Are you a member of the executive board or board of directors? Are you a decision maker, perhaps an IT manager in a private company or public authority? Then you may feel like 80% others in similar positions. You are worried about hacker attacks.
This article is for those who are well aware of the threat of cybercrime, but who may not be a technical specialist in the field and therefore rely on good input from others.
The Danish business community understands that the threat from hackers is imminent and serious for companies. However, the term ”hacker attack” is a very broad term for a number of different issues. This makes the topic complex, and for many business owners who don't specialize in IT themselves, it can feel overwhelming to have an opinion on everything and a solution for every problem.
As a CEO, you naturally trust that your company's IT manager or external IT provider is on top of things. And you've probably already spent a lot of resources on solutions like firewalls and antivirus software.
That should be good enough, right? Unfortunately, in our experience, it's often not enough.
Ransomware
One of the big threats when we talk about ”hacker attacks” is ransomware attacks. It has been growing rapidly for a number of years. These are attacks where hackers have gotten through firewalls and antivirus programs undetected. Perhaps a USB stick has been plugged into a PC in your company by someone you trust. That's all it takes. Unfortunately, it's easier than many people think. The hackers then snoop around your systems for an unknown period of time, typically a few weeks. After a few weeks, the attack breaks out and the encryption starts from the inside. Once the encryption starts from the inside, it's too late to rely on the usual IT solutions of firewalls and antivirus software, which are primarily designed to prevent such threats from getting in. Unfortunately, this means that the malware is typically also inside the company's backup. Therefore, the strategy of rolling out backups is no longer a very secure strategy. The attack simply starts all over again immediately after the backup is rolled out. Then you're in trouble.
Business shuts down for weeks or months
The result of a hacker attack in this form is that the business can't function for weeks, maybe months. This is very serious.
Whether you're a small or large business, whatever your industry, and whether you're a private company or a government agency, you're paralyzed. We've all seen large international corporations with huge IT budgets come under attack. We've also seen smaller smithies, law firms, finance companies, logistics and sales companies and foundations attacked. So it can happen to your business too. Just look your IT supplier in the eye and ask the question: ”are we protected against this, or could it happen to us?”.
Costs are exploding
Imagine you're looking at your computer screen telling you that you've been hacked and need to pay a ransom in bitcoin. By then, the cybercriminals have looked at your accounts and typically know what you can pay. The cleverest criminals have also copied all your sensitive data. It can be sold if you don't pay - or may be sold to competitors even if you pay the ransom - to get the encryption key.
This is when you're under pressure. So you call an IT consultancy and maybe a security company to negotiate a ransom on your behalf. It's expensive. Meanwhile, your own IT department is working around the clock. Often in vain. All other employees are either out of work because your entire digital platform is locked down, or struggling with pen and paper to keep the business running smoothly. A huge amount of typing awaits when you're up and running again.
You can't invoice your customers. You can't receive or pay your bills. Can your customers wait, or will they shop elsewhere when all this is over? Taken together, it adds up to a serious financial loss. But that's just the tip of the iceberg. Now there's a ransom to pay, and criminals never ask for small change. Days and weeks disappear while you work hard. The management and board hold crisis meetings at regular intervals. Insurance companies and maybe your bank get involved.
Destroying BIOS renders IT equipment worthless
Facts. Did you know that if you don't pay the ransom, you risk having to replace all the IT equipment in your company? The most modern and malicious ransomware attacks also target the BIOS (Basic Input Output System) of IT equipment. If the BIOS is destroyed, the IT equipment is worthless. Every laptop, every server and probably more - EVERYTHING has to be replaced. It's expensive. It takes time. Is it possible to get all that IT equipment at a time when so much is on backorder?
Naturally, the police advise against paying ransom. However, it is not a crime to do so. In reality, we believe that very few people want to pay, but many do anyway, both in Denmark and abroad. This is understandable in the serious situation you find yourself in. But paying the ransom (for the decryption key) also encourages criminals to continue their misdeeds and target others. They get what they came for - payment - and go about their ”business”.
