Zero Trust: The ransomware scourge is not new, but in recent months there has been a spate of new attacks on city governments. A case in point is Baltimore, which faced a lengthy system outage in May and June after refusing to pay the ransom. The attack cost a total of $18 million in both recovery and defense upgrades.

While the FBI recently said it doesn't have enough evidence to suggest that one sector is being targeted more than another, attacks on municipalities are often more visible because they can't be resolved quietly like in the private sector — they create chaos for citizens by disrupting payments, and licensing systems, and require taxpayer funding for repair and recovery.
Municipalities also tend to be more vulnerable than large businesses because they often have limited technology budgets, poorly managed online security often characterized by outdated and unpatched systems, and a lack of cybersecurity expertise tasked with managing challenges or resolving issues. These reasons create challenges that leave small and medium-sized cities vulnerable to cybercriminals and other hostile states.

IoT destroying us?
Some of the key steps to take to combat ransomware include network segmentation, which is still one of the best ways to prevent malware infection.
In fact, micro-distribution is even more critical as the number of IoT connected to networks increases, creating more new potential vulnerabilities as attacks can scale.
The IoT challenge is most evident in the healthcare industry. Like municipalities, healthcare organizations have become significant targets of ransomware attacks in recent years. Many hospitals use a wide range of new and legacy technologies, and employees often don’t know what systems are running on the medical devices they use, have no information about security protocols or recommended security upgrades, and wouldn’t recognize if a device they’re using has been compromised.
Smaller hospitals, especially those in rural areas, may not have the awareness or resources to hire cybersecurity staff or update their systems. While hospitals are extremely focused on protecting the confidentiality of patient health data, they often pay less attention to the security of medical devices that do not contain patient information.
Addressing the rapidly evolving threat environment is becoming an increasingly difficult task, given the explosive growth of IoT and the impending future of 5G.

Be Proactive – Switch to Zero Trust
For decades, the internet operated under a hypothetical trust model, where you are presumed to be who you say you are until proven otherwise. Given the current reality and the fact that cyber threats will continue to overcome defenses, any organization that continues to operate under this model risks the security of its data and networks.
By moving towards a Zero Trust model that incorporates micro-distribution, municipalities and hospitals can create a much more difficult environment for hackers. A zero trust architecture requires authorization for any person or device attempting to connect to a network or access network resources, even for users already within the network perimeter. Every entity attempting a network connection must be authenticated before the connection is completed, and once access is authorized ,that identity must be used to further control access to critical servers and data.
As IoT and mobile devices increase the likelihood of attack, leading to an increased proliferation of ransomware attacks and other cyber threats, organizations must ensure that a single infected system cannot compromise all the others. Implementing identity-assured segmentation to achieve a zero-trust network environment will help cities and hospitals defeat these attacks – and significantly reduce the risk of having to make a costly ransom payment or initiate a massive system recovery and rebuild.
