Tuesday, July 1, 2025
  • Home
  • About
  • Contact
  • Advertising Information
  • Subscribe
  • ist Live
ist Magazine
  • Home
  • Columns
    • ASA News
    • Ask Wolff
    • Epic Sales
    • Ergoline Focus
    • Eye to Eye
    • Lamp Talk with Leif
    • Lync IT
    • Notes from the Road
    • Trending @DevotedCreations
    • UK View
    • Monthly Motivation
  • Features

    Letter From The Publisher – March 2025

    SunCatchers, Boutique – Sun – Spa | Phenix City, AL

    Shining a Light: My Experience at the Heartland Tanning VIBE Expo

    sunbed

    Compliance Reliance

    sunbed

    Peak Season 2025 Success: Proven Strategies to Boost Profits

  • Health
    • All
    • Health Newsletter
    • Nutrition Corner
    red light therapy

    The Science of Light: Why It’s the Next Big Thing in Wellness

    “Love The Skin You’re In”

    3 Ways to Keep Your Bones Healthy & Strong

    The Truth About Retinol Confirmed by a Dermatologist

  • News
    • All
    • In The News
    • Industry Happenings
    • News Extra
    • Special Interest
    linked in as a sales platform

    The Rise of Short-Form Content on LinkedIn: A Game Changer for Business Growth

    Dmitry Tsvetkov / stock.adobe.com

    Revolutionizing The Industry: Why Tanning Is The New Full-Body Skincare

    heartland tan

    Talking About Heartland Tan’s January 2025 VIBE Event 

    IST Industry Choice Awards Winners 2024

    IST Industry Choice Awards Winners 2024

  • Spotlight
    tanned smiling woman teeth

    PSA: Delivering Bronze Skin Is Not Enough Anymore

    April 6, 2025
    glo tanning arkansas paragould

    Glo Tanning: New Salon Opening Spotlight

    April 4, 2025
    When focus flows, energy goes

    “Where Focus Goes Energy Flows”

    April 1, 2025
    The Secrets of Visionary Thinkers: 10 Rules For Brainstorming Success

    Warren Buffett Hates EBITDA. Here’s Why You Should Too

    March 18, 2025
    salon of distinction

    Salon of Distinction: Bear Naked Tanning

    March 17, 2025
    jchizhe / stock.adobe.com

    Keep It Simple Sales – K.I.S.S.

    March 17, 2025
  • Resources
    • Industry Links
    • Sun is Life
  • Lamp Talk
  • Digital Edition
No Result
View All Result
ist Magazine
  • Home
  • Columns
    • ASA News
    • Ask Wolff
    • Epic Sales
    • Ergoline Focus
    • Eye to Eye
    • Lamp Talk with Leif
    • Lync IT
    • Notes from the Road
    • Trending @DevotedCreations
    • UK View
    • Monthly Motivation
  • Features

    Letter From The Publisher – March 2025

    SunCatchers, Boutique – Sun – Spa | Phenix City, AL

    Shining a Light: My Experience at the Heartland Tanning VIBE Expo

    sunbed

    Compliance Reliance

    sunbed

    Peak Season 2025 Success: Proven Strategies to Boost Profits

  • Health
    • All
    • Health Newsletter
    • Nutrition Corner
    red light therapy

    The Science of Light: Why It’s the Next Big Thing in Wellness

    “Love The Skin You’re In”

    3 Ways to Keep Your Bones Healthy & Strong

    The Truth About Retinol Confirmed by a Dermatologist

  • News
    • All
    • In The News
    • Industry Happenings
    • News Extra
    • Special Interest
    linked in as a sales platform

    The Rise of Short-Form Content on LinkedIn: A Game Changer for Business Growth

    Dmitry Tsvetkov / stock.adobe.com

    Revolutionizing The Industry: Why Tanning Is The New Full-Body Skincare

    heartland tan

    Talking About Heartland Tan’s January 2025 VIBE Event 

    IST Industry Choice Awards Winners 2024

    IST Industry Choice Awards Winners 2024

  • Spotlight
    tanned smiling woman teeth

    PSA: Delivering Bronze Skin Is Not Enough Anymore

    April 6, 2025
    glo tanning arkansas paragould

    Glo Tanning: New Salon Opening Spotlight

    April 4, 2025
    When focus flows, energy goes

    “Where Focus Goes Energy Flows”

    April 1, 2025
    The Secrets of Visionary Thinkers: 10 Rules For Brainstorming Success

    Warren Buffett Hates EBITDA. Here’s Why You Should Too

    March 18, 2025
    salon of distinction

    Salon of Distinction: Bear Naked Tanning

    March 17, 2025
    jchizhe / stock.adobe.com

    Keep It Simple Sales – K.I.S.S.

