Part II. Protect
Building Your Defenses Before the Attack
The NIST Cybersecurity Framework’s Protect function is about implementing appropriate safeguards to ensure delivery of critical services and to limit or contain the impact of potential cybersecurity events. Now that you’ve identified the ransomware threat and your critical vulnerabilities, it’s time to build the defenses that will reduce your risk and minimize damage when attacks occur. We’re not trying to prevent every attack, but we are going to make attacks harder and easier to recover from.
Chapter 3, “Backup and Recovery Basics”, establishes the fundamental concepts you need to understand before securing your backup system.
Chapter 4, “Stop Most Ransomware”, covers the prevention basics that will stop most attacks before they start. We’ll tackle the table stakes (patching, multifactor authentication [MFA], password management) and comprehensive cyber hygiene.
Chapter 5, “Minimize the Blast Radius”, focuses on limiting how much damage ransomware can do if it gets in. We’ll harden endpoints, segment networks, lock down access controls, and protect data so that a ransomware attack doesn’t become a disaster.
Chapter 6, “Get Ready for Battle”, is where we secure your last line of defense: the backup system itself. We’ll talk about cyber professionals, forensic tools, and immutable storage. This chapter transforms your ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access