Chapter 4. Stop Most Ransomware
This book takes an “assume breach” stance because we’re realists: some ransomware attacks will get through. But here’s the thing—“some” is a lot better than “all.” Let’s talk about doing what we can to stop ransomware in the first place.
Most ransomware attacks succeed because organizations fail at basic cyber hygiene: they don’t patch systems, they don’t enable multifactor authentication, and they ignore password management. If you implement the measures in this chapter, you should stop almost all ransomware. Most attacks would never become the crisis scenarios we’ll prepare for in other chapters.
So yes, this chapter is a departure from our assume-breach philosophy—but it’s a necessary one. Prevention doesn’t contradict preparation; it complements it. Every attack you stop is one less incident your team has to respond to, one less backup you have to restore, one less ransom demand you have to consider. Prevention reduces the frequency and severity of the breaches we’re assuming will happen.
Think of it this way: Your car has brakes AND airbags. You assume you might get in an accident (that’s the airbag), but you also have brakes to prevent running into other cars. This chapter gives you some brakes. The rest of the book is your airbag, crumple zones, and emergency glass breaker.
We’ll cover proactive cybersecurity measures like vulnerability management and system hardening, and employee training that turns your people into a defensive asset rather ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access