1 of 12

RANSOMWARE ATTACKS, IMPACTS, THREATS, SECURITY CONTROLS AND PREVENTIVE STRATEGIES

Name

2 of 12

Introduction

  • Ransomware is a malware that locks out and prevent users from accessing their files or data (Memmi, 2023).
  • A recent ransomware attack at my hospital encrypted all the patient files stored in the servers.
  • The hospital operations were interrupted, including the inpatient and outpatient services.
  • Hospital emergency services were also impacted.
  • As the IT expert, I was called to help the hospital address the incident.
  • Presented is the expert analysis of the ransomware attack and recommended protection strategies.

3 of 12

Analysis of the Attack

  • The ransomware attack at the hospital was first reported on December 1st 2022.
  • An employee at the out-patient department opened a phishing mail and clicked a malicious link without suspecting.
  • The link downloaded a small file which was the “ransomware”.
  • After several unsuccessful attempts to open the file, the worker resumed what she was doing.
  • However, all the files that she initially opened easily were not opening.
  • In every attempt, she got an error response.

4 of 12

Analysis of the Attack

  • The staff did not report the incident because her duty was to end in the next 10 minutes.
  • The next morning, the situation was worse.
  • All the staff reported that they were unable to access the patients’ files.
  • As an IT expert, I was called in to intervene.
  • I realized it was a ransomware attack on the company’s network and server.
  • I led the IT Team to shut down the network and decrypted the files.
  • Luckily, the hospital had backed-up data remotely; used to restore operations.

5 of 12

Summary of the Ransomware Attack

6 of 12

Attacked Assets and Impacts

  • The main assets that were attacked by this ransomware attack were:
  • Storage server
  • Network server
  • Disk drives
  • Network system
  • Computer systems
  • The major adverse impact was the encryption of the stored patients’ files.
  • The normal service delivery was interrupted due to lack of information.
  • Financial loss on network modification.

7 of 12

Impacts of the Attack

  • The hospital restored 98% of the files from remote back-up but permanently lost the essential 2% after the files were deleted.

8 of 12

Threats Made to the Assets and Exploited Vulnerabilities

  • The attack exposed the network vulnerabilities to the attacker.
  • The storage server’s security system was compromised and needed overhaul to be used again (Memmi, 2023).
  • The authentication codes were compromised.
  • The attacker exploited the insider thread to launch attack on the hospital’s system.
  • The unaware staff unwillingly gave access to the attacker by clicking the phishing email link.
  • The attacker also exploited the network and server vulnerabilities (lacked intrusion detection software).

9 of 12

CERT Security Controls

  • CERT recommends a combination of good monitoring applications, frequent file backups, anti-malware software, and user training.
  • The monitoring tools like intrusion detection software would have detected the ransomware.
  • This would alert the user, resulting to immediate response and mitigation of the attack.
  • Anti-malware software would have prevented the ransomware from entering and spreading through the network.
  • User training would have boosted the staff’s awareness; she would have not clicked the link.
  • Frequent file backups would have helped to restore even the 2% of data that was lost.

10 of 12

CISA Preventive Strategies

  • Maintain offline, encrypted backups of data and to regularly test your backups (CISA.Gov., n.d.).
  • Create, maintain, and exercise a basic cyber incident response and communication plans for ransomware attack (CISA.Gov., n.d.).
  • Conduct regular vulnerability scanning to identify and address internet-related vulnerabilities.
  • Regularly patch and update software and OSs to the latest available versions (CISA.Gov., n.d.).
  • Configure devices properly and enable security features on the network.
  • Disable/block Server Message Block (SMB) protocol outbound (CISA.Gov., n.d.).
  • Implement a cybersecurity user awareness and training program for all employees.

11 of 12

Additional CERT Preventive Tips

12 of 12

References