Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Thursday, 26 May 2016

CERT-UK identify massive increase in new releases of ransomware in last 8 months

Between January 2012 and October 2015 there were 33 new releases of ransomware.

In the last 8 month this figure has jumped to 70 showing the rapid rise of pre-packaged off the shelf tools for hackers.

Ransomware delivers a virus into a system (often via a phishing email) which locks the system up totally and destroys data unless a ransom is paid within an agreed period.

The only realistic defence against this is regular offline backups of material to a secure location.

Law enforcement agencies such as the Met Police and City of London Police strongly advise against the payment of ransoms.

Tuesday, 17 May 2016

Cert-UK publish data for 2015-16 - cyber incidents increase by 85% in 12 months

Cert-UK has released data recently which paints a picture of rapidly growing cyber crime combined with the increased popularity of easy to use "off the shelf" hacking tools.

As you can see malicious code makes up the lions share of reported incidents with a further breakdown below of the types of malware that are proving the most common.

Cyber data released recently shows variations and the NTT report released at the end of April 2016 showed a decrease in DDoS attacks while Cert-UK has seen that number increase.

Taking a helicopter view what is clear is that as hacking and cyber attack becomes de-skilled the volume of attacks is rapidly increasing.

Cert-UK saw the greatest increase in Phishing as a form of attack and predicted that in 2016 Ransomware would dominate. In addition there is a very high probability of a major cyber attack on national infrastructure.

IT departments often bamboozle their line managers in respect of the security or otherwise of their systems and processes - especially if the line managers are not digital natives.

In fairness to IT departments many of the core risks are entirely people related and have no technical aspect to them but either way the knowledge that most internet connected IT systems are extremely vulnerable in spite of the machine that goes "ping", is reaching a much broader audience.