Petya outbreak Why are cyber criminals successful in deploying a ransomware attack | Global Knowledge
Skip to main Content
Article

(Not)Petya outbreak: Why are cyber criminals successful in deploying a ransomware attack?

Global Knowledge

This week we have experienced again that cyber criminals can do much damage and that we are very vulnerable and exposed when it comes to the modern backbone of our society and organizations, namely IT. Just six weeks after the Wannacry Ransomware attack, many organizations across the globe are currently dealing with a second ransomware attack called (Not)Petya. I say ransomware attack, but there is some debate on whether this attack is actually designed as a Ransomware attack or just uses the ransomware aspect as a disguise to prevent the discovery of its real purpose.

Many companies that are infected by (Not)Petya are based in the Ukraine. However several companies in the Netherlands, Russia, France and Germany are also effected. It is expected that many more organizations and countries will follow, because of the way (Not)Petya spreads. But how do you prevent an infection with (Not)Petya in your organization?

How to prevent infection

The main questions for companies hit by (Not)Petya will be ‘where did my security fail?’  and ‘How do I prevent this in the future?’ Well the simple answer is that you haven’t updated your Windows computer yet. Many organizations still use computers and servers with operation systems that are no longer supported or do not deploy security updates in a timely manner; Leaving computers, networks and the entire organization vulnerable. Secondly, these organizations and their staff lack sufficient knowledge in how to do their work without creating a security risk. People do not know how to recognize risky email, incorrect and unsafe links an corrupt files. They haven’t learned what makes a situation a possible risk. They don’t know how to build their defence and in the case of an infection they often don’t know what actions to take in order to minimize damage.

Our advice would be to develop a well-structured Security and Data Privacy policy and train your employees to enhance their knowledge and make them aware of their responsibility in preventing these successful Ransomware attacks or any other cyber-attack towards your organisation.

 

10 reasons to consider a career in Cyber Security

Global Knowledge