{"id":29159,"date":"2019-09-18T11:25:02","date_gmt":"2019-09-18T11:25:02","guid":{"rendered":"http:\/\/4e845f05-bcd4-4f2e-8fff-01e94390b299"},"modified":"2019-09-18T11:25:02","modified_gmt":"2019-09-18T11:25:02","slug":"ransomware-11-steps-you-should-take-to-protect-against-disaster","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/","title":{"rendered":"Ransomware: 11 steps you should take to protect against disaster"},"content":{"rendered":"<p>Ramsomware continues to be one of the <a href=\"https:\/\/www.zdnet.com\/article\/the-ransomware-crisis-is-going-to-get-a-lot-worse\/\" target=\"_blank\" rel=\"noopener noreferrer\">biggest menaces on the internet<\/a>. Clicking on the wrong link could be enough to set off a sequence of events that ends with all your data being encrypted by crooks, who will only unlock it in return for a hefty ransom &#8212; usually in bitcoin or another hard-to-trace cryptocurrency.<\/p>\n<p>Criminal ransomware gangs are well financed (thanks to all those bitcoin ransoms) and employ increasingly sophisticated tactics. Only low-level crooks are interested in encrypting PCs one-by-one: the big gangs seek backdoors into corporate networks and then explore until they are ready to cause maximum chaos (and a big payday) by encrypting as many devices as possible in one go.<\/p>\n<p>It&#8217;s not just criminal gangs that have noticed the <a href=\"https:\/\/www.techrepublic.com\/article\/ransomware-the-smart-persons-guide\/\" target=\"_blank\" rel=\"noopener noreferrer\">power of ransomware<\/a>: state-backed hacking groups have also used ransomware to create both chaos and profit for their backers.<\/p>\n<p>What we&#8217;re seeing is an arms race between the crooks looking for new ways to compromise systems and businesses trying to plug every gap in their defences.<\/p>\n<p>This level of threat means there&#8217;s no way to absolutely protect yourself or your business from ransomware, or indeed any other kind of malware. But there are a number of steps you can take to minimise your attack surface.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/05\/30\/d59d04eb-50ea-4502-846c-985304e20a6a\/resize\/470xauto\/f5e3a453f3ace679b6450bd8bbc850b0\/istock-1124997379.jpg\" class alt=\"ransomware attack\" height=\"auto\" width=\"470\"><\/span> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>11. MAKE SURE YOUR ANTIVIRUS SOFTWARE IS UP TO DATE<\/strong><\/h3>\n<p>This seems obvious, but is occasionally neglected by smaller organisations. Many antivirus packages now offer ransomware-spotting features or add-ons that try to spot the suspicious behaviour that&#8217;s common to all ransomware: file encryption. These apps monitor your files for unexpected behaviour &#8212; like a strange new piece of software trying to encrypt them all &#8212; and aim to prevent it. Some security packages will even make copies of the files that are threatened by ransomware.<\/p>\n<h3><strong>10. UNDERSTAND WHAT&#8217;S HAPPENING ACROSS THE NETWORK<\/strong>&nbsp; &nbsp;&nbsp;<\/h3>\n<p>There&#8217;s an array of related security tools &#8212; from intrusion prevention and detection systems to <a href=\"https:\/\/www.techrepublic.com\/article\/azure-sentinel-microsofts-thoroughly-modern-siem\/\" target=\"_blank\" rel=\"noopener noreferrer\">security information and event management<\/a>&nbsp;(SIEM) packages &#8212; that can give you an insight into the traffic on your network. These products can give you an up-to-date view of your network, and should help you spot the sort of traffic anomalies that might suggest you&#8217;ve been breached by hackers, whether they are intent on infecting your systems with ransomware or have something else in mind. If you can&#8217;t see what&#8217;s happening on the network, there&#8217;s no way you can stop an attack.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Magnifying glass showing a spam folder.\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/6fed0d89-3afc-4815-802d-818d3f3664f3\/resize\/470xauto\/ba9e1d11d8b0bdf6af8511a1fe204df9\/email.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/6fed0d89-3afc-4815-802d-818d3f3664f3\/resize\/470xauto\/ba9e1d11d8b0bdf6af8511a1fe204df9\/email.jpg\" class alt=\"Magnifying glass showing a spam folder.\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>9. SCAN AND FILTER EMAILS BEFORE THEY REACH YOUR USERS<\/strong><\/h3>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>The easiest way to stop staff clicking on a ransomware link in an email is for the email never to arrive in their inbox. This means using content scanning and email filtering, which ought to take care of many phishing and ransomware scams before they actually reach staff.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Serious woman boss talking to multiracial team at boardroom meeting\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/07\/29\/83b3e747-4a61-4591-9cd3-260d5a3c3301\/resize\/470xauto\/44c238459ac594228823cd1f8777aefb\/istock-9585313641.