deletion.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Restoration processes must also include mechanisms to rapidly assess the state of&nbsp;backedup&nbsp;data by&nbsp;identifying,&nbsp;based on indicators of compromise,&nbsp;data that has been compromised,&nbsp;modified, or corrupted,&nbsp;so as to&nbsp;effectively target the&nbsp;appropriate restoration&nbsp;points.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Integrating the Risk of Backup Compromise into the Restoration Strategy</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">To ensure reliable recovery following a compromise, it is essential to account, within the overall restoration strategy, for the risk of alteration or manipulation of&nbsp;backedup&nbsp;data. This involves addressing the risk of data alteration or manipulation occurring upstream of backup processing by the backup agent, for example:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto">Being able to rely on full backups created prior to the attacker’s intrusion, as&nbsp;identified&nbsp;during the&nbsp;initial&nbsp;investigations. In such cases, the&nbsp;backedup&nbsp;data can be considered uncompromised and used to rebuild systems and applications.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">When restoring unaltered application or system components that are not reinstalled from trusted sources, the restoration process must also include the application of security patches and hardening measures to prevent any&nbsp;subsequent&nbsp;compromise.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">The backup process alone cannot prevent potential data compromise before the data is handed over to it. Depending on the context,&nbsp;additional&nbsp;measures may be implemented, such as:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<ul>
<li><span data-contrast="auto">Protecting data integrity through system-level mechanisms and/or cryptographic&nbsp;means;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
<li><span data-contrast="auto">Detecting data alteration through application-level validation,&nbsp;monitoring&nbsp;of “canary&nbsp;files” data, or the use of an EDR (Endpoint Detection and Response) solution.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">These topics must be addressed in addition to backup protection measures.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Extending Backup and Restoration Best Practices to Cloud Environments</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Finally, the backup rules defined for&nbsp;onpremises&nbsp;environments must be replicated and adapted to cloud environments.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><i><span data-contrast="none">According to the Cyber Benchmark conducted by Wavestone, approximately 25% of the organizations observed have a regularly reviewed and updated backup policy covering both onpremises and cloud environments.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}">&nbsp;</span></p>
<p style="text-align: justify;"><i><span data-contrast="none">In addition,&nbsp;around&nbsp;29% of&nbsp;organizations&nbsp;externalize&nbsp;a backup of&nbsp;their&nbsp;cloud data to&nbsp;another&nbsp;region&nbsp;or to an&nbsp;onpremises&nbsp;environment,&nbsp;ensuring&nbsp;resilience&nbsp;against&nbsp;cyberattacks&nbsp;and&nbsp;regularly&nbsp;testing&nbsp;this&nbsp;process.</span></i><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559740&quot;:259}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Beyond the usability of backups, securing the infrastructure that hosts them&nbsp;represents&nbsp;an equally critical challenge,&nbsp;one that is sometimes insufficiently addressed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h1><b><span data-contrast="none">2. Strengthening the security of the backup infrastructure against attacker takeover</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559740&quot;:259}">&nbsp;</span></h1>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Before considering more advanced mechanisms, it&nbsp;is important to recall that effective backup protection first relies on best practices for securing the backup infrastructure, notably those documented by ANSSI</span><span data-contrast="auto">3</span><span data-contrast="auto">. A compromise of this infrastructure could indeed result in the alteration of backups (encryption, destruction, etc.).</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<h2><b><span data-contrast="none">Ensuring Defense in Depth for the Backup Infrastructure</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">These best practices include segregating production and backup environments, using dedicated administrative accounts, and hardening infrastructure components,&nbsp;particularly through the application of ANSSI hardening guides applicable to Windows, Linux, and other systems. They also apply to backup agents, which may&nbsp;constitute&nbsp;a propagation vector toward production systems.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">In addition to hardening measures, the backup infrastructure must be subject to both technical and cybersecurity monitoring.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Implementing technical and cyber monitoring of backup infrastructures</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Technical monitoring of backup infrastructures helps ensure&nbsp;their proper&nbsp;operation and detect any anomalies. The effective handling of detected anomalies must be regularly reviewed.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Cybersecurity monitoring of the backup infrastructure relies on&nbsp;appropriate logging&nbsp;and traffic analysis. It must be capable of detecting the main attack techniques&nbsp;observed&nbsp;in the wild.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<h2><b><span data-contrast="none">Maintaining&nbsp;Threat Intelligence Focused on Backup Systems</span></b><span data-ccp-props="{}">&nbsp;</span></h2>
<p>&nbsp;</p>
<p style="text-align: justify;"><span data-contrast="auto">Threat intelligence specifically targeting backup systems must be&nbsp;maintained, beyond the technical vulnerability monitoring performed as part of&nbsp;maintaining&nbsp;the backup infrastructure in a secure operating condition. This&nbsp;threat&nbsp;intelligence should cover attack techniques and tactics used against backup infrastructures,&nbsp;in order to&nbsp;anticipate&nbsp;potential attacks and adapt protection, detection, and response capabilities accordingly.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p style="text-align: justify;"><span data-contrast="auto">Despite the measures implemented to prevent the compromise of backup infrastructures, the risk of logical destruction&nbsp;remains&nbsp;and must be&nbsp;anticipated.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}">&nbsp;</span></p>
<p>&nbsp;</p>
<h1>Reference</h1>
<p>[1] Wavestone, <a href="https://www.wavestone.com/en/insight/2024-wavestone-cert-report/">CERT</a></p>
<p>[2] ANSSI, <a href="https://messervices.cyber.gouv.fr/guides/fondamentaux-sauvegarde-systemes-dinformation">Sauvegarde des systèmes d&#8217;information</a></p>
<p>[3] ANSSI, <a href="https://messervices.cyber.gouv.fr/guides/fondamentaux-sauvegarde-systemes-dinformation">Sauvegarde des systèmes d&#8217;information</a></p>






<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/">Backups : The Last Line of Defense Against Ransomware &#8211; Part 1 </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/04/backups-the-last-line-of-defense-against-ransomware-part-1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Successful Ransomware Crisis Management: Top 10 pitfalls to avoid</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/#respond</comments>
		
		<dc:creator><![CDATA[Nicolas Gauchard]]></dc:creator>
		<pubDate>Fri, 06 Jan 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[crisis management]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19337</guid>

					<description><![CDATA[<p>Once again, the CERT-W 2022 report confirms that the main motivation of attackers continues to be financial gain and ransomware remains the most common means of extortion. Ransomware attacks are among the most severe cyberattacks in terms of their impact on...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/">Successful Ransomware Crisis Management: Top 10 pitfalls to avoid</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">Once again, the <a href="https://www.wavestone.com/fr/insight/cert-w-2022-cybersecurite-tendances-analyses/">CERT-W 2022 report</a> confirms that the main motivation of attackers continues to be financial gain and <strong>ransomware</strong> remains the most common <strong>means of extortion</strong>. Ransomware attacks are among the most severe cyberattacks in terms of <strong>their impact on the continuity</strong> of IT services and, by extension, the business operations itself.</p>
<p style="text-align: justify;">Wavestone assists many victims in managing their <strong>crisis triggered by ransomware attacks</strong>. Often, poorly trained IT and management teams make incorrect decisions in response to these unexpected situations.</p>
<p style="text-align: justify;">This list of the top ten pitfalls to avoid in ransomware crisis management is based on the feedback from over 5 years of supporting victims.</p>
<p> </p>
<h1 style="text-align: justify;">#1 Paying the ransom will speed up your back up process</h1>
<p style="text-align: justify;">Although the French National Agency for the Security of Information Systems (ANSSI) recommends never paying a ransom, <strong>this question will always arise</strong> for certain stakeholders, especially the decision-makers, who are not completely aware of these issues. Beyond the fact that paying the ransom encourages attackers to continue their activities, it should also be noted that paying the ransom <strong>does not always lead to the recovery of the decryption key.</strong></p>
<p style="text-align: justify;">In cases where a ransom payment allows the decryption key to be obtained, the <strong>decryption time</strong> is often very lengthy. It can take several hours or even dozens of hours per server or workstation, depending on the size of the encrypted files. When there are large numbers of computers, strict coordination is necessary for processing all the systems. In comparison, it will be <strong>faster to restore systems from backups</strong>.</p>
