본문으로 건너뛰기

Why ransomware is no match for a Zero Trust architecture

a person handing over a paper to be signed by another person
Contents

이 페이지 공유하기

Jason Blosil Author Photo
Jason Blosil
224 조회수

As the fastest-growing cybercrime, ransomware is expected to attack every 2 seconds and cost $265 billion in damages annually by 2031. At this rate, it’s just a matter of when you will be the next victim. How do you stop fast-moving ransomware in its tracks—or at least slow it down so that the damage is minimal?

It’s a matter of trust: Zero Trust principles

In the past, the biggest hurdle that hackers faced was getting past your security perimeter to access your data. But with a booming illegal market full of stolen credentials for purchase, the job is getting easier for cybercriminals. In fact, attackers are now more likely to use stolen credentials than malware, with more than 60% of data breaches involving the use of stolen credentials to slide past security barriers. An example is the famous Colonial Pipeline attack, which crippled fuel supplies in the eastern United States. Security analysts suspect that the group responsible for the attack purchased stolen credentials on the dark web.

After attackers gain access to a company’s network, they usually spend time poking around to find just the right data to take hostage. The more critical the data, the more ransom it will bring. Attackers then (typically) encrypt the high-value data and exfiltrate it (and possibly even publish it on a public website). They then use this stolen data to negotiate ransom payment.

So, how can you put up your guard against these cybercriminals? A Zero Trust architecture can address every phase of a ransomware attack and stop attackers in their tracks. Here’s how.

Zero Trust architecture: Continuous verification

Traditional security solutions require a user name and password for you to access internal networks. After you’re inside, it trusts that you are who you say you are by default, and you’re free to roam. A Zero Trust architecture assumes nothing and requires verification every time that system or information access is requested—even if you’re already past the security perimeter and behind the company firewall. If user access appears to be suspicious, the user is immediately blocked and IT security teams are notified so that they can further investigate.

Zero Trust architecture: Data segmentation

If an attacker does make it through the firewall, Zero Trust architectures offer another layer of protection by segmenting data and by applying “least privilege” rules for access. Typically, after a user gets past the firewall, they have full access to the entire network. This freedom gives attackers full access to all your data—they just have to look around to find the most critical files.

With Zero Trust, data is segmented into smaller buckets, and users are given access to the least amount of data that they need to do their job. This approach severely limits the amount of damage that an intruder can do because the pool of data that they can see and access is much smaller. And because you know exactly what data was compromised, it’s also easier to recover if a ransomware attack is successful.

Zero Trust architecture: continuous monitoring

A Zero Trust architecture offers centralized monitoring and management. Continuous monitoring with a single-pane view of your data environment makes it easier to identify anomalies in user behavior so that you can act instantly to prevent data loss. For example, the monitoring software sends an alert to notify you that a particular user is attempting to access data that’s not related to their job function. Or that a user is attempting to delete a large number of files. With the right technology in place, the Zero Trust architecture automatically blocks the user in question as soon as the unusual behavior is detected. It also makes a copy of the data at that point in time so that you have a current backup to restore if the attacker’s attempts are successful.

Build up your own defense against ransomware

With the speed and ferocity at which ransomware is growing, a Zero Trust architecture is a necessity in the fight against cybercrime. If you’re ready to start building your own Zero Trust architecture, check out NetApp® cyber-resilience and ransomware protection solutions. You will see how a data-centric approach to security can help you protect, detect, and recover if ransomware strikes your business.

Jason Blosil Author Photo

Jason Blosil

Jason은 20년이 넘는 제품 마케팅, 제품 관리 및 기업 재무 경험을 보유한 비즈니스 및 마케팅 전문가입니다. 2008년 NetApp에 합류한 이후 SAN 및 NAS 스토리지, 백업 및 재해 복구 솔루션, 클라우드 데이터 서비스에 주력하고 있습니다. 여가 시간에는 사이클링이나 요리를 하거나 가족과 함께 시간을 즐기며 교회와 지역사회에서 자원봉사를 합니다.Jason Blosil의 모든 게시물 보기

다음 단계

Why ransomware is no match for a Zero Trust architecture