How do you prevent your organization from becoming infected with ransomware?


Ransomware is on the rise, no one will deny that anymore. Where once the goal was to gain access to bank accounts, attackers are now getting paid to decrypt victims’ files.

Preventing you from becoming a victim of ransomware

As a business owner, you don’t want to think about your organization’s files being encrypted by an internet criminal. Unfortunately, the trend of ransomware has only increased recently and it does not look like it will go away anytime soon. There are now even providers that offer ransomware as a Software-as-a-Service (SaaS) solution – this is also known as Ransomware-as-a-Service (RaaS). In this process, a ransomware creator sells a software package, this software package is then used by other criminals to attack victims. In ransomware, files and systems on a computer are encrypted and the hostage taker demands a ransom to release them. Companies and organizations that do not have backups or are missing critical data often feel compelled to meet this requirement.

6 tips to reduce the risk of a ransomware attack

It is important for organizations to properly guard against ransomware. In any case, these 6 tips will help you ensure that your organization is more resilient to ransomware.

  1. Make backups using the 3-2-1 principle

The 3-2-1 backup principle is certainly not a luxury; the principle is as follows:

  • Make sure you have 3 copies of your most important data
  • Keep backups on at least 2 different media (e.g., hard drive and tapes)
  • Store 1 copy outside the door

3 copies of your most important data
Make sure you store important data securely in three different locations. So not in the same folder or on the same disk. The more copies you make of your data in different locations, the lower the risk of losing the data becomes. Also check that IT administrator is backing up your data.

2 different storage media
If several copies have been made, it is obviously not convenient to keep them on the same device. In an age where viruses, malware and hackers are the order of the day, you run the risk (and it’s risk is high if you haven’t secured it properly) of losing all the data on the device where you stored it. Therefore, make sure you have a copy on at least two different storage media. For example, a NAS but also tapes.

1 backup offsite
Finally, it is important to have physical separation for your third copy. So make sure you don’t keep all the data in the same physical location. For example, keep in mind that a fire could break out or be broken into.

  1. Provide a safe work-from-home environment

It is important to provide a safe home working environment for employees so that they can meet your organization’s security requirements even from home. You can read more about this in the article “How do you make sure your staff works from home safely?”

  1. Have the corporate network tested

To be more certain about the digital security status of your corporate network, it is important to have it properly pen-tested. This involves detecting potential vulnerabilities before they can be exploited by potential attackers.

  1. Make sure all systems are up to date

It is important to ensure that all business systems (e.g. laptops, computers, phones but also servers) are regularly provided with the latest security updates. This reduces the chance of hackers getting into your organization through vulnerabilities.

  1. Have a clear and strong password policy

It is important for employees to choose a secure password, to facilitate this it is important to have a clear and strong password policy. It is recommended to have a password length of at least 12 characters, special characters, numbers, uppercase and lowercase letters

  1. Have a digital burglar alarm installed

In order to detect if an attacker may be trying to get in, it is important to apply some form of security monitoring to the corporate network. This is just as important as having an alarm system for your office building. Security monitoring involves monitoring traffic to detect attackers. So a kind of digital burglar alarm.