<p style="text-align: justify;">In addition to the time required, the encrypting or decrypting process is rife with errors, according to past experience. Thus, even with the decryption key, certain <strong>files</strong>, particularly the largest ones, are sometimes <strong>modified</strong> and cannot be restored as they are.</p>
<p style="text-align: justify;">In short, we are far from the widely held notion that a simple click can restore a functional information system after ransom payment. <strong>There is no point in considering a ransom payment</strong> to restart services if there are <strong>healthy and functional backups</strong>. In the case of data theft, the issue gets more complex.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">#2 Reopening the information system too quickly</h1>
<p style="text-align: justify;">To limit operating losses due to inactivity, the crisis unit is often <strong>urged by the business to restart the information system as quickly as possible</strong>. During the reconstruction phase following a cyber-attack, it is necessary to control the following two main risks:</p>
<ul>
<li style="text-align: justify;">Resumption of the attacker&#8217;s attack and <strong>re-encryption of the reconstructed systems</strong></li>
<li style="text-align: justify;">Theft of new information by the attacker who restarts the <strong>data exfiltration</strong></li>
</ul>
<p style="text-align: justify;"><strong>Isolating the information system</strong> from the outside world is the initial security measure that must be implemented to reduce these risks significantly (internet access in and out, links with partners, etc.). This measure eliminates the connection between the attacker and his malicious tools, and thus drastically reduces the likelihood of a repeated attack. Certain external flows can be opened individually for the most critical activities (from or to a controlled server, on a given port), but reopening a wide range from or to the outside increases the risks.</p>
<p style="text-align: justify;">Restoring servers is the first step in the rebuilding process. However, since servers are not always backed up simultaneously, <strong>resynchronisation of applications and data are often necessary</strong> before the servers are put into service. As an example, a hasty restart of a payment application during a crisis has already resulted in a double payment of hundreds of thousands of euros, which had already been transmitted to the bank before the attack.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">#3 Wait for an extreme level of security before reopening</h1>
<p style="text-align: justify;">As cyberattacks can have a significant impact, fear of repeated attacks can be traumatic for crisis teams, leading them to impose an <strong>extreme level of security</strong> before restarting. The challenge here is to find the right <strong>balance between security and rapid recovery.</strong></p>
<p style="text-align: justify;">There are two possible strategies for rebuilding servers:</p>
<ul>
<li style="text-align: justify;"><strong>The green zone strategy-</strong> It prioritises security over the speed of recovery. It involves creating a new network zone in which only the rebuilt machines are hosted. The technical components (Active Directory, DHCP, DNS, etc.) are dedicated to this secure zone. However, changing the addressing plan can have unintended consequences and it will slow down the reboot.</li>
<li style="text-align: justify;"><strong>The grey zone approach-</strong> It favours the speed of recovery over security. It consists of rebuilding or restoring servers in their initial zone. Compromised machines can be found alongside the restored machines. This strategy will represent a risk when the attack is propagated from server to server.</li>
</ul>
<p style="text-align: justify;"><img decoding="async" class="aligncenter wp-image-19326 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN.png" alt="" width="4180" height="1921" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN.png 4180w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN-416x191.png 416w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN-768x353.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN-1536x706.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image1EN-2048x941.png 2048w" sizes="(max-width: 4180px) 100vw, 4180px" /></p>
<p style="text-align: justify;">The choice of strategy must be made in the light of the investigations and techniques used by the attacker. As mentioned earlier, isolation from the outside world remains as a key measure in reducing the risk.</p>
<p> </p>
<h1 style="text-align: justify;">#4 Denying a restart in degraded mode</h1>
<p style="text-align: justify;">In most companies, IT has become indispensable for all their operations. In the exceptional situation of a total IT shutdown, it is often initially inconceivable to <strong>continue working without IT</strong>. This is the common argument put forward by the IT and business managers during cyber crisis.</p>
<p style="text-align: justify;">By working in <strong>degraded mode</strong>, it is possible to <strong>limit the impac</strong>t in many instances. This includes implementing previously defined resilience and business continuity plans. To consider implementing these plans when all the activities are ceased during a crisis, special emphasis must be given to when these activities were stopped during the crisis, as well. Managers often underestimate the mobilisation and creativity of the teams to work differently (disengaging non-essential processes, transferring to a partner, carrying out operations manually, etc.).</p>
<p style="text-align: justify;">It is essential to find a <strong>good balance</strong> between restarting the first application in degraded mode within two days, rather than waiting two weeks to have the complete application chain.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">#5 Wanting to restart all at once</h1>
<p style="text-align: justify;">Quite often, the information systems of large organisations contain hundreds or thousands of applications. During cyber crisis situations, it is impossible to spend an enormous time on all these applications. Thus, it is essential to prioritise them by defining a restart order.</p>
<p style="text-align: justify;">Each department often tends to consider that its own activity is the most important in the company. Arbitration by general management is often necessary to establish a <strong>restart plan</strong> that can be utilised by everyone. Some departments, countries, or regions will see their applications getting started later than others too.</p>
<p style="text-align: justify;">It should also be noted that there are many <strong>dependencies between applications,</strong> and these are not always known by IT teams. But this must be considered in the reboot plan.</p>
<p> </p>
<h1 style="text-align: justify;">#6 Executing major changes in a hurry</h1>
<p style="text-align: justify;">It is sometimes tempting to want to take advantage of the situation of a system shutdown <strong>to carry out major changes</strong> in the information system.</p>
<p style="text-align: justify;">Security teams see this as an opportunity to <strong>carry out projects that the IT department has turned down in the past</strong> because of their perceived complexity and impact: network partitioning, upgrading operating system versions, Active Directory tiering, multi-factor authentication, etc.</p>
<p style="text-align: justify;">If these projects are necessary to reinforce a level of security, it is advisable <strong>to avoid making too many changes</strong> during the crisis period. Thus, the teams can concentrate on actions that are necessary to restart within a controlled level of security.</p>
<p style="text-align: justify;">For example, partitioning the network requires a review of the addressing plan, the addition of network equipment, and the modification of configurations. These actions often cause additional problems to be dealt with (IP hardcoded in the application, blocking of flows necessary for the proper functioning of the application, etc.).</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">#7 Waiting until investigations are complete</h1>
<p style="text-align: justify;">Investigations are essential to understand the attacker&#8217;s techniques and identify the vulnerabilities they exploited to carry out the attack. These <strong>vulnerabilities can be corrected during the reconstruction</strong> to avoid a new attack. However, investigations are complex and time-consuming (sometimes several weeks).</p>
<p style="text-align: justify;">A standard mistake is to wait until the end of the investigation to launch the reconstruction. In reality, it is essential to start the reconstruction operations before the end of investigations. According to the conclusions from the investigative teams, the plan for <strong>secure reconstruction</strong> will be regularly revised.</p>
<p style="text-align: justify;">In many instances, it will not be possible to identify <strong>patient zero</strong> or reconstruct the <strong>attack&#8217;s chronology</strong>. Indeed, the traces (log) maintained by the information system are not always precise (verbosity) or it does not permit going back far enough (retention time). They have sometimes been deleted by the attacker itself, while erasing his traces.</p>
<p style="text-align: justify;">Finally, decision-makers frequently ask whether the <strong>data has been exfiltrated</strong> from an information system. It should be emphasised that unless the organisation has advanced security systems, it is rarely possible to respond precisely to this issue (DLP, for example).</p>
<p> </p>
<h1 style="text-align: justify;">#8 Not anticipating human resource management</h1>