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/07\/29\/83b3e747-4a61-4591-9cd3-260d5a3c3301\/resize\/470xauto\/44c238459ac594228823cd1f8777aefb\/istock-9585313641.jpg\" class alt=\"Serious woman boss talking to multiracial team at boardroom meeting\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>8. HAVE A PLAN FOR HOW TO RESPOND TO A RANSOMWARE ATTACK, AND TEST IT<\/strong><\/h3>\n<p>A recovery plan that covers all types of tech disaster should be a standard part of business planning, and should include a ransomware response. That&#8217;s not just the technical response &#8212; cleaning the PCs and reinstalling data from backups &#8212; but also the broader business response that might be needed. Things to consider include how to explain the situation to customers, suppliers and the press. Consider whether regulators need to be notified, or if you should call in police or insurers. Having a document is not enough: you also need to test out the assumptions you have made, because some of them will be wrong.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Make money\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/2b29f76a-a335-4062-a367-27ba7ba638ef\/resize\/470xauto\/996acc55ecee7cd1a0ca04677a52eb65\/internet-cash.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/2b29f76a-a335-4062-a367-27ba7ba638ef\/resize\/470xauto\/996acc55ecee7cd1a0ca04677a52eb65\/internet-cash.jpg\" class alt=\"Make money\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>7. THINK VERY LONG AND HARD BEFORE YOU PAY A RANSOM<\/strong><\/h3>\n<p>Ransomware crooks have found their way through your defences and now every PC across the business is encrypted. You could restore from backups, but it will take days and the criminals only want a few thousand dollars. Time to pay up?<\/p>\n<p>For some, that may be the obvious conclusion. If the attackers only want a relatively small amount then it might, in the short term, make business sense to pay up because it means the business can be up and running again quickly. However there are reasons why you might not want to pay.<\/p>\n<p><strong>SEE:<\/strong> <a href=\"https:\/\/www.techrepublic.com\/resource-library\/whitepapers\/10-tips-for-new-cybersecurity-pros-free-pdf\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>10 tips for new cybersecurity pros<\/strong><\/a> <strong>(free PDF)<\/strong><\/p>\n<p>First, there&#8217;s no guarantee that the criminals will hand over the encryption key when you pay up &#8212; they are crooks, after all. If your organisation is seen to be willing to pay, that will probably encourage more attacks, either by the same group or others. There&#8217;s also the broader impact to consider. Paying a ransom, either from your own funds or via cyber insurance, is to reward these gangs for their behaviour. It will mean that they are even better funded and able to run even more sophisticated campaigns against you or other organisations. It might save you some pain in the short term, but paying the ransom only fuels the ransomware epidemic.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Businesswoman Working On Computer\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/6ac22579-1040-4bf7-a5d2-d9fff04fb76d\/resize\/470xauto\/661f824120f1fc223ac4e968bdb1b2de\/spreadsheet-cfo.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/6ac22579-1040-4bf7-a5d2-d9fff04fb76d\/resize\/470xauto\/661f824120f1fc223ac4e968bdb1b2de\/spreadsheet-cfo.jpg\" class alt=\"Businesswoman Working On Computer\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>6. UNDERSTAND WHAT YOUR MOST IMPORTANT DATA IS AND CREATE AN EFFECTIVE BACKUP STRATEGY<\/strong><\/h3>\n<p>Having secure and up-to-date backups of all business-critical information is a vital defence, particularly against ransomware. In the event that ransomware does compromise some devices, having a recent backup means you can restore that data and be operational again fast. But it&#8217;s vital to understand where that business-critical data is actually being held. Is the CFO&#8217;s vital data in a spreadsheet on their desktop, and not backed up in the cloud as you thought? It&#8217;s no good having a backup if you&#8217;re backing up the wrong stuff, or backing it up so infrequently that it&#8217;s useless.<\/p>\n<h3><strong>5. UNDERSTAND WHAT&#8217;S CONNECTED TO YOUR NETWORK<\/strong><\/h3>\n<p>PCs and servers might be where your data resides, but they aren&#8217;t the only devices you have to worry about. Thanks to the office wi-fi, the Internet of Things and working from home, there&#8217;s now a wide variety of devices connecting to the company network, many of which will lack the kind of built-in security you&#8217;d expect from a corporate device. The more devices, the greater the risk that one will offer hackers a backdoor into your network, and then use that access to move through your systems to more lucrative targets than a badly secured printer or a smart vending machine. Also, think about who else has access to your systems: are your suppliers aware of the potential risk of ransomware and other malware?