White Paper - Crypto Virus A guide to protecting your IT
Contents What is Crypto Virus?... 3 How to protect yourself from Crypto Virus?... 3 Antivirus or Managed Agents... 3 Enhanced Email Services & Extra Scanning Tools... 3 Internal Email Servers vs Hosted Email Servers... 4 3 rd Party Hosted Email Security Solution... 4 Prevention is Key: Training... 4 Patched, Updated & Secured.... 5 Backups, Backups, Backups!... 5 What to do if you are infected?... 5 Page 2 of 5
What is Crypto Virus? Crypto Virus is a powerful, well-designed malicious software which is constantly updated and changed. It is designed by pirates to encrypt data which can only be decrypted after you pay them a ransom. This is where Crypto Virus is unique, the creators of the malware have created a full business model around the infection, and have kept honorable in providing the decryption key where ransoms are paid. Crypto Virus has been around for a number of years now, and shows no signs of going away or its development ceasing; and as such is an ongoing and serious threat. In a world where big company hacks headline every month and Australia alone is hit for $1.65 Billion in cybercrime each year (and climbing), businesses really need to pay attention to the darker side of IT. How to protect yourself from Crypto Virus? There is no silver bullet to protect yourself from Crypto Virus, and this is mainly due to it getting ongoing updates to its software; thus constantly shifting the way standard defenses need to protect your systems from the virus. Antivirus or Managed Agents Antivirus or managed agents may seem like a logical fix to fully protect yourself but not all antivirus are made equal. Nor do they automatically protect against all threats. When a new virus is released or a new version of a virus is released antivirus software needs to be taught how to fight against it. This is done by engineers who learn how a virus works and how to disable malicious software; then giving those moves to the antivirus software via means of definition updates. It is for this reason that by default Tropical Business Solutions own antivirus product, Managed Agent, has updates pushed to it every 3 hours to ensure the very latest defense against threats on the internet. Even this is not fail-proof. After a new virus is released into the wild, learning how they work can take days or even weeks; during which time you can be vulnerable regardless of the antivirus software you use. There is a quality of antivirus software to consider as well an example is the inbuilt Microsoft antivirus that comes with Windows. When compared to other free and paid antivirus products is one of the worst software s on the market for actually protecting your computer. The Tropical Managed Agent (with Antivirus in built) by comparison was one of the first software s on the market that we saw actually disable iterations of the Crypto Virus itself, a fact we are pretty proud of. As standard practice however you should always scan all files you open on disks, USB drives or downloaded from the internet. Antivirus is still a good line of defense to keep protected; but it should no longer be your only one. Enhanced Email Services & Extra Scanning Tools Email is one of the more common ways for a system to become infected and for whole offices to have downtime from virus infections. This is also true of the Crypto Virus as it is designed to copy itself and encrypt files on network shared drives as well as local computers; which can stop work dead in a business. To make emails a safer place there are a few key things to consider; Page 3 of 5
Internal Email Servers vs Hosted Email Servers In-house email is a great solution for some business, however in some cases hosted solutions may be better. This can be for a number of reasons such as cheaper server licenses, increased reliability (data center level uptime), but in this context; protection, better screening of viruses. The thing about hosted email solutions is that A LOT more money and effort can be spent on that solution then a small business email server in their office. Because of this you have many MANY different levels of scanning technology directed at your emails to determine if they should be blocked and deleted or approved to be forwarded to your computer. Tropical Business Solutions Cloud Email is no different and has a pretty good track record of keeping clients safe. 3 rd Party Hosted Email Security Solution If you prefer to have your email in house, or the business case dictates you must have it locally housed; or even if you want further protection over your other 3 rd party hosted email there are products that allow you to push your emails over a moat of sorts which checks emails before they hit your email server; to gain the same benefits of protection that hosted email solutions have. Tropical Business Solutions also has a product like this called Tropical Cloud Mail Protection, which even works with other mail servers (such as google mail or office 365), and has added benefits like being able to act as your mail server at times when your own server