<p style="text-align: justify;">Cyber crises are situations <strong>where employees are intensely mobilized</strong>. Some members of the teams can be so determined to settle this matter, that they do not wish to quit at all! Concurrently, it is quite common to see cases of burnout, hospitalization, or sick leave during a poorly managed crisis.</p>
<p style="text-align: justify;">In the case of a large-scale ransomware attack, <strong>intensive team mobilisation will take at least three weeks</strong>. It is essential to organise <strong>team rotations</strong> from the start of the crisis ensuring that key resources are maintained over time.</p>
<p style="text-align: justify;"><img decoding="async" class="aligncenter wp-image-19330 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN.png" alt="" width="2722" height="1507" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN.png 2722w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN-345x191.png 345w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN-768x425.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN-1536x850.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Image2EN-2048x1134.png 2048w" sizes="(max-width: 2722px) 100vw, 2722px" /></p>
<p style="text-align: justify;">It is often appropriate to call on <strong>external service providers</strong> for expertise (digital investigations, Active Directory reconstruction, backup systems, etc.) to multiply efforts (reinstallation of workstations, upgrading of operating system versions, coordination of tasks, etc.).</p>
<p> </p>
<h1 style="text-align: justify;">#9 Hiding the situation from employees, partners, customers</h1>
<p style="text-align: justify;">More than five years ago, companies that suffered a cyberattack but failed to take adequate precautions had their reputations severely harmed. Due to the rise in cyber-attacks, an increasing number of organisations are falling victim to cyber-attacks, and firms will be evaluated not just on their <strong>ability to manage a crisis</strong>, but also on their status as victims.</p>
<p style="text-align: justify;">One of the first reflexes of management teams is often not communicating with stakeholders (employees, partners, and customers) in the hope that the <strong>attack will go unnoticed</strong>. It is clear that a major attack will always end up being communicated. In these situations, social networks and the media will communicate before the victim, who will then have to adopt a defensive posture in response. It is recommended to adopt a <strong>posture of transparency</strong> with the stakeholders, who will be reassured to know that the situation is under control. </p>
<p style="text-align: justify;">Finally, there must be <strong>appropriate communication</strong> between <strong>partners</strong>. Without specific information, many of the attackers tend to cut all the links with the victim, and thus the reopening could be longer and more complex. Moreover, s will be inclined to reopen if the victim has proactively warned them.</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">#10 Failing to structure crisis management</h1>
<p style="text-align: justify;">Since ransomware attacks have a significant impact on information systems, they <strong>inevitably cause chaos within an organization</strong>. Thus, no longer we can rely on the current communication and decision-making procedures.</p>
<p style="text-align: justify;">Some people think that a crisis situation allows <strong>approximate management</strong>: improvised meetings, follow-up of perfectible actions, lack of formalisation, etc. On the contrary, decisions must be precise, rapid, formalised, and communicated to all stakeholders involved. This discipline is the key to successful crisis management, where everyone finds their place and is utilised wisely.</p>
<p style="text-align: justify;">In certain large-scale crises, such as those involving international groups, keeping a PMO crisis unit for several dozen individuals is advantageous. It will be their responsibility for consolidating precise inventory, organising crisis committees, communicating, and following up on the decisions taken by the crisis unit. This unit of crisis management professionals is an indispensable asset for effective crisis management.</p>
<p style="text-align: justify;">A ransomware attack is a <strong>sudden event</strong> that has a very <strong>significant impact</strong> on the business&#8217;s operations. There are various <strong>pitfalls to avoid</strong> in crisis management to quickly regain a functional situation. To optimise operations and gain valuable feedback, it is strongly advised to <strong>surround yourself with cyber crisis management professionals</strong>.</p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/">Successful Ransomware Crisis Management: Top 10 pitfalls to avoid</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/01/successful-ransomware-crisis-management-top-10-pitfalls-to-avoid/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CDT Watch – September 2022</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/09/cdt-watch-september-2022/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/09/cdt-watch-september-2022/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Fri, 30 Sep 2022 15:02:56 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[maui]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=18819</guid>

					<description><![CDATA[<p>FOCUS TECH MAUI Sources: https://www.cisa.gov/uscert/ncas/alerts/aa22-187a https://stairwell.com/wp-content/uploads/2022/07/Stairwell-Threat-Report-Maui-Ransomware.pdf https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/   Ransomware Activity Presentation of the figures collected by our tool on the data given by the RaaS platforms about their successful attacks. This graph gives an estimation of the number of victims...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/09/cdt-watch-september-2022/">CDT Watch – September 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">MAUI</h2>
<p><img loading="lazy" decoding="async" class=" wp-image-18821 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1-277x191.png" alt="" width="579" height="399" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1-277x191.png 277w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1-57x39.png 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1-768x530.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1-1536x1060.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/1-1.png 1600w" sizes="auto, (max-width: 579px) 100vw, 579px" /></p>
<h6 style="text-align: left;">Sources:</h6>
<p><a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-187a">https://www.cisa.gov/uscert/ncas/alerts/aa22-187a</a></p>
<p><a href="https://stairwell.com/wp-content/uploads/2022/07/Stairwell-Threat-Report-Maui-Ransomware.pdf">https://stairwell.com/wp-content/uploads/2022/07/Stairwell-Threat-Report-Maui-Ransomware.pdf</a></p>
<p><a href="https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/">https://securelist.com/andariel-deploys-dtrack-and-maui-ransomware/107063/</a></p>
<h1> </h1>
<h1 style="text-align: center;"><strong>Ransomware Activity</strong></h1>
<p>Presentation of the figures collected by our tool on the data given by the RaaS platforms about their successful attacks. This graph gives an estimation of the number of victims by the most active RaaS groups, by month.</p>
<p><strong>Number of announced victims by the most active Ransomware-as-a-Service (RaaS) for the past 10 months:</strong></p>
<p><img loading="lazy" decoding="async" class=" wp-image-18827 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1-435x191.png" alt="" width="663" height="291" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1-435x191.png 435w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1-768x338.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1-1536x675.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/4-1.png 1920w" sizes="auto, (max-width: 663px) 100vw, 663px" /></p>
<p><strong>Noticeable change: </strong></p>
<ul>
<li>Lockbit2.0 disappears to make room for Lockbit3.0</li>
<li>Conti’s number of victims is dropping after May 2022. It does not mean that the individuals stopped their activities since the organization could have been divided into several groups after the events related to the Russian situation in April 2022 and come back under other names.</li>
<li>The activity has decreased during the summer of 2022, except for Lockbit 3.0.</li>
</ul>
<p><strong>   Number of announced victims by the 15 most active RaaS groups for the past 10 months:</strong></p>
<p><img loading="lazy" decoding="async" class=" wp-image-18829 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1-324x191.png" alt="" width="576" height="340" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1-324x191.png 324w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1-768x453.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/5-1.png 957w" sizes="auto, (max-width: 576px) 100vw, 576px" /></p>
<p>It must be taken into account that the data is based on the RaaS declaration of victims, the graphs are therefore an estimation of the reality.</p>
<p> </p>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<p><img loading="lazy" decoding="async" class=" wp-image-18823 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1-330x191.png" alt="" width="637" height="369" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1-330x191.png 330w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1-67x39.png 67w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1-768x444.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/2-1.png 1488w" sizes="auto, (max-width: 637px) 100vw, 637px" /></p>
<p> </p>
<p> </p>
<h1 style="text-align: center;"><strong>VULNERABILITY OF THE MONTH</strong></h1>
<h2 style="text-align: center;">Sophos Firewall</h2>
<h6 style="text-align: center;"><img loading="lazy" decoding="async" class=" wp-image-18825 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/3-1-288x191.png" alt="" width="557" height="370" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/3-1-288x191.png 288w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/3-1-59x39.png 59w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/3-1-768x509.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/09/3-1.png 1524w" sizes="auto, (max-width: 557px) 100vw, 557px" /></h6>