<\/p>\n<h3><strong>4. MAKE IT HARDER TO ROAM ACROSS YOUR NETWORKS<\/strong><\/h3>\n<p>Ransomware gangs are increasingly looking for the biggest possible payday. Encrypting the data on one PC isn&#8217;t going to make them rich, so they are likely to gain access to a network and then explore widely in order to spread their malware as far as possible before pulling the trigger and encrypting everything. Make this harder by segmenting networks, and also by limiting and securing the number of administrator accounts, which have wide-ranging access. Phishing attacks have been known to target developers simply because they have broad access across multiple systems.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Worried stressed businessman shocked by bad news online using laptop\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/462d2f18-397b-4dc2-9532-d69d10a7fd6a\/resize\/470xauto\/9fe85c68e900eea3492a1b42daf31a14\/ransomware.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/462d2f18-397b-4dc2-9532-d69d10a7fd6a\/resize\/470xauto\/9fe85c68e900eea3492a1b42daf31a14\/ransomware.jpg\" class alt=\"Worried stressed businessman shocked by bad news online using laptop\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>3. TRAIN STAFF TO RECOGNISE SUSPICIOUS EMAILS<\/strong><\/h3>\n<p>One of the <a href=\"https:\/\/www.techrepublic.com\/article\/more-than-99-of-attacks-in-the-past-year-relied-on-human-error-to-gain-access\/\" target=\"_blank\" rel=\"noopener noreferrer\">classic routes for ransomware<\/a> to enter your organisation is via email. That&#8217;s because spamming out malware to thousands of email addresses is a cheap and easy way for ransomware gangs to try and spread malware. Despite the basic nature of these tactics, it&#8217;s still depressingly effective.<\/p>\n<p><strong>SEE:<\/strong> <a href=\"https:\/\/www.zdnet.com\/article\/the-ransomware-crisis-is-going-to-get-a-lot-worse\/\"><strong>The ransomware crisis is going to get a lot worse<\/strong><\/a><\/p>\n<p>Training staff to recognise suspicious emails can help protect against ransomware and other email-borne risks like phishing. The basic rule: don&#8217;t open emails from senders you don&#8217;t recognise. And don&#8217;t click on the links in an email if you aren&#8217;t absolutely sure it is legitimate. Avoid attachments whenever possible and beware of attachments that ask you to enable macros, as this is a classic route to a malware infection. Consider using two-factor authentication as an additional layer of security.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"istock-468347435.jpg\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2017\/08\/17\/bc0a0d25-afe8-4558-9f5c-fd621ef7b603\/resize\/470xauto\/b1be8d9510a908060431ba7cf07587a4\/istock-468347435.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet2.cbsistatic.com\/hub\/i\/r\/2017\/08\/17\/bc0a0d25-afe8-4558-9f5c-fd621ef7b603\/resize\/470xauto\/b1be8d9510a908060431ba7cf07587a4\/istock-468347435.jpg\" class alt=\"istock-468347435.jpg\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>2. CHANGE DEFAULT PASSWORDS ACROSS ALL ACCESS POINTS<\/strong><\/h3>\n<p>Clicking on a bad link in an email is probably the best known way of getting infected with malware, but it&#8217;s far from the only way. Nearly a third of ransomware was distributed via brute force and remote desktop protocol (RDP) attacks, according to research by F-Secure. <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-crooks-hit-synology-nas-devices-with-brute-force-password-attacks\/\">Brute force attacks<\/a>&nbsp;are attempts by hackers to access servers and other devices by trying as many passwords as possible, usually with the aid of bots, in the hopes of hitting the jackpot.&nbsp;<\/p>\n<p><strong>SEE:&nbsp;<\/strong><a href=\"http:\/\/www.zdnet.com\/topic\/a-winning-strategy-for-cybersecurity\/\"><strong>A winning strategy for cybersecurity<\/strong><\/a><strong>&nbsp;(ZDNet special report) |&nbsp;<\/strong><a href=\"https:\/\/www.techrepublic.com\/resource-library\/whitepapers\/a-winning-strategy-for-cybersecurity-free-pdf\/?ftag=CMG-01-10aaa1b\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Download the report as a PDF<\/strong><\/a><strong>&nbsp;(TechRepublic)<\/strong><\/p>\n<p>As many companies fail to change default passwords or use easily-guessed combinations, brute force attacks are regularly effective. RDP allows remote control of PCs, and is another common ransomware attack avenue. There are steps you take to reduce the risk of a attack via RDP, ranging from ensuring strong passwords are used, to changing the RDP port, to limiting its availability to only the devices that really need it.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"screen-shot-2019-09-17-at-15-31-36.png\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/35113966-ca81-4ab1-8c83-b28e916e9e41\/resize\/470xauto\/fc6ec9685161b6a013e4c9f37eb93c93\/screen-shot-2019-09-17-at-15-31-36.png\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/35113966-ca81-4ab1-8c83-b28e916e9e41\/resize\/470xauto\/fc6ec9685161b6a013e4c9f37eb93c93\/screen-shot-2019-09-17-at-15-31-36.png\" class alt=\"screen-shot-2019-09-17-at-15-31-36.png\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Image: F-Secure<\/span><\/p>\n<h3><strong>1. APPLY SOFTWARE PATCHES TO KEEP SYSTEMS UP TO DATE<\/strong><\/h3>\n<p>Patching software flaws is a painful, time-consuming and tedious job. It&#8217;s also <a