Government Update: Since the global coordinated ransomware attack on thousands of private and public sector organisations across dozens of countries on Friday, there have been no sustained new attacks of that kind. But it is important to understand that the way these attacks work means that compromises of machines and networks that have already occurred may not yet have been detected, and that existing infections from the malware can spread within networks.
This means that as a new working week begins it is likely, in the UK and elsewhere, that further cases of ransomware may come to light, possibly at a significant scale.
There have been attempts to attack organisations beyond the National Health Service. It is essential that any organisation that believes they may be affected follows and implements the following guidance. BEIS has set out two pieces of guidance: one for organisations and one for private individuals and SMEs which can be applicable regardless of the age of the software in question. Updates will also be released via @ncsc on Twitter.
There are a number of easy-to-implement defences against ransomware that considerably reduce the risk of attack and the impact of successful attacks. These simple steps to protect against ransomware are not being applied by either the public or organisations as thoroughly as they should be.
Three simple steps for companies to undertake, which are also set out on the following website (https://www.ncsc.gov.uk/guidance/protecting-your-organisation-ransomware) can be summarised as follows:
- Keep your organisation’s security software patches up to date
- Use proper anti-virus software services
- Most importantly for ransomware, back up the data that matters to you, because you can’t be held to ransom for data you hold somewhere else
Home users and small businesses can take the following steps to protect themselves:
- Run Windows Update
- Make sure your AntiVirus product is up to date and run a scan – If you don’t have one install one of the free trial versions from a reputable vendor
- If you have not done so before, this is a good time to think about backing important data up – You can’t be held to ransom if you’ve got the data somewhere else