<p> </p>
<p style="text-align: center;">SEE YOU NEXT MONTH!!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/09/cdt-watch-september-2022/">CDT Watch – September 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/09/cdt-watch-september-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Ransomware: Inside the former CONTI group</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/07/ransomware-inside-the-former-conti-group/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/07/ransomware-inside-the-former-conti-group/#respond</comments>
		
		<dc:creator><![CDATA[Laurenne-Sya Luce]]></dc:creator>
		<pubDate>Fri, 01 Jul 2022 15:30:00 +0000</pubDate>
				<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[CONTI]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybercriminality]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=18223</guid>

					<description><![CDATA[<p>We recently learned from AdvIntel researcher Yelisey Boguslavskiy that the Russian group Conti shut down its operation, thereby making the brand obsolete.[1] This announcement comes only a few months after it was the center of attention of the specialized press...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/07/ransomware-inside-the-former-conti-group/">Ransomware: Inside the former CONTI group</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">We recently learned from AdvIntel researcher Yelisey Boguslavskiy that the Russian group Conti shut down its operation, thereby making the brand obsolete.<a href="#_ftn1"><sup>[1] </sup></a>This announcement comes only a few months after it was the center of attention of the specialized press following the &#8220;<strong>Conti Leaks</strong>&#8220;.</p>
<p style="text-align: justify;">Last February, a Ukrainian researcher released more than 60,000 messages from inside conversations between different members of the group. Through these discussions, several revelations are made about their operations, allowing us to understand the RaaS ecosystem (<em>Ransomware-as-a-Service)</em>.</p>
<p style="text-align: justify;">Through this article, let&#8217;s take a look at how a Ransomware platform operates, then let&#8217;s question the organizational structure and the benefits generated by former CONTI group.</p>
<h1> </h1>
<h1 style="text-align: justify;"><strong>Ransomware platform ecosystem</strong></h1>
<p style="text-align: justify;">The proliferation of articles on the Ransomware threat over the last few years gives the impression that the sector is flourishing. There are <strong>several players involved</strong>, and data theft amounts to <strong>hundreds of millions of dollars</strong> per year. For instance, CERT-Wavestone shared that <a href="https://www.riskinsight-wavestone.com/en/2021/10/cyberattacks-in-2021-ransomwares-still-threat-n1/">about 60% of its incident responses in 2021 were for ransomware attacks</a>.<a href="#_ftn2"><sup>[2]</sup></a></p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-18227 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN1.jpg" alt="" width="605" height="419" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN1.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN1-276x191.jpg 276w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN1-56x39.jpg 56w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<p style="text-align: justify;">As described in the figure, ransomware platforms <strong>do not work alone</strong>. It receives help from different <strong>service providers</strong> or other platforms and offers its services (in the form of ransomware) to different groups of attackers. Finally, the platform can also directly extract data from its victims: individuals, companies, states&#8230;</p>
<p style="text-align: justify;">These platforms have fueled the growth of a RaaS economy. <strong>Approximately $5.2 billion of BTC transactions</strong> have been identified by the US Treasury with the <strong>payment</strong> of the most commonly reported <strong>ransomware platforms</strong>.<a href="#_ftn3"><sup>[3]</sup></a> This makes it a <strong>highly profitable business</strong>.</p>
<p style="text-align: justify;">At the same time, it is also an activity where there is a <strong>significant number of established groups</strong> of players that seem to frequently appear and disappear and which generally last several months. Behind these multiple platforms usually hide the same individuals. If the CONTI franchise, supposed successor of the Ryuk<a href="#_ftn4"><sup>[4]</sup></a>,has only survived 2 years, its former members still seem to be active.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-18229 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN2.jpg" alt="" width="605" height="419" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN2.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN2-276x191.jpg 276w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN2-56x39.jpg 56w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<p style="text-align: justify;">In this fragmented and complex environment, it is difficult to retrieve consistent information on the functioning of the platforms. The internal discord that followed the war in Ukraine and the publication of the Conti Leaks allowed us to investigate the functioning of this secretive group before its dissolution.</p>
<h1> </h1>
<h1 style="text-align: justify;"><strong>Conti enterprise ?</strong></h1>
<p style="text-align: justify;">On February 27th, 2022 we discover the underside of CONTI organization. The disclosures are made within a few days and soon reveal :</p>
<ul style="text-align: justify;">
<li><strong>Well-established recruitment processes</strong>, that can even go as far as advertising on legitimate recruitment sites</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18231 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN3.jpg" alt="" width="605" height="419" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN3.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN3-276x191.jpg 276w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN3-56x39.jpg 56w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<ul style="text-align: justify;">
<li><strong>A vertical organization </strong>with its own HR, financial and operational departments</li>
</ul>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-18233 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN4.jpg" alt="" width="605" height="419" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN4.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN4-276x191.jpg 276w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN4-56x39.jpg 56w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<ul style="text-align: justify;">
<li>A <strong>salary policy</strong> established according to the different functions in the organization, including bonuses per position after a successful ransom (See. <a href="/wp-content/uploads/2022/06/Note-de-synthese-groupes-de-ransomware-ANG.pdf">Full study</a>)</li>
</ul>
<p style="text-align: justify;">This thoughtful and efficient organization seems to be one of the secrets to the profitability of the group.</p>
<h1> </h1>
<h1 style="text-align: justify;"><strong>A highly profitable business model</strong></h1>
<p style="text-align: justify;">We have endeavored to recreate the cash flow statement of CONTI from scratch.</p>
<p style="text-align: justify;">Each line of profit and cost is researched to be estimated as accurately as possible over a year.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter wp-image-18235 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN5.jpg" alt="" width="605" height="417" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN5.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN5-277x191.jpg 277w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/EN5-57x39.jpg 57w" sizes="auto, (max-width: 605px) 100vw, 605px" /></p>
<p style="text-align: justify;">According to The 2022 Crypto Crime Report<a href="#_ftn5"><sup>[5]</sup></a>, in 2021, CONTI and its affiliates held at least <strong>$180M in bitcoins</strong> for ransom from <strong>addresses traceable </strong>on the blockchain. It is estimated that <strong>70% is paid back to its affiliates</strong>, and the remaining $45M is the group&#8217;s revenue.</p>
<p style="text-align: justify;">CONTI then has to deal with traditional expenses, which are common in traditional companies. The main ones are: <strong>money laundering</strong>, which represents up to 50% of the earnings, purchases of <strong>third party services and maintenance costs</strong>, and finally.</p>
<p style="text-align: justify;">CONTI would therefore generate <strong>a net profit of $16M</strong> (if we assume that the group does not pay Russian taxes). The <strong>ROI</strong> of the group is estimated at about <strong>+163%</strong>, according to the same information.</p>
<h1> </h1>
<h1 style="text-align: justify;"><strong>Conclusion</strong></h1>
<p style="text-align: justify;">The Conti Leaks enabled to better understand the organization and ecosystem of Ransomware-as-a-Service platforms through the study of a group. This work thus provides a solid foundation for the popularization of the RaaS threat.</p>
<p style="text-align: justify;"><strong><img loading="lazy" decoding="async" class="aligncenter wp-image-18261 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-scaled.jpg" alt="" width="2560" height="1441" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-scaled.jpg 2560w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-339x191.jpg 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-69x39.jpg 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-768x432.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-1536x865.jpg 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-2048x1153.jpg 2048w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/07/info-EN-800x450.jpg 800w" sizes="auto, (max-width: 2560px) 100vw, 2560px" /> </strong></p>
<p> </p>
<h3 style="text-align: justify;"><strong>About our method</strong></h3>
