When it comes to ransomware, it is best to be on offense with a plan before an attack, experts say.

Organizations should prepare for a cyberattack by running through scenarios to ensure everyone knows what to do, said Carolyn Crandall, chief security advocate for Attivo Networks, an advanced persistent threat (APT) bot detection and network security firm.
“This means having visibility, being able to detect live attack activity and having run tabletop exercises that assess the institution’s readiness for responding to an attack,” Crandall said.
Such exercises should include all the relevant parties that will be involved in an actual response, including technical teams, management, public relations, finance and legal teams, she told BAN.
Triage
Once an attack is identified, it’s time to triage and stop the bleeding, said Justin Estadt, head of product at SEI IT Services and a 20-plus-year veteran of IT security.
“Immediately, just shut everything down to take everything offline, stop whatever is happening from happening, stop the communication out and try to pinpoint and take the devices that may or may not be compromised,” Estadt told BAN. “If you’re not sure it doesn’t really matter at that point, just get them offline and stop allowing them to connect to each other.”
Banks should take some cursory effort to ensure it’s not a false positive, Estadt added.
Next steps
Bank Automation News asked six cybersecurity experts how to defend against ransomware attacks, which have been on the rise this year. Cybersecurity experts told BAN that after stopping a cyberattack, financial institutions (FIs) should take the following four steps internally:
1. Investigate the incident by determining the attack vector or identifying the path by which an attacker gained access, Estadt said. Determine how it was hit and what was compromised and then remove the malware, he added.
“Understanding those aspects really help you figure out how you can take the next action to either try to clean things up, or at least understand the level and the scope of how bad the incident really is,” Estadt said.
2. Evaluate the active directory, suggested Crandall, adding that cybersecurity firm Mandiant says the No. 1 reason for ransomware success is active directory exposures.
“They also said that active directory is leveraged in almost every ransomware attack,” Crandall said. “The most misconfigurations and weaknesses found in active directory included controlling privileged credentials and limiting what accounts have these privileges, the lack of visibility to see when privileged accounts are utilized and how credentials are exposed at the endpoints.”
Determine how extensive the active directory rebuild will be. Systems may not be able to go back online until this is understood, Crandall added.
3. Initiate a business continuity or data recovery plan, said Simon Eyre, chief information security officer and managing director of Europe at Drawbridge.
“Following a developed and tested plan prevents a reactionary response that may cause more harm such as reputational damage or an incorrect response to regulatory requirements,” Eyre said. “Making all staff aware of the specific requirements of this BCP scenario is paramount.”
4. Contact law enforcement. It may also be necessary to engage a forensic cybersecurity expert who understands the complexities and techniques of ransomware recovery, said Barbara Kissner, chief information security officer for Tassat, a fintech and digital payments platform. Someone already may have decrypted whatever was used to lock the data, added Safi Raza, director of cyber security at Fusion Risk Management.
To pay or not to pay, that is the question
The first question executives and risk professionals will tackle after a ransomware attack is whether to pay it, Raza told BAN.
“The pros and cons of doing so depend on each case, but it’s important to note that paying the ransom is not a guarantee that the attackers will decrypt the financial organizations systems,” Raza said. “They could also keep copies of sensitive data and use it in the future to extort more money.”
Regulators are against motivating criminals by paying a ransom, Raza added, pointing to an October 2020 statement from the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) that any payment made to a ransomware attacker by an FI could be investigated as a violation of OFAC regulations. OFAC reiterated that last week when it issued new security guidance to target those who facilitate ransomware payments.
If an FI insists on paying the ransom, there are a few things to keep in mind, Raza said.
“Remember that while criminals might ask for huge ransoms – they might settle for much less,” he said. “Just remember that payment does not guarantee decryption or safety from attacks in the future.”






