Skip to main content
CNYRIC 
Click here to go to homepage

Protecting Your Organization from Ransomware

 
protect yourself against ransomware
As you may have heard, the instances of ransomware attacks being made on local public and municipal institutions (such as school districts and libraries) are becoming increasingly common. “Ransomware” is a type of malicious software that attempts to deny a user access to a computer system/data/resources unless a literal ransom is paid to restore said access.  

In light of the rapid advancement and evolution of hacking methods, you may be surprised to learn that an estimated 95% of ransomware cases result from end-user error, which can often upend even the best security measures and antivirus protection. Most commonly, this occurs when someone unwittingly clicks on a link in a phishing email. With this in mind, the CNYRIC highly recommends the following measures for your staff and for your local workstations:
  • Implement a staff training program such as KnowBe4.
  • Review your workstation access controls and limit users to a rule of least privilege.
  • Require two factor authentication where appropriate.
  • Maintain a centrally managed and updated antivirus solution.
  • Review your email server rules and ensure that any executable extensions are stripped.
  • Implement other preventive security measures as set forth in the recent Department of Homeland Security and Emergency Services document that has been shared with all districts.
  • Prepare an incident response plan for your district so you know how to respond should something happen.
“While the back-end data infrastructure may be nicely secured in an organization, the front-end workstations, local network design, and end-user actions all play a critical role in preventing malware from entering in the first place,” advised CNYRIC Director Pamela Mazzaferro. 

The CNYRIC has made a concerted effort to mitigate the effectiveness of these attacks as well. 
 
“We are actively instituting geo-blocking of all IP ranges from countries outside of the United States and Canada,” said CNYRIC Assistant Director Rick Pollard. “The reason for this is due in large part to the significant amount of malicious traffic that we see each day that originates from foreign countries. We strongly encourage districts to purchase the advanced security features for their firewall that provide malware/intrusion detection services.”
 
Regarding antivirus/malware end-point protection for laptops and PC's, the CNYRIC is recommending that districts have a robust antivirus/malware solution such as Symantec or CrowdStrike (not Windows Defender) in place, and that it is fully managed and regularly updated.
 
CNYRIC
Phone: 315.433.8300
Visit: 6075 E. Molloy Rd. | Syracuse, NY 13211
Mail: P.O. Box 4754 | Syracuse, NY 13221
AICPA SOC
click for cayuga boces website
click for citi boces website
click for ocm boces website
click for tst  boces website