<p style="text-align: justify;">All of the information presented in this study comes from Wavestone&#8217;s field observations as well as multiple sources &#8211; both public and private such as: the National Cyber Security Center, Check Point Research, Palo Alto Networks, Breachquest and Chainalysis.</p>
<p> </p>
<h3 style="text-align: justify;">Sources :</h3>
<p style="text-align: justify;"><a href="#_ftnref1">[1]</a> « Conti ransomware shuts down operation, rebrands into smaller units », Bleeping Computer, May 2022</p>
<p style="text-align: justify;"><a href="https://www.bleepingcomputer.com/news/security/conti-ransomware-shuts-down-operation-rebrands-into-smaller-units/">Conti ransomware shuts down operation, rebrands into smaller units (bleepingcomputer.com)</a></p>
<p style="text-align: justify;"><a href="#_ftnref2">[2]</a> « Cyberattacks in 2021: ransomwares, still threat n°1 », Risk Insight, October 2021</p>
<p style="text-align: justify;"><a href="https://www.riskinsight-wavestone.com/en/2021/10/cyberattacks-in-2021-ransomwares-still-threat-n1/">https://www.riskinsight-wavestone.com/2021/10/cyberattaques-en-france-le-ransomware-menace-numero-1/</a> </p>
<p style="text-align: justify;"><a href="#_ftnref3">[3]</a> « US links $5.2 billion worth of Bitcoin transactions to ransomware », Bleeping Computer, October 2021</p>
<p style="text-align: justify;"><a href="https://www.bleepingcomputer.com/news/security/us-links-52-billion-worth-of-bitcoin-transactions-to-ransomware/">https://www.bleepingcomputer.com/news/security/us-links-52-billion-worth-of-bitcoin-transactions-to-ransomware/</a></p>
<p style="text-align: justify;"><a href="#_ftnref4">[4]</a> « Le rançongiciel Ryuk », ANSSI, September 2021</p>
<p style="text-align: justify;"><a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2020-CTI-011.pdf">CERTFR-2020-CTI-011.pdf (ssi.gouv.fr)</a></p>
<p style="text-align: justify;"><a href="#_ftnref5">[5]</a> « THE 2022 CRYPTO CRIME REPORT », Chainalysis, Février 2022</p>
<p style="text-align: justify;"><a href="https://go.chainalysis.com/rs/503-FAP-074/images/Crypto-Crime-Report-2022.pdf">Crypto-Crime-Report-2022.pdf (chainalysis.com)</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/07/ransomware-inside-the-former-conti-group/">Ransomware: Inside the former CONTI group</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/07/ransomware-inside-the-former-conti-group/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CDT Watch &#8211; December 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/12/cdt-watch-december-2021/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2021/12/cdt-watch-december-2021/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Thu, 30 Dec 2021 16:46:00 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CDT]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[log4shell]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=17506</guid>

					<description><![CDATA[<p>THE ROLE OF DECRYPTION TOOL AGAINST THE RANSOMWARE THREAT The ransomware threat is increasing continuously and is now considered a national threat for countries, such as the US, France, or the UK.  Last summer, the Virtual System Administrator (VSA) edited...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/12/cdt-watch-december-2021/">CDT Watch &#8211; December 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 style="text-align: center;"><strong>THE ROLE OF DECRYPTION TOOL AGAINST THE RANSOMWARE THREAT</strong></h2>
<table>
<tbody>
<tr>
<td width="627">
<p>The ransomware threat is increasing continuously and is <a href="https://searchsecurity.techtarget.com/news/252507290/Ransomware-Has-the-US-reached-a-tipping-point">now considered a national threat for countries</a>, such as the <a href="https://www.europol.europa.eu/newsroom/news/13-countries-join-global-fight-against-ransomware-0">US, France, or the UK.</a> </p>
<p>Last summer, the Virtual System Administrator (VSA) edited by KASEYA in the US has been exploited by REvil, impacting the company and many of its international clients. In this case, <a href="https://www.washingtonpost.com/national-security/ransomware-fbi-revil-decryption-key/2021/09/21/4a9417d0-f15f-11eb-a452-4da5fe48582d_story.html">the FBI kept secret the decryption key for three weeks from the victims,</a> in order to protect their operation against REvil.  </p>
<p> </p>
<p><strong>What’s the purpose of a decryption tool? </strong></p>
<p>As the name suggests, decryption tools are designed to decrypt encrypted data. Often based on previous ransomware analysis, those tools use decryption keys like a password to access blocked data. Today many decryption tools are proposed online, <a href="https://www.nomoreransom.org/fr/decryption-tools.html">sometimes even for free, providing a quick solution in case of known ransomware</a>.</p>
<p>Let’s consider a company ransomed. Following the criticality of the encrypted data, the company will have to choose between paying the ransom or, in case they are prepared, launching their recovery plan. This will imply rebuilding their infrastructure based on previous saves if they are still accessible which is never a trivial assumption. Paying the ransom represents an even less reliable solution to recover a safe and complete information system.</p>
<p>The decryption tool could be an alternative option to recover the data, with advantages such as being a widely available, affordable, and quick solution. The No More Ransom project launched by the National High Tech Crime Unit of the Netherlands&#8217; police, Europol&#8217;s European Cybercrime Centre, Kaspersky, and McAfee now make available 121 free ransomware decryption tools that can decrypt 151 ransomware families. <a href="https://blog.barracuda.com/2021/10/05/decryption-tool-controversy-erupts/">More than six million ransomware victims have used those tools to recover encrypted files.</a></p>
<p>However, a decryption tool can be developed only for the ransomware containing vulnerabilities. If a ransomware is 100% correctly coded, there is no vulnerability to exploit and no decryption key to be developed. Therefore, the decryption tool is a solution only for a certain type of ransomware. </p>
<p>Moreover, this option is safe only when proposed by a reliable editor. Many fake decryption tools used as scamming vectors are proposed for free online. Besides, the ransomware being in constant evolution, the decryption tools have to follow the updates to not be rapidly irrelevant.</p>
<p> </p>
<p><strong>The controversy of the decryption tools publication </strong></p>
<p>Decryption keys can be seen as ransomware vulnerabilities. In the same way that vulnerabilities are patched when discovered, when a decryption key is found, criminals patch their ransomware to make it more effective. The decryption key becomes irrelevant for the next victims. </p>
<p>Months before the Colonial Pipelines attacks, two searchers had found a decryption key to help DarkSide victims to recover and chose to not share it. But BitDefender discovered the key as well and published it online, alerting the victims, as well as the attackers. The day after this publication, DarkSide publicly informed they have corrected the problem and <a href="https://www.technologyreview.com/2021/05/24/1025195/colonial-pipeline-ransomware-bitdefender/">even address its “Special thanks to BitDefender for helping fix our issues. This will make us even better</a>”. </p>
<p>This is not an isolated case. Earlier this year, a Spanish searcher found and developed a decryption tool for the Avaddon ransomware. He published it online on GitHub with an explanation about how to use its tool. As in the case of DarkSide, <a href="https://www.lemondeinformatique.fr/actualites/lire-quand-la-publication-d-un-decrypteur-renforce-le-ransomware-avaddon-81965.html">this information was shared publicly, available for the victims as well as the ransomware developers, who corrected the vulnerabilities.</a> </p>
<p>In the KASEYA case, this decryption key was kept by the FIB because its publication would hinder an offensive cyber operation against the REvil gang. This implied letting victims such as schools and hospitals deal with the problem without sharing with them a solution, in order to reach the attackers. The operation didn&#8217;t happen immediately, as, in the same month, websites run by the REvil ransomware gang suddenly became inaccessible. </p>
<p>BreachQuest CTO Jake Williams called the situation a classic case of an intelligence gain/loss assessment. He pointed out that the direct financial damage was almost certainly larger than the FBI believed, but <a href="https://www.zdnet.com/article/fbi-decision-to-withhold-kaseya-ransomware-decryption-keys-stirs-debate/">“on the other hand, releasing the key solves an immediate need without addressing the larger issue of disrupting future ransomware operations</a>”. </p>
<p> </p>
<p><strong>Decryption tools: a partial solution</strong></p>
<p>Outside of the debate on the necessity to publish them, the crisis management interventions of the W-CERT pointed out that, even if helpful, the decryption tools are not the ultimate and perfect solution in a ransomware attack. </p>
<p>Indeed, decryption tools are only usable for a limited subset of existing ransomware, where encryption mechanisms were not created using state-of-the-art security. Even if the related ransomware attack falls under this case, which would mean the affected data will be able to get recovered safely, the attacked company still has to tackle the biggest issue of such an attack, meaning rebuilding at the very least the core of the information system that got compromised. Relying on decryption tools only to face the ransomware threat is far from being a complete and reliable solution.</p>
</td>
</tr>
</tbody>
</table>
<figure id="post-16217 media-16217" class="align-center">
<p style="text-align: center;"> </p>
</figure>
<figure id="post-16210 media-16210" class="align-center">
<figure id="post-16367 media-16367" class="align-center"></figure>
</figure>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<figure id="post-16221 media-16221" class="align-center">
<figure id="post-16228 media-16228" class="align-center">
