New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

The importance of crisis management in the age of ransomware

New York Tech Editorial Team by New York Tech Editorial Team
October 18, 2021
in Cybersecurity
0
The importance of crisis management in the age of ransomware
Share on FacebookShare on Twitter

Cybersecurity crises are becoming commonplace. With the massive surge in ransomware attacks in the last few years, businesses can’t afford to ignore the increasing possibility of facing one, and should invest money and effort into crisis management.

Some have already been burned and are (hopefully) working on creating incident response and business continuity plans and practicing them right now. Those who haven’t yet been hit should thank their lucky stars and start the same process as soon as possible.

We’ve asked Ron Tosto, CEO and founder of cybersecurity and compliance consulting firm Servadus, for some insight on the topic.

ransomware crisis management

[Answers have been edited for clarity.]

What are some frequent obstacles preventing companies from considering crisis management?

The most common obstacle is the lack of sponsorship from the executive leadership in the organization. If they do not see a reason for crisis management, then it will not be a priority for the company. This establishes company culture as it relates to crisis preparedness.

Schedules are also a very common challenge for organizations. Practice in crisis management steps requires maximum participation by the organization.

Finally, crisis management preparedness has a financial impact. Companies that are watching the bottom dollar may not take money for margin to prepare for crisis.

What or who is the most crucial element/person/team when it comes to crisis management planning and putting the plan in practice?

Within an incident response plan, every role is vital to the success of the response. However, the most imperative role is either the network operation center or security operation center who would be responsible for discovering the incident and alerting the organization.

If the person has an opportunity to identify an incident and misses it, no one else will respond. During the incident, more team members are present and aware of supporting each other. There is an opportunity for every end-user to notice suspicious activity and to report it. Team members must understand the symptoms of an incident and receive encouragement to initiate the plan’s first steps as a part of the culture to protect the company.

Can crisis management planning be completely outsourced to outside experts?

Elements of crisis management can include outside experts; legal consultants, PR firms, and forensic investigators are good resources to have on retainer.

When it comes to crisis management CEOs can use crisis management consultants, but the leader of the company should never lose focus that decisions made during a crisis are the owners of the company with stake in the outcome.

How often should incident response and business continuity plans be revised, and how often should they be practiced?

Organizations with no major change to leadership and their operating model should be reviewing and testing incident response plans annually.

Merging operations after an acquisition, moving to a cloud environment, and restructuring the VPN infrastructure to support remote workers are all good examples of when to generate updates to the business continuity plan.

Every time there is a new business continuity plan there needs to be an incident response exercise. If the person assigned to a major role within the incident response plan changes, then test the plan at least to a minimum level. There must be a hands-on exercise awareness training for all new employees including technical roles and leadership personnel.

Planning for a cybersecurity crisis is important, but so is implementing strategies for mitigating the risk of facing one in the first place. What is important to keep in mind?

How to prepare for ransomware attacks is an often-asked question. From my point of view, the best action is to go through the checklist of security controls that prevent hackers from taking control of your network.

Organizations like Servadus offer a Ransomware Readiness Assessment which helps organizational leadership identify current risks to the corporation. Of course, having up-to-date incident response and business continuity plans are part of that assessment. Outside, the real value comes from remediating weak cybersecurity controls.

Additionally, organizations implement a framework to shore security control implementation and sustainability. Many organizations try to maintain compliance and security controls but are vulnerable to attacks 3 to 6 months after validating security in channels in place.

The long-term strategy is about validating sustainable security controls. The service framework also allows organizations to evaluate threats to the organization and vulnerabilities of the system software in use. This is the fundamental formula for cyber risk: Threats + vulnerabilities = risk. Beyond the cyber security framework strategy, organizations must have the capability to understand vulnerabilities and the threats.

If a business leader believes any of this is too expensive, they usually believe insurance will pay the bill. But they should look at the fine print of their insurance policy; the fact of the matter is that even if you have cyber security insurance, the insurance company will often not cover losses resulting from an attack if an organization does not prepare for a cyber attack.

Some companies try to justify their decision to forego preparation by saying that the cost of a cyber-attack is usually less than the cost of prevention and preparation. The reality is that ransom payouts are now in the millions of dollars for large organizations; there are examples of a $4 million payment for ransom attacks. Even if an organization paid $1 million in preparedness to maintain the business, it is still $3 million ahead of paying bad actors.

Credit: Source link

Previous Post

Zypp Electric & Venture Catalysts In Tie-Up For Logistics Innovation Challenge

Next Post

Seoul Robotics debuts 3D plug-in with Milestone Systems XProtect

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
Seoul Robotics debuts 3D plug-in with Milestone Systems XProtect

Seoul Robotics debuts 3D plug-in with Milestone Systems XProtect

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Global Funeral Traditions Meet Technology

Global Funeral Traditions Meet Technology

March 9, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Recommended

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media