Ransomware attacks can be prevented, but this requires a layered approach, according to Michael Dell.
When asked if ransomware is a solvable problem, the Dell Technologies founder and CEO, speaking at a ransomware virtual event today, said it’s a topic that comes up in every conversation he has with customers.
“It’s going to take a tremendous effort across multiple layers of defense, including public-private partnerships, to tackle this and the other cybersecurity-related issues,” Dell said, adding he was “very pleased” to see the White House take steps to curb ransomware. This includes an open letter to private-sector companies outlining best practices to prevent attacks and an executive order on improving the United States’ cybersecurity posture.
“And we know the industry as a whole is making some positive gains,” Dell added, noting a Sophos ransomware report that found 39% of cybersecurity incidents were stopped before data could be encrypted, up from 24% last year. “There’s still a long way to go and we may never completely overcome ransomware or other related kinds of attacks, but there is some good progress.”
As the attack surface expands with more people and machines connecting to corporate networks, building security into products as opposed to bolting it on after becomes increasingly important, Dell said. “We believe that security, privacy, the resiliency of these systems really should be central to the design and manufacturing process for digital products and services, and this puts organizations in a better starting position to defend themselves.”
At Dell Technologies this starts with its secure development lifecycle and supply chain initiatives. And it also spans the company’s backup and data recovery products including new software and managed security services that it announced today, Dell said.
“There are things organizations can do now to protect themselves,” he continued. “They’ve got to have a plan, they’ve got to prepare, they’ve got to run drills and simulations, and really assume that you’ve been attacked. Follow the ransomware guidelines that the White House put out in June, adopt the NIST Cybersecurity Framework to identify, protect, detect, respond, and recover.”
Additionally, organizations need to prioritize data protection, and use an immutable data vault that allows them to quickly recover business-critical data in case of a cyberattack, Dell said. “Protecting their data is really at the core of that trust that they have with their customers and the people they serve,” he added. “Security is evolving into a conversation about trust.”
As the amount of data increases — organizations manage more than 10 times the amount of data than they did five years ago, according to Dell Technologies’ most recent Global Data Protection Index study — corporations need to take a risk-based approach to cybersecurity, and they also need to consider trust.
“Trust takes the conversation to another level, inclusive of security, privacy, ethics, accountability, transparency of governance, quality, and resiliency,” Dell said. “It’s important that we all work together to build that framework of trust as we build this digital future.”
Comments