WEBINAR RECAP: Ransomware in the real world. Is your IT Department ready to be attacked?

Ransomware in the real world

Last week, we hosted a Webinar to ask businesses if their IT department is really ready for a ransomware attack.

Over 50% of businesses will be victim of Ransomware in 2022, and the average bill to rectify an attack, considering downtime, people time, device cost, network cost, lost opportunity, ransom paid, and more… will be over £1.3m!

Did you miss it? Or would you like to watch it again? Well, the good news is that we recorded it and you can check it out here:

 

Your Questions, Answered.

A sign of a good webinar is the quality of the questions asked at the end. We had too many questions to be able to answer them all in the time allowed so James and Kosta have answered anything we didn’t have time for during the session.

Remember, if you you would like to find out more about Sophos MTR, have any questions around cybersecurity or need advice for your IT team, please reach out to James directly, [email protected], or call one of the team 01235 433900

 

What about false positives within Powershell and ps1 files, repositories like PSGet, NuGet etc – these constantly get flagged in our org with Defender Endpoint!

We would suggest if these are trusted internal tools they should be excluded from Scanning based on their HASH values or path. If these are dynamic libraries then in Sophos central we would create a policy for staff allowed to use these system tools and restrict all other user access to these tools.

 

How much Sophos will be responsible in case of a Ransomware attack?

If your business only has the Sophos Endpoint products, firewalls or email products in the case of an attack Sophos will provide remote support but hold no responsibility as the configuration and management of the platform is the responsibility of the business. However if the MTR service is in use then the business does have a level of protection from Sophos and the remediation services are covered under your contract.

 

How do we get the board to take cybersecurity seriously? We’ve covered the basics in terms of controls, but anytime I try to increase budget to add additional controls – it gets pushed back.

The best option to get senior management / board to take ownership of cyber security and cyber insurance is to use the scare factor of examples like our cyber victim where all senior management, directors and the board where removed from their posts under gross negligence as part of the work that took place to recover the business. Many of these have struggled to get new roles following the merger of the business because of the legacy association with such a large scale failure.

Michael Davey

What are the biggest cybersecurity threats right now?

The biggest threat remains ransomware and this continues to appear in different forms and flavours but ultimately the goal remains the same and that is to disrupt system usage.

 

Am I spending enough, appropriately on information security-related tools and controls? (Is there a network security or information security tool I should buy?)

There is no golden figure for how much to spend on protection but what you need to do is take a risk based assessment on what protection you have in place and make sure you are covering the full stack and have a solution in place for every risk in the system.

 

Not convinced that cyber insurance provides any real cover

Cyber Insurance is only going to work for you and your business if you have the right tools in place to protect the business in the first place as with car insurance they wont pay out if you are negligent , it is up to you and your business to make sure you have the correct protection in place.

 

Who would you recommend in terms of cyber security insurance providers?

We don’t directly recommend providers.

Cybersecurity health check

If you have someone in your team who is a disgruntled Employee and may be leaving the company and they leave a logic bomb on your network without you knowing it would Cyber Security Insurance cover this or would it then be void as its happened within your own team? What would be the legal response to this?

This is a very loaded question. In most cases, Cybersecurity Insurance will protect against this provided you have all other requirements in place. If however this disgruntled employee was part of your security team, that may raise questions around your employee vetting process and you may need to lean on your employee terms and conditions, specifically your computer misuse act should you need to follow up with legal proceedings.

 

Is the standard Sophos Endpoint not enough either?

We would recommend Sophos Intercept X as a minimum for protection in 2022.

 

Are there any courses that you would recommend for Cyber Security specialisation?

We would recommend you look at CISSP and then anything linked to business solutions you have in place.

 

Are the MTR team UK based?

Sophos MTR is a global follow the sun team. There is a UK team as part of this but to enable truly 24/7 support this is covered by a global team.

 

How do we get the board to take cybersecurity seriously? We’ve covered the basics in terms of controls, but anytime I try to increase budget to add additional controls – it gets pushed back.

The best option to get senior management / board to take ownership of cyber security and cyber insurance is to use the scare factor of examples like our cyber victim where all senior management, directors and the board where removed from their posts under gross negligence as part of the work that took place to recover the business. Many of these have struggled to get new roles following the merger of the business because of the legacy association with such a large scale failure

 

For us, the major deficiency we see today is not with attacks via known end points or servers but the chances of unknown devices being attached to our networks. This is an area which I feel very few companies or vendors are addressing well and cost effectively so I’d love to know if this is an area you guys both Planet and Sophos are investigating/investing in?

There are a number of NAC product’s that have surfaced over the years to try and fill this gap. What we are seeing the the solution for most business now is to terminate all VLAN’s on the firewall and use the synchronised security aspects of the Sophos XGS firewall to remove unwanted network traffic in controlled sectors, with only trusted devices being able to route traffic.

 

Is webinar recorded?

Yes, you can watch it here: https://youtu.be/qLPPw4kndy4

 

 

Looking for a technology partner?
Let’s talk

  • This field is for validation purposes and should be left unchanged.