ESET: As modern business increasingly relies on digital technology, and with the incidence of cyberattacks constantly increasing, protecting corporate data becomes even more important.
Denise Giusto Bilić, Security Researcher at ESET, advises companies and organizations that have been attacked to follow five key steps so they can protect their important assets.
Step 1: Determine the extent of the infection.
Companies that have been attacked often rely on their intuition to assess the situation, rather than a thorough examination of the problem. If the company has invested in developing robust emergency management systems, it is possible to quickly gather evidence that will lead to sound assessments, in order to investigate the first important questions: which systems have been compromised and how? Is the infection limited to a single part of the network? Has data been leaked? Are we talking about corporate data or personal data about employees and/or customers?
Step 2: Ensure business continuity.
In the event of a leak of information that may endanger employees or customers, it is first necessary to inform and warn them. If the company has taken care of backup copies of its files, and already has an action plan, it can immediately return to its normal pace of serving its customers.
Step 3: Contain the infection.
Initially, the compromised equipment and/or network segment should be isolated. If it is determined that the communications used for the attack are encrypted, the keys should be identified using reverse engineering techniques, while if the communication is carried out in non-confidential protocols such as HTTP, identifying the commands used by the attacker will be easier. In both cases, the goal is to create firewall rules to quickly create a first line of defense. The extent to which the company has invested in proactive threat detection and detection mechanisms, and uses a comprehensive security solution, will determine its ability to respond to this critical phase.
Step 4: Eliminate the infection and attack.
Removing malicious code is a complex process. The first stage involves detailed analysis of the code to understand how it works, which antivirus solutions do automatically, saving valuable time in the response process. It is important to remove any malicious remnants and remove the vulnerability from which the attack was launched, strengthen the process of analyzing packets transmitted over the network, review firewall settings, change passwords on corporate networks and update keys. At this point, it is worth determining whether the infection was the result of simple carelessness or part of a targeted series of attacks.
Step 5: Learn from any mistakes.
A thorough investigation into what happened can be a catalyst for improving processes within the company. Removing any previously unknown vulnerabilities is an opportunity to identify other vulnerabilities and strengthen defenses. It will also reveal elements of the system design that need to be strengthened, and it will uncover weaknesses in the current defenses so that a stronger one can be designed.