<figure id="post-16369 media-16369" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17508" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-respond.jpg" alt="" width="783" height="486" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-respond.jpg 783w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-respond-308x191.jpg 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-respond-63x39.jpg 63w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-respond-768x477.jpg 768w" sizes="auto, (max-width: 783px) 100vw, 783px" /></figure>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17510" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first.jpg" alt="" width="783" height="425" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first.jpg 783w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-352x191.jpg 352w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-71x39.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/first-768x417.jpg 768w" sizes="auto, (max-width: 783px) 100vw, 783px" /></p>
<p style="text-align: center;">For more information for vulnerability detection and remediation, contact Wavestone CERT-W!</p>
</figure>
</figure>
<p> </p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">To learn more about the evolution of cybercrime, we recommend reading the <em>Internet Organized Crime Threat Assessment 2021</em> of Europol. This report focuses on changes and developments of cybercrime threats during the last 12 months.</p>
<figure id="post-16219 media-16219" class="align-center">
<figure id="post-16387 media-16387" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-17512 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/lock.jpg" alt="" width="325" height="152" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/lock.jpg 325w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/01/lock-71x33.jpg 71w" sizes="auto, (max-width: 325px) 100vw, 325px" /></figure>
<p style="text-align: center;"><a href="https://www.europol.europa.eu/cms/sites/default/files/documents/internet_organised_crime_threat_assessment_iocta_2021.pdf">Internet Organized Crime Threat Assessment 2021, Europol</a></p>
</figure>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/12/cdt-watch-december-2021/">CDT Watch &#8211; December 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2021/12/cdt-watch-december-2021/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber resilience in an industrial environment</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/03/cyber-resilience-in-an-industrial-environment/</link>
		
		<dc:creator><![CDATA[Alexandrine Torrents]]></dc:creator>
		<pubDate>Mon, 15 Mar 2021 10:30:33 +0000</pubDate>
				<category><![CDATA[Focus]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[cyber resilience]]></category>
		<category><![CDATA[industrial IS]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Operational Resilience]]></category>
		<category><![CDATA[OT]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[Reconstruction]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15352</guid>

					<description><![CDATA[<p>For the most impatient readers, you can go directly to the Key Elements at the end of the article. Reminder of the state of the threat ANSSI states in ÉTAT DE LA MENACE RANÇONGICIEL &#8211; À L&#8217;ENCONTRE DES ENTREPRISES ET...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/03/cyber-resilience-in-an-industrial-environment/">Cyber resilience in an industrial environment</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">For the most impatient readers, you can go directly to the <a href="#key">Key Elements</a> at the end of the article.</p>
<h3 style="text-align: justify;">Reminder of the state of the threat</h3>
<p style="text-align: justify;">ANSSI states in <em>ÉTAT DE LA MENACE RANÇONGICIEL &#8211; À L&#8217;ENCONTRE DES ENTREPRISES ET INSTITUTIONS<a href="#_ftn1" name="_ftnref1">[1] </a></em><a href="#_ftnref1" name="_ftn1"></a>published on 05/02/2020: «  Since 2018, ANSSI and its partners have observed that more and more cybercriminal groups with significant financial resources and technical skills favour the targeting of particular companies and institutions in their ransomware attacks. ».</p>
<p style="text-align: justify;">Faced with this observation, it is more necessary than ever to secure information systems. This involves applying the fundamentals of security: applying patches, managing accounts and passwords, managing network segmentation etc. As a reminder, the application of these initial measures permits a significant reduction in the probability that an information system will be subject to a ransomware but can in no way guarantee that this will not happen.</p>
<h3 style="text-align: justify;">Specificity of the industrial sector</h3>
<p style="text-align: justify;">However, even though new defensive solutions are continually being developed, the cost and complexity of deploying some of them ultimately make them little used. This is truer in an industrial environment, where their integration can be complex, as some systems are fixed in a functional configuration. Moreover, the budgets allocated to IT security in an industrial environment, although increasing in recent years, are still not sufficient for many sites.</p>
<p style="text-align: justify;">Furthermore, an industrial information system shares a common base with a conventional information system and is therefore subject to the same attacks. Of course, attacks such as Stuxnet, Triton, or BlackEnergy (on a smaller scale) require additional skills. However, it is always worth remembering that the targets of interest for groups possessing this type of means are generally already subject to regulatory obligations (LPM in France, NIS directive etc.), which if respected, greatly limit the risks of a successful attack against them. However, these systems are not invulnerable, and must therefore also be prepared to respond to an attack.</p>
<h3 style="text-align: justify;">Inevitable attack on industrial systems: how to minimise the impact and restart operations quickly?</h3>
<p style="text-align: justify;">It therefore appears that:</p>
<ul style="text-align: justify;">
<li>Protecting oneself from the threat is often limited to the application of basic security measures if there is no regulatory obligation applicable to the target information system;</li>
<li>Identifying the sources of threat and detecting an attack before it reaches its objective requires in most cases resources that are too important in relation to the budgets of current industrial information systems.</li>
</ul>
<p style="text-align: justify;">If the probability of an information system undergoing a successful cyber-attack, and more specifically a ransomware, is almost certain, the following question arises: &#8220;How can we prepare for a major cyber-attack, maintain critical activities in a degraded mode, while rapidly regaining confidence in the industrial information system? ».</p>
<p style="text-align: justify;">The answer to this question is covered by the last two pillars of computer security according to the NIST framework: respond and recover. An attempt to answer this question is presented in this article.</p>
<p style="text-align: justify;">Note: the first part of this article &#8220;How to respond to an attack before it is too late?&#8221; is not necessary to implement the recommendations detailed in the second part &#8220;How to recover after an attack if it could not be contained? ». Although the implementation of network filtering measures is highly recommended, it may be interesting for sites where the implementation of such filtering measures takes too long to implement, to start with the preparation part of the remediation of a cyber-attack, which is easier to implement.</p>
<h2 style="text-align: justify;">How to respond to an attack before it is too late?</h2>
<h3 style="text-align: justify;">Involving industrial teams</h3>
<p style="text-align: justify;">Before talking about the measures that can be put in place to respond to a digital security incident, it may be interesting to remember that industrial staff are used to crisis management.</p>
<p style="text-align: justify;">Indeed, many industries regularly organise crisis management exercises (fire, chemical risk, natural disasters, etc.). On many sensitive sites, procedures are therefore already available to respond to this type of incident, under the direction of a dedicated manager. In addition, autonomous physical protection is generally available: pressure relief valve, non-return valve, sprinkler etc., although these are sometimes replaced by connected instrumented safety systems.</p>
<p style="text-align: justify;">The context is therefore appropriate for adding a new procedure in order to respond to a computer attack. This will generally consist of isolating the industrial information system from the outside via a procedure known as the &#8220;red button&#8221;. In order to draw up the associated procedure, the involvement of site personnel will be essential, particularly to ensure that the application is not more harmful than the attack itself.</p>
<h3 style="text-align: justify;">A prerequisite for the implementation of the isolation posture: the control of its flows and the implementation of network partitioning/filtering.</h3>
<p style="text-align: justify;">It is necessary to measure the impacts generated using the &#8220;red button&#8221;. To do this, it is necessary to list the interconnections of the industrial site with other systems.</p>
<p style="text-align: justify;"><strong>List the interconnections with other information systems.</strong></p>
<p style="text-align: justify;">It may be interesting to start by listing the flows between the industrial information system and the outside. First of all, it is necessary to define what this system contains. In a basic case, it includes the PLCs, the supervision, as well as the equipment necessary for the interconnection of the first two.</p>
<p style="text-align: justify;">Other equipment can then be added: an Historian server, client stations for supervision, a NAS, etc. This network, later called an industrial network, is generally connected with other networks in order to share information with the equipment of the latter.</p>
<p style="text-align: justify;">It is possible to mention:</p>
<ul>