href=\"https:\/\/www.techrepublic.com\/article\/wannacry-ransomware-attack-industry-experts-offer-their-tips-for-prevention\/\" target=\"_blank\" rel=\"noopener noreferrer\">vital to your security<\/a>. Malware gangs will seize on any software vulnerabilities and attempt to use them as a way into networks before businesses have had time to <a href=\"https:\/\/www.zdnet.com\/article\/cybersecurity-how-to-get-your-software-patching-strategy-right-and-keep-the-hackers-at-bay\/\" target=\"_blank\" rel=\"noopener noreferrer\">test and deploy patches<\/a>. The classic example of what happens if you don&#8217;t patch fast enough is WannaCry. This ransomware caused chaos in the summer of 2017, including significantly disrupting the NHS in the UK. A patch for the underlying Windows Server Message Block protocol exploit that allowed WannaCry to spread so far had actually been released several months before the ransomware hit. But not enough organisations had applied the fix to their infrastructure, and over 300,000 PCs were infected. It&#8217;s a lesson many organisations are still to learn: one in three IT professionals admitted that their organisation had been breached as a result of an unpatched vulnerability, according to a survey by&nbsp;<a href=\"https:\/\/www.tripwire.com\/state-of-security\/vulnerability-management\/unpatched-vulnerabilities-breaches\/\" target=\"_blank\" rel=\"noopener noreferrer\">security company Tripwire<\/a>.<\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" class=\"lazy\" alt=\"Hand inserting USB flash drive into laptop computer port closeup\" height=\"auto\" width=\"470\" data-original=\" https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/edff4c36-fe5b-4eac-87a6-3cbfefe44254\/resize\/470xauto\/6abe5db979b7000bfbc3cb34f71ad48a\/usb.jpg\"><\/span><noscript><\/p>\n<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet3.cbsistatic.com\/hub\/i\/r\/2019\/09\/17\/edff4c36-fe5b-4eac-87a6-3cbfefe44254\/resize\/470xauto\/6abe5db979b7000bfbc3cb34f71ad48a\/usb.jpg\" class alt=\"Hand inserting USB flash drive into laptop computer port closeup\" height=\"auto\" width=\"470\"><\/span><\/p>\n<p><\/noscript> <span class=\"credit\">Getty Images\/iStockphoto<\/span><\/p>\n<h3><strong>BONUS TIP: DON&#8217;T PLUG IN THAT RANDOM USB STICK&#8230;<\/strong><\/h3>\n<p>&#8230;you know, the one you found in the street by the office.&nbsp;<\/p>\n<p>Seriously, do we <em>still<\/em> have to warn about this stuff?&nbsp;<\/p>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Falling victim to ransomware could put your vital business or personal data at risk of being lost forever. These steps can help bolster your defences.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":29160,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-29159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-09-18T11:25:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"470\" \/>\n\t<meta property=\"og:image:height\" content=\"313\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Ransomware: 11 steps you should take to protect against disaster\",\"datePublished\":\"2019-09-18T11:25:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/\"},\"wordCount\":1733,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/\",\"name\":\"Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg\",\"datePublished\":\"2019-09-18T11:25:02+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg\",\"width\":470,\"height\":313},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/ransomware-11-steps-you-should-take-to-protect-against-disaster\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ransomware: 11 steps you should take to protect against disaster\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/","og_locale":"en_US","og_type":"article","og_title":"Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-09-18T11:25:02+00:00","og_image":[{"width":470,"height":313,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Ransomware: 11 steps you should take to protect against disaster","datePublished":"2019-09-18T11:25:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/"},"wordCount":1733,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/","url":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/","name":"Ransomware: 11 steps you should take to protect against disaster 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg","datePublished":"2019-09-18T11:25:02+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/09\/ransomware-11-steps-you-should-take-to-protect-against-disaster.jpg","width":470,"height":313},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/ransomware-11-steps-you-should-take-to-protect-against-disaster\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Ransomware: 11 steps you should take to protect against disaster"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/29159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=29159"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/29159\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/29160"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=29159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=29159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=29159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}