
With ransom and phishing attacks on the rise, most businesses struck with an attack have no clue what to do to respond. Now that we know lightning strikes twice when it comes to ransom attacks, once attacked your chances of a subsequent attack are very likely, it is more important than ever to be prepared to completely remediate an infection and respond afterwards.
Conduct a root cause analysis
On the surface you might be thinking about ransomware remediation as specifically recovering your files and getting your team up and running. What you or your IT team might be seriously overlooking is that your chances of a reinfection, and continued downtime, are higher now than they were before you got hit the first time.
The clearest way to ensure attackers do not get in a second time is by evaluating the root cause. You may think you know what happened. Maybe you suspect a user clicked on a link, or someone self-identified as patient zero. But there are multiple ways for an attack to have presented itself, and the symptoms your users saw may not be conclusive as to the actual cause.
Create a workflow and playbook that goes beyond remediation. After a phishing attack, ask how the person got targeted. What was the messaging on the email? How did it get through spam filtering? It may turn out that someone used their corporate email address to sign up for a less than reputable website. Does your security policy address issues like this, and if so, was the user unaware of it? Simply treating the symptoms will get you nowhere when it comes to preventing the next attack.
Use metrics to improve
Making sure you at least have metrics to track progress will help you see security issues going away and hold specific people accountable. Note that most IT support teams try to avoid accountability metrics because they fear the unknown. Most often, instead of taking ownership of security issues, they will pass the buck to specific users they blame rather than finding proactive ways to get to the bottom of it.
I strongly recommend leveraging security metrics as a basis for making process improvements, because they reveal truths about your system that get overlooked if not exposed, and because measurable metrics help you quantify improvements to your board, team or clients.
Keep evidence of the attack
Many IT support teams cannot figure out how to determine the extent of a breach unless files are visibly encrypted for ransom. In the post-incident phase, you should carefully determine what was touched by the attack. This will help you enormously in the event of any litigation or audits down the road. If you do not satisfactorily document what you did and how you assessed your cyber event, a court may hold you responsible for negligent behavior and your clients may lose trust in your ability to hold their best interest at heart.
Self-reflect, and change your policies
The organizations that survive cyberattacks are the ones that learn from their mistakes. They perform third party network security assessments and find ways to improve. In addition to strengthening your security weaknesses, evaluate your team preparedness. Make sure you have full awareness and training of your entire staff, and clearly assign roles to key members so you can bounce back quickly.
Write or modify your existing security policy so people know what is acceptable in the workplace, and if best-practice policies conflict with current habits, find a way to reconcile the inconvenience. For instance, if most of your users insist on using personal cell phones on your network, consider limiting them to a guest WiFi to mitigate the risk of devices infecting your network. Bottom line, if you were a victim of any type of cyberattack, you need to prepare your team and network for the next one.



