Ransomware recovery is an identity problem too
Restoring the data is only part of it. If the attacker still holds valid credentials, they are back.
Recovery has to include rebuilding trust in identity: rotating credentials, revoking sessions and tickets, and in a directory compromise sometimes rebuilding the directory. Organisations that restore quickly without doing this get re-encrypted, occasionally within days.
More on Ransomware and malware
- Ransomware is often the last stage, not the firstThe bang is the end of the fuse
- Backups are ransomware targetsThe lifeboat goes first
- Lateral movement turns one foothold into manyAlong the loft, house to house
- Command and control gives malware an operatorSomebody is still holding the controller
- Persistence is about surviving changeStill there after the tide
- Living off the land reduces new-tool visibilityThey use your tools, not theirs