or service is offline; which can be very handy. Prevention is Key: Training As with most things; training is key. By teaching your staff to practice techniques below you can save a lot of money, downtime and heartache; Don t download or open ANY unknown attachments in an email. This is especially true if it is from someone you don t know. Don t click on emails links for sites and companies that normally wouldn t send you links. I.e. banks rarely send mass emails, nor does the ATO. If you hover your mouse over a link in outlook the actual URL of an address will show up if you are unsure; make sure the domain is what you would expect it to be before clicking it if you need too. Always keep your antivirus updated (with Tropical Managed Agents this happens automatically as long as you are connected to the internet). Turn off Macros in Microsoft Office Word, Excel & PowerPoint as they can be used as an entry point to your computer. If you copy a file from a USB drive or CD, scan it first to make sure it doesn t have a virus on it. Only copy files from media sources you trust Don t go to websites that have a shady reputation (file sharing sites, adult content, etc), browsing too deep into search engine results & ignore scareware popup windows. These web pages have a reputation for being a big source of virus infections. (The Tropical Managed Agent does have an add on that can be enabled for web security; which checks the known reputation of a website, scans for viruses, and can even block based on the category of a website (i.e. adult, illegal, etc.). You can also get corporate internet usage information from the tool as well). If your computer starts to behave in a way you wouldn t expect contact tech support ASAP. Page 4 of 5
Patched, Updated & Secured. Windows and other software updates can be annoying (BELIEVE US, we know!), but they serve a critical purpose in the protection of your computer. Updates fix holes or vulnerabilities that hackers and viruses take advantage of to damage computers or steal data. Software companies like Microsoft keep an eye on this and as they find their software being taken advantage of, release fixes to counter the potential attacks to ensure you are able to work on a safer platform. This is obviously never a done thing especially with Crypto virus, as the bad guys keep working to find ways in; so regular updates really are a must for your computers. It should be noted here that our Tropical Managed Agent is a great tool to automate the majority of update deployments for all the big companies software such as Adobe, Microsoft, etc. Backups, Backups, Backups! Backups are our last line of defense. If everything else fails recovery from backups may be your only bet, so regular offsite backups are critical to ensure that no matter what you still will have data. There are a few different flavors of backups now; Your more traditional backup to USB hard drive option. This is good but does require a staff member to manually swap out hard drives and take offsite to ensure backups occur. Software can be used to automate the actual backup of data overnight however. Cloud Backups have become a lot more popular in recent years (which Tropical Cloud Backup is a very good example of). This automates backups so no human interaction is required. This occurs live (as files are changed) or at regular intervals throughout the day and sends all data offsite over the internet. What to do if you are infected? If your computer is infected with Crypto Virus - or any virus, your best bet is to disconnect it from the internet & network immediately and shutdown. Crypto Virus especially is known for encrypting files not only on a local computer but on other computers on the network as well via network shares which means servers can be at risk too. It is also a common practice for a lot of different viruses to attempt and replicate themselves onto other computers on a local network and over the internet; which is why disconnecting is very important. Shutting down the computers and awaiting a tech to come and look at the machine can help prevent damage to files on the computer; especially in the encryption phase; and help keeping your down time to a minimum. Depending on the severity of the issue, a decision will be made to either fresh install or repair your computer to achieve the best outcome. Don t forget our helpdesk is able to support at a moment s notice: 08 8922 0000 or help@tropicalbusiness.com.au Note: Commercial in Confidence Information. This document, including any associated elements, documents or files; remain the intellectual property of Tropical Business Solutions Pty Ltd. Any information contained within this document should be considered privileged and confidential; and should not be used for any purpose other than the sole purpose for which you received it. Disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited, unless approved in writing by Tropical Business Solutions Pty Ltd. If you have any further questions regarding the above statement, please email help@tropicalbusiness.com.au for more information. Page 5 of 5