    March 17, 2025
  • Resources
    • Industry Links
    • Sun is Life
  • Lamp Talk
  • Digital Edition
No Result
View All Result
ist Magazine
No Result
View All Result
Home Features Feature Story

Ransomware Readiness and Recovery: 8 Do’s and Don’ts

Bryce Austin by Bryce Austin
January 4, 2022
in Feature Story
Reading Time: 4 mins read
0

nuclear_lily / stock.adobe.com

0
SHARES
0
VIEWS
Share on FacebookShare on Tweeter

There were seven people seated around the table: The CEO, the VP, the CFO, the Special Agent from the FBI, the business owner, the forensics technician and the company’s CISO (Chief Information Security Officer).

“Don’t pay” was the CEO’s vote. Same for the VP.

You might also like

Letter From The Publisher – March 2025

Shining a Light: My Experience at the Heartland Tanning VIBE Expo

Compliance Reliance

“Pay it,” was the owner’s response. The CFO nodded in agreement.

“Paying could be a violation of Federal law,” stated the FBI representative.

The CISO had a hard time getting words out, as this was the largest ransom that he had dealt with at the time. $1,200,000 was a lot of money. “I don’t see another option, given the status of our backups. Either we pay the ransom or we begin liquidating the company’s assets as soon as possible. Which is the lesser of two evils?”

The CISO negotiated the ransom down to $410,000. The Bitcoin took several hours to amass. The cybercriminals delivered a decryption key, but 30% of the company’s data was gone forever – some of their hard drives filled up during the ransomware encryption process, and the encryption software kept running after the drives couldn’t hold any more data. Every file encrypted after that point was irretrievable. The total recovery took three months to ensure that no backdoors were left in the company’s systems, and the lawsuit to get the insurance company to cover the incident lasted almost two years.

Stopping ransomware includes three key areas: Cybersecurity hygiene of your staff, proper practices by your IT department, and your data-backup strategy. Here are eight ways to prevent a ransomware attack, and eight ways to recover if you fall victim to one:

Ransomware Defenses to Help Prevent Attacks:

  1. Add Multi-Factor Authentication (MFA) on all of your company’s email accounts and on all external access to your network (VPN, TeamViewer, WebEx, etc.). This will help prevent a cybercriminal from taking over an email account using a compromised username/password.
  2. If your company uses Windows Active Directory, do NOT log in to computers with Domain Admin accounts. There is an attack called “Pass the Hash” that will steal encrypted (hashed) credentials left behind. If you must log in with a Domain Admin account, change the password. 
  3. Patch your PCs. Workstations and servers. Every month. No exceptions. That includes conference room PCs, loaner PCs, HVAC computers, etc.
  4. Patch your networking gear. Firewalls, switches, UPSs, phone systems, etc.
  5. Install good antivirus software everywhere. All PCs. All Macs. All servers. Everywhere.
  6. Geofilter your Internet traffic and emails – if you don’t do business with a foreign country, block traffic and emails to/from it. It keeps out lazy cybercriminals. No, it won’t keep out the cybercriminals who VPN into your country before attacking you; but it’s surprising how many cybercriminals don’t take the time to do that.
  7. If you are part of a company with many workstations, use the Microsoft Local Administrator Password Solution (LAPS) to randomize the local administrator password on all PCs. If you have the same initial local admin username/password for every workstation, then if one machine gets compromised, it’s very easy for all of them to get compromised.
  8. If your users have local admin credentials, you may want to rethink that. Today. Right now. If a cybercriminal compromises a computer, they normally inherit the permissions of the user for that computer. If that user is a local administrator, the bad guys are going to use that access to do more damage.

In case you fall victim to ransomware, you need the following. Please note that most of these need to be done before the attack takes place:

