As ransomware attacks skyrocket, experts argue the best way avoid paying ransoms is to adopt a zero-trust architecture, embrace a zero-tolerance attitude, back up important data, and rehearse recovery procedures regularly.

“The more you can rely on not paying the ransom, the more that's going to basically take the economic incentive away” from the ransomware groups, said Simon Jelley, GM and VP of backup at Veritas Technologies. “Ultimately, we have to keep in mind while we talk about ransomware threats, it's about a money-making enterprise.”

There's been an evolution in the ransomware industry over the past year as it's shifted from an opportunistic market into a well-organized, two-tier marketplace.

The attack vectors have changed from testing attacks against industries historically seen as easier to penetrate, like public sectors and nonprofit organizations, to organized attacks on larger enterprises, like Accenture and Colonial Pipeline, he added.

The two-tier model includes "suppliers" that develop the initial ransomware-attack algorithms, and “attackers” that have the access to the targeted organizations, buy the code, and actually orchestrate the attack, Jelley explained. 

“The key to any successful ransomware attack is not actually the ransomware algorithm." It's can you get access into someone's network, he said.​ ​

As the ransomware crisis continues to evolve and gain momentum, organizations are looking for ways to mitigate attacks, Jelley said. Many companies are already using zero-trust architectures to protect their networks, and multi-factor authentication remains one of the most used and trusted tools, he added.

These methods make the penetration harder for the attackers, but Jelley argues "there are still ways in if they can buy access.” And there is a strong incentive to do just that as enterprises have proven to be more lucrative than traditional targets.

Zero-Tolerance Approach

There isn’t a 100% reliable way to stop an attack from happening. “The reality is that security vendors are always playing catch up to the next hacker [who is] trying to develop ... that very best phishing algorithm to get you to click that link, and it is going to happen at some point,” Jelley said.

Because of this, Jelley suggests organizations “take a zero-tolerance approach in terms of understanding that you are going to get attacked.”

Organizations should also establish a recovery plan so they can get back online after a ransomware attack without having to pay the ransom, he said.

Jelley referenced a recent ransomware attack on IT services and consulting company Accenture as an example. Accenture did not rely on security software to block the attacks. Instead, it took a zero-tolerance approach and had a fallback mechanism to get the data back, he explained.

Test the Backup

Jelley noted that many organizations recognize they have to have recovery techniques in place, including backing up their critical data. Cisco executives also warned a solid backup plan is needed to deal with the sheer volume of ransomware attacks at this year’s Black Hat event.

Jelley recommends organizations prioritize their data policies instead of protecting everything at the same level. In other words, organizations should know what data and applications are critical to their business, devise a policy to generate siloed copies of that data, and establish a restoration plan before an attack occurs.

Most importantly, organizations need to be rehearsing those recoveries at least once a month so they can bring back the data without affecting productivity, Jelley said.

With zero-trust, zero-tolerance approach, and a backup as the ultimate safety net, “you don't fuel the ransomware attackers," he said.

"Why do we want to not fuel this industry further in terms of paying ransoms? It's because of the real-world implications of ransomware attacks,” Jelley said, citing the Colonial Pipeline shutdown and Howard University canceling classes.