<li style="text-align: justify;">Exchanges with the company&#8217;s ERP (whether an MES &#8211; Manufacturing Execution System is present or not), generally located on the office network;</li>
<li style="text-align: justify;">Exchanges with partners: regulation of electricity, water and gas networks, etc.;</li>
<li style="text-align: justify;">Exchanges with service providers: weather, cloud solutions for energy optimisation, predictive maintenance, etc.</li>
</ul>
<p style="text-align: justify;">These flows, although useful to simplify operations, can generally be temporarily cut off or replaced by alternative means (telephone call to indicate production levels for example).</p>
<p style="text-align: justify;">Moreover, each industrial site is different, and therefore manages these interconnections differently. It is common to see MPLS networks dedicated to industrial sites when the company owns several of them. In other cases, the office network will be used to federate them. It is also true for the connection needs between these industrial networks and the Internet, which sometimes pass first through the office network, or benefit from a direct output.</p>
<p style="text-align: justify;"><strong>List its internal flows</strong></p>
<p style="text-align: justify;">After listing the interconnections between the industrial network and the outside, the internal flows remain to be listed. Most of these flows should be strictly necessary for the proper functioning of the industrial process, such as those between supervision and PLCs. Cutting off these connections would therefore require stopping the industrial process, or at least making it safe.</p>
<p style="text-align: justify;">It may then be interesting to separate the equipment and associated flows into several zones:</p>
<ul>
<li style="text-align: justify;">Supervision;</li>
<li style="text-align: justify;">Field network;</li>
<li style="text-align: justify;">Others (supervision client stations, historian server, etc.).</li>
</ul>
<p style="text-align: justify;">Setting up these zones allows the exposure of these components to be drastically reduced. Indeed, only the supervision should have access to the field networks, while the &#8220;Others&#8221; category should only have access to the supervision.</p>
<p style="text-align: justify;">Other zones may be necessary to implement such as:</p>
<ul style="text-align: justify;">
<li>An administration zone: which could also be used to program the PLCs according to the distribution of roles and responsibilities on site;</li>
<li>A DMZ: which can accommodate a relay server so that equipment outside the industrial site does not connect directly to the supervision system to retrieve production data, etc.</li>
</ul>
<p style="text-align: justify;">Depending on the services offered (WSUS server, antivirus server, Terminal Server for remote access etc.) other zones can of course be added.</p>
<p style="text-align: justify;"><strong>Evaluate the real need for these flows</strong></p>
<p style="text-align: justify;">After listing all these flows, it is interesting to identify the real need for each of them. For example, is it necessary to be able to access e-mails from a supervision server?</p>
<p style="text-align: justify;">In order to limit the exposure of the industrial network to the outside, it could also be necessary to take some equipment out of it. For example, if a database accessed from the office network is fed by the supervision, but not useful to it, hosting it directly on the office network may prove simpler than trying to limit access.</p>
<p style="text-align: justify;">Once the necessary flows have been clearly identified, the associated filtering rules must be configured in detail (source IP address, destination IP address, destination port). This work generally requires a significant human investment, mainly from the teams in charge of the industrial site, as well as a significant material cost to acquire security equipment. However, it is a prerequisite for setting up the fallback postures described below. In an ideal case, application filtering (level 7 of the OSI model) could also be implemented.</p>
<p style="text-align: justify;">This work, although essential to the implementation of isolation postures, is also one of the fundamental actions to be carried out within the framework of securing an information system (industrial or not). Indeed, each flow cut off is a flow that does not need to be monitored, as well as one that is less exploitable by an attacker.</p>
<h3>Preparing fallback postures</h3>
<p style="text-align: justify;">Complete isolation of all the equipment in an industrial information system is not always desirable, even in the event of an attack. After having listed these flows, it may be interesting not to set up a single isolation posture, but several fallback postures, allowing in some cases to continue working almost normally.</p>
<p style="text-align: justify;"><strong>Preventive fallback posture: isolate the plant in the event of an attack on an external network</strong></p>
<p style="text-align: justify;">After identifying the flows between the industrial network and the outside, it is possible to create an associated fallback posture in order to deactivate them if necessary. The objective of this posture is to cut all interconnections of the industrial network with the outside in order to prevent any propagation of an attack. A proven solution is to group these flows on a few dedicated Ethernet ports. Thus, it is sufficient to indicate in the associated procedures to disconnect the associated cables to activate the fallback posture. This also avoids having to intervene on the configuration of firewalls in the event of a cyber security incident.</p>
<p style="text-align: justify;">In addition, it is also necessary to define the cases in which this posture should be activated. If it can be activated without posing any problem to production, or adding too much work to the site staff, the question may arise as to whether these flows are necessary.</p>
<p style="text-align: justify;">If this posture does have an impact on the site&#8217;s industrial activities, a good balance must be found between triggering it too early (as soon as the antivirus software on an office workstation raises an alert), or too late (after the first industrial workstations have been encrypted). This will also depend on the context of the company and its resources (dedicated or non-dedicated security monitoring team, etc.).</p>
<p style="text-align: justify;"><strong>Specificity (distributed sites, non-autonomous sites, etc.)</strong></p>
<p style="text-align: justify;">If all flows with the outside do not have the same destination, it may also be interesting to define several specific fallback positions. Indeed, if the service provider in charge of managing the site&#8217;s cameras warns that he is undergoing a ransomware attack, it seems more optimal to disconnect only the flows between this service provider and the factory network, rather than all the flows, including those to the ERP.</p>
<p style="text-align: justify;">In the case where the industrial process is distributed over several sites (production and distribution plant in particular), the activation of the preventive fallback posture should not cut off the flows between these different sites. Indeed, specific links should be dedicated to this. If this is not the case, use of the office network to ensure these connections, for example, a project to overhaul the industrial network is probably to be expected (deployment of a dedicated VRF, or a SDWAN network for example).</p>
<p style="text-align: justify;">Finally, it is always good to remember that each factory is different, so a local study will have to be carried out on each one to understand its specificities.</p>
<p style="text-align: justify;"><strong>Last resort fallback position: switch off the information system in the event of a proven attack on the plant</strong></p>
<p style="text-align: justify;">Finally, it may be interesting to prepare a last resort fallback posture. This should consist of isolating each VLAN (if defined, preferably with a local HMI per VLAN to ensure a degraded mode) or each piece of equipment (turn off the switches) in order to prevent the attacker from continuing his actions, which in the most advanced cases of attack, could directly target the site&#8217;s industrial process.</p>
<p style="text-align: justify;">The objective is then to secure the site or ensure its essential services. The activation of this posture implies working without an information system and should only be applied in the event of proven compromise of at least one piece of equipment on the site, since it leads to the same immediate result as a ransomware, if not worse.</p>
<p style="text-align: justify;">An upstream work with the operators will be necessary in order to list all the actions to be carried out when this posture is activated and to define degraded modes. Indeed, this will generally require the activation of on-call duty in order to manually perform certain tasks: checking the correct operation of equipment, especially on remote sites, use of local HMIs, etc. Moreover, some industrial processes are no longer manually controllable today, and will therefore have to be stopped since no degraded mode is available.</p>
<p style="text-align: justify;">In order to estimate the impacts of activating such a posture, it may be interesting to look at the impacts listed in the event of fire or a general power failure. Moreover, only a real test of this posture can ensure its operational impacts.</p>
<h2 style="text-align: justify;">How to recover after an attack if it has not been contained?</h2>
<p style="text-align: justify;">In some cases, the activation of fallback postures may not be sufficient to protect the entire industrial information system, especially if they are activated too late. It is then essential to be able to proceed with the reconstruction of all or part of the said system in a sufficiently short time to limit the associated impacts.</p>
<p style="text-align: justify;">The main prerequisites for restoring an industrial information system are listed below.</p>