  1. OFFLINE backups. These are backups that are kept off your network. Cybercriminals try to delete your backups; if your backups are not on your network, the bad guys can’t destroy them.
  2. Tested restore procedures. If you try to restore your backups only when you need them, you are rolling the dice every time you are in a real bind.
  3. Offline restore methodology. Don’t begin a restore with your network still attached to the Internet. Ransomware cases often unfold where the cybercriminals still have hooks into a company’s network, and they destroy the used-to-be-offline backups as soon as the restore process begins.
  4. Workstation reimages. You need a clean workstation image to restore workstations quickly if you suspect they have been compromised.
  5. Server rebuilds. You need a clean server image to recreate your servers quickly.
  6. Pre-negotiated incident response team contract. Find a cyber incident response company and get a contract in place. That way, you will know how to “call in the cavalry” very quickly as opposed to going through contract negotiations in the middle of a crisis.
  7. 35% free drive space on all network drives. Ransomware often bloats the data on the drives it encrypts. As soon as a drive fills up, the encryption process will keep trying to move forward, but every file it encrypts after the drive is full will be unrecoverable.
  8. If you have cybersecurity liability insurance, call your insurance company ASAP! There are many stories of insurance policies with a clause stating that the customer must inform their insurance company of a suspected incident within 24 hours of the initial discovery. If they take a few days to confirm that the incident was real, it can be an expensive mistake.

If all companies followed the specific recommendations above, ransomware cybercriminals would become a thing of the past. With proactive action and a good cybersecurity awareness training program for your staff, cybercrime is a solvable problem!

 

 

 

Previous Post

Start the Year with Peace of Mind

Next Post

Ready to Crush 2022?

Bryce Austin

Bryce Austin

Bryce Austin is the CEO of TCE Strategy, an internationally-recognized speaker on emerging technology and cybersecurity issues, and author of Secure Enough? 20 Questions on Cybersecurity for Business Owners and Executives. With over ten years of experience as a Chief Information Officer and Chief Information Security Officer, Bryce actively advises companies across a wide variety of industries on effective methods to mitigate cyber threats.

Related Posts

Feature Story

Letter From The Publisher – March 2025

by Onyi Odunukwe
March 18, 2025
SunCatchers, Boutique – Sun – Spa | Phenix City, AL
Feature Story

Shining a Light: My Experience at the Heartland Tanning VIBE Expo

by Kristin Smithers
March 18, 2025
sunbed
Feature Story

Compliance Reliance

by Joe Schuster
March 18, 2025
sunbed
Farr Factor

Peak Season 2025 Success: Proven Strategies to Boost Profits

by John Farr
March 17, 2025
Glo tanning palm harbor FL
Feature Story

Glo Tanning: New Salon Opening Spotlight

by Ossiana Tepfenhart
March 17, 2025
Next Post

Ready to Crush 2022?

Recommended

IST June 2025 Cover

June 2025 – IST Digital Edition

June 2, 2025
Ist-may-2025 cover

May 2025 – IST Digital Edition

May 5, 2025
credit cards stacked on each other

Planning For Trouble With Merchant Advances

April 7, 2025
IST april 2025 cover

April 2025 – IST Magazine Digital Edition

April 7, 2025

Popular Posts

  • The Heat Is On Sun Protection Lotions

    10 Tips To Abolish Raccoon Eyes

    0 shares
    Share 0 Tweet 0
  • Peak Season 2025 Success: Proven Strategies to Boost Profits

    0 shares
    Share 0 Tweet 0
  • A TOWEL IS NOT ENOUGH!

    0 shares
    Share 0 Tweet 0
  • Red-Light Therapy: Do Skincare Products Help or Hinder?

    0 shares
    Share 0 Tweet 0
  • Let’s Talk About Stripes, White Patches & White Spots.

    0 shares
    Share 0 Tweet 0

Don't Miss It

IST June 2025 Cover
Digital Edition

June 2025 – IST Digital Edition

June 2, 2025
Ist-may-2025 cover
Digital Edition

May 2025 – IST Digital Edition

May 5, 2025
credit cards stacked on each other
Epic Sales

Planning For Trouble With Merchant Advances

April 7, 2025
IST april 2025 cover
Digital Edition

April 2025 – IST Magazine Digital Edition

April 7, 2025

IST Magazine is the premiere, multi-award-winning business-to-business publication for the indoor tanning industry, providing valuable business articles and industry information in a fun, professional format.

Information

  • Advertising Information
  • Contact
  • Copyright Policy
  • Privacy Policy
  • Subscribe
  • Terms of Use

Categories

  • Columns
  • Features
  • Health
  • News
  • Spotlight
  • Digital Edition

© 2024 ist Magazine.

No Result
View All Result
  • Home
  • Columns
    • ASA News
    • Ask Wolff
    • Epic Sales
    • Ergoline Focus
    • Eye to Eye
    • Lamp Talk with Leif
    • Lync IT
    • Notes from the Road
    • Trending @DevotedCreations
    • UK View
    • Monthly Motivation
  • Features
  • Health
  • News
  • Spotlight
  • Resources
    • Industry Links
    • Sun is Life
  • Lamp Talk
  • Digital Edition

© 2024 ist Magazine.