No guarantee that the decryption key works
As a company, you have no guarantee that the decryption key provided to you will work, so your money is wasted and you are still stuck. Even if the key works, you still have at least two problems:
- Firstly, the criminals may still have a copy of your sensitive data. It's completely out of your control. They may promise they won't, but what is a criminal's word worth?
- Second. Even if you get a decryption key, you won't return to normal operations the next morning. It usually takes weeks to repair the damage that has been done. The costs continue.
This entire summarized process costs a lot of money, as most people can figure out.
”Luckily we are insured”
Are you now too? Very few insurance companies have products that cover all the costs involved in this situation. Many have been surprised by how little their insurance policies actually paid out.
In bad cases, only 10-20% of the actual costs, which can easily amount to millions of dollars. It can bring a business to its knees.
It takes a very thorough review of your business before an insurance company will cover your actual needs. Very few insurance companies have such a process before offering proper coverage.
Is cyber insurance enough?
It's not unheard of to be offered ”cyber insurance” presented on a ”one page PDF”. And it's typically cheap. That way, you can be confident that you're covered in the event of an accident.
We believe that several insurance companies are coming up with new products, but they are unsure of the scope, costs and what they need to do to help their customers, even if they want to - we have a few good suggestions for that too.
Want to avoid the above scare scenarios?
Stupid question. Fortunately, there is a solid Danish preventive solution that is definitely affordable.
As a reader, you've probably figured out that this article could end with a ”buy this” message, so let's just be honest about that part. But we also have something to say.
yourCompany consists primarily of former police and intelligence professionals. Our mission is to reduce fraud and deception in companies. Whether it's internal or external fraud, the result is the same. Companies suffer financial losses that affect their bottom line. We have been successfully fighting this since 2016 and our goal is for you to make or save money by using us.
Buy RC (RansomCare) from yourITdefence
YourCompany has been following the spread of ransomware attacks for years before we took this step. We have opened the subsidiary yourITdefence ApS, which together with the other companies in our family will reduce financial losses for companies and public authorities. The solution that wards off ransomware attacks is called RC and is a Danish piece of software.
RC is a last-line-of-defense tool. It does not replace any of your current security measures such as firewalls or antivirus programs. It is an essential complement.
Should you be unlucky enough to be targeted by a ransomware attack by a criminal hacker group, the RC software will intervene the moment encryption is initiated. It simply shuts down the affected computers and servers in seconds. This prevents the attack from spreading. The attack is stopped and only a few employees realize that you have been under attack.
Avoid the horror scenarios
So you can skip all the horror scenarios described in this article. Your IT department will automatically be notified of the scope of an ongoing attack that RC stopped even down to the file level. This makes GDPR reporting much easier and perhaps even unnecessary.
You can maintain normal operations or at least only have a very short downtime - unlike what would have happened if RC was not installed.
RC is installed centrally on your IT system without the purchase of additional hardware.
RC (RansomCare) installs in no time
It can be done online, so whether you're a small business in Næstved or Thisted or an international company with locations in several countries, the solution can be installed in no time. If you like us to come to you and install it, we are happy to do so. Installation is done in just a few days and you can be up and running in no time. Your decision-making process is probably the one that takes the longest.
RC is not expensive. On the other hand, it has a huge value for your business because it can save you a lot of costs, real losses and a lot of hassle. It contributes to a good night's sleep. It's a tool that prevents the accident. With 80% of business owners expecting to be affected in the coming year, perhaps choosing prevention is the right thing to do.
I'm interested in hearing more. What do I do?
It's simple. We have a 45-60 minute introduction where we tell you a little more about what the system can do and how it can help you. RC can be integrated into most systems and IT security setups, and our CTO, Morten Kliver, can tell you more about this.
Morten Kliver (CTO) can be contacted at:
Email: mk@yourcompany.dk or
Tel: +45 23 80 80 08.
You can also contact our main number +45 53 53 46 04 04 or info@yourcompany.dk
Link and source reference: Morning briefing: Four out of five companies expect to be hit by hacker attacks / Danish police: Don't pay ransomware extortion / FC Nordsjælland abused by cybercriminals in million-dollar fraud case - Computerworld