<h3 style="text-align: justify;">What must be backed up to be able to restore its PLCs?</h3>
<p style="text-align: justify;">In order to be able to restart the factory, it is necessary in most cases to start restoring PLCs, which requires two main elements.</p>
<p style="text-align: justify;"><strong>Having an up-to-date copy of your PLC programs</strong></p>
<p style="text-align: justify;">PLCs are spared in most current attacks, probably because targeting Windows workstations is enough for attackers to achieve their intended objectives. However, attacks are likely to be increasingly targeted, and most PLCs currently in use are not secure (unencrypted and unauthenticated communications, default passwords, administration functionality that cannot be deactivated, etc.).</p>
<p style="text-align: justify;">It is therefore necessary to save these programs, which is already generally the case, particularly on the programming station (sometimes belonging to a service provider) used when the device is commissioned. It should be noted that these backups should be stored on at least one off-line medium, so that they are not encrypted in the same way as the workstation hosting them.</p>
<p style="text-align: justify;">These observations remain valid even for the new generations of PLCs, which, although benefiting from a level of security that is far superior to that of their predecessors, are not invulnerable.</p>
<p style="text-align: justify;"><strong>Save a means of downloading these programs to the PLCs</strong></p>
<p style="text-align: justify;">Many PLCs require dedicated software to be programmed. This is even the case if you just want to download an already written program. It is therefore advisable to have a copy of these programs.</p>
<p style="text-align: justify;">In some cases, a programming station disconnected from the network and reserved for this purpose can be a solution. It should be noted, however, that maintaining such a station in a safe condition can quickly become complex. If this solution is selected, this station could also host the copy of the PLC programs. Keeping a second backup set off-line (external hard disk for example) would however be an additional security measure.</p>
<p style="text-align: justify;">Furthermore, if new generations of PLCs are used, with the latest security features enabled, other elements should be backed up such as: PLC program passwords, certificates used for certain communications (or a means of regenerating them) etc.</p>
<p style="text-align: justify;">These prerequisites are also valid for network equipment (firewalls, switches etc.).</p>
<h3 style="text-align: justify;">What needs to be backed up to be able to restore essential computer hardware?</h3>
<p style="text-align: justify;"><strong>Identifying what is really needed</strong></p>
<p style="text-align: justify;">Restoring SCADA system, and associated client workstations, is generally equivalent to restoring a Windows system and associated programs. Several questions must be asked to identify the items to be backed up:</p>
<ul style="text-align: justify;">
<li>What equipment is needed? An engineering workstation, a SCADA server, a few operator workstations?</li>
<li>Is it possible to reinstall the SCADA system from scratch (new installations of Windows and the supervision software) and then deposit a backup of the SCADA configuration? Is this feasible in a sufficiently short time?</li>
<li>Would not a complete copy of the SCADA server disk be simpler? It would indeed be sufficient to insert the saved disk to reboot.</li>
<li>Are changes regularly made to the supervision software? If yes, is it necessary to back them all up? In this case, it seems complex to make a complete copy of the disk each time.</li>
</ul>
<p style="text-align: justify;"><strong>Backing up intelligently</strong></p>
<p style="text-align: justify;">In many cases, backups of Windows workstations are made in the same way as those of PLC programs, by copy/paste. It could then be interesting to look at automatic backup mechanisms. However, these are probably to be avoided for factories starting from scratch and not having enough budget to install them serenely. Indeed, implementing this type of solution in a secure manner is generally more complex than making a simple bit-by-bit copy of a hard disk.</p>
<h3 style="text-align: justify;">Do not neglect documentation and training</h3>
<p style="text-align: justify;">However, it is not enough to have complete backups available. It is also necessary to draw up detailed operating procedures for restoring these backups. Indeed, if a crisis were to occur, the stress of the teams and the potential unavailability of some of the knowledge could lead to handling errors in the absence of documentation.</p>
<p style="text-align: justify;">These procedures are not intended to enable a complete restoration of all systems, but at least to enable the essential elements previously identified to be restarted:</p>
<ul style="text-align: justify;">
<li>An engineering workstation with the associated PLC programming software;</li>
<li>A SCADA server;</li>
<li>Two to three operator workstations;</li>
<li>The plant&#8217;s essential PLCs.</li>
</ul>
<p style="text-align: justify;">In addition, it is generally recommended to have at least two sets of backups, one to be stored near the equipment concerned, the other to be stored on another physical site, with access limited to a limited number of people. It may be tempting to store an additional set of backups online, but it should be noted that in the event of a cyber-attack, and activation of fallback procedures, it is complex to download these backups and deposit them on the systems to be restored.</p>
<p style="text-align: justify;">Finally, it is essential to test all these procedures to ensure that they are exhaustive. A test could, for example, be the opportunity to realise that the backup of the SCADA configuration does not include the licence key, or that the passwords configured when the complete disk was copied have since been modified without keeping the history.</p>
<h2 style="text-align: justify;">Conclusion</h2>
<p style="text-align: justify;">Crisis management is an important component of the business for many industrial system operators. These same people are also the most experienced in their perimeter. However, they are generally not IT experts. Pragmatic measures, adapted to their context, will therefore be far more useful than a generic 200-page guide containing all the good practices to be applied to an information system.</p>
<p style="text-align: justify;">As in development with the KISS principle (<em>Keep it simple, stupid),</em> <strong>fallback postures, as well as restoration procedures, should be kept simple to understand, and stupid to apply.</strong></p>
<p style="text-align: justify;">Furthermore, although the application of a strict network filtering policy can only be advised, it is not strictly necessary for the implementation of backup and recovery actions. Thus, even if the probability of a successful attack is increased, it will still be possible to restore critical systems.</p>
<p style="text-align: justify;">Finally, it should be noted that more and more industrial processes are nowadays operating in a just-in-time mode. In this type of context, the preservation of the industrial system from an attack, or the ability to restore it quickly, would not be sufficient to maintain the level of production if the management of orders or distribution, for example, are unavailable. Cyber resilience must therefore be considered at the company level, and not only at the level of the industrial site.</p>
<h2 id="key" style="text-align: justify;">Key elements</h2>
<p style="text-align: justify;">To respond to an attack before it is late, it is necessary:</p>
<ul style="text-align: justify;">
<li>To involve the industrial teams (without which it is highly likely that the computer will survive the attack, but without the factory continuing to fulfil its primary mission);</li>
<li>To control its flows and implement network partitioning/filtering in order to be able to set up fallback postures:
<ul>
<li>Preventive, in order to isolate the factory in the event of an attack on an external network without having too significant an impact on the industrial process;</li>
<li>As a last resort, in order to shut down the information system in the event of a proven attack on the factory before the attacker modifies the industrial process.</li>
</ul>
</li>
<li>To test these fallback postures, in order to ensure that their activation is not worse than the attack.</li>
</ul>
<p style="text-align: justify;">And in the case where the attack could not be contained, the following elements are generally necessary in order to recover from the said attack:</p>
<ul style="text-align: justify;">
<li>Possess an up-to-date copy of your PLC programs;</li>
<li>Save a means of downloading these programs to the PLCs;</li>
<li>Have at least one copy of all critical backups on an off-line medium (external hard disk for example);</li>
<li>Identify its essential computer equipment (in particular so as not to restore the history server before the supervision server, etc.);</li>
<li>Backing up intelligently, sometimes a bit-by-bit copy of the hard disk is more efficient than an automatic copy on a dedicated server, generally encrypted at the same time as the system whose backups it hosts;</li>
<li>Don&#8217;t neglect documentation and training (otherwise a forgotten license key, or someone on holiday could quickly sign the end of the restore&#8230;).</li>
</ul>
<p style="text-align: justify;"><a href="#_ftnref1" name="_ftn1">[1]</a> <a href="http://www.cert.ssi.gouv.fr/uploads/CERTFR-2020-CTI-001.pdf">www.cert.ssi.gouv.fr/uploads/CERTFR-2020-CTI-001.pdf</a></p>
<p style="text-align: justify;">A new version of the threat assessment was published at the beginning of the year: <a href="https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-001.pdf">https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-001.pdf</a></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/03/cyber-resilience-in-an-industrial-environment/">Cyber resilience in an industrial environment</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
