Part I. Identify
Understanding the Threat Landscape and Your Critical Assets
We wrote this book around the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 because it’s one of the most practical, widely adopted approaches to cybersecurity that exists. The framework organizes cybersecurity activities into five functions: Identify, Protect, Detect, Respond, and Recover. Each function addresses a critical aspect of managing cybersecurity risk, and together they provide a complete lifecycle for defending against threats like ransomware.
This is the first section: Identify. You can’t defend against threats you don’t understand, and you can’t protect assets whose vulnerabilities you haven’t recognized. That’s what Identify is all about—developing the organizational understanding you need to manage cybersecurity risk to your systems, people, assets, data, and capabilities.
For ransomware defense, identification starts with two critical questions: What exactly are we up against? And what are our most vulnerable assets?
Chapter 1, “What Is Ransomware?”, answers the first question by breaking down the ransomware threat landscape. You’ll understand what ransomware actually is, how it’s evolved from simple encryption to sophisticated double-extortion campaigns, who the attackers are, and—most importantly—how attacks unfold from initial reconnaissance through ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access