833-847-3280
Schedule a Call

The Wannacry Infection … not a problem if you practice cyber hygiene.

The Wannacry Infection: What it is

I am sure that, over the weekend, you were inundated with news about the latest worldwide, The Wannacry Infection, cyber attack, infecting hundreds of thousands of systems around the world. Encryption occurred in the files of the affected computers and servers. From a hacker’s perspective, the infection was a complete success, affecting major corporations, government agencies and business worldwide.

If you didn’t read too deeply, you would think that The Wannacry Infection was the end of the world. You would think that some secret NSA developed virus was taking over businesses, government entities and personal computers. You would think that there was no way to stop it. But a deeper dive into the infection demonstrates once again, why proper cyber and IT hygiene is critical in preventing such serious infections.

The Wannacry Infection: How it Works

The Wannacry Infection works by taking advantage of a flaw in older Microsoft operating systems. A hacking group called Shadow Brokers released the infection. They are allegedly tied to hacks that were stolen from the NSA. Regardless of its origin or the effectiveness of the hack, basic IT and cyber hygiene would have prevented these infections. Why? Microsoft released a fix in February. IT managers should have updated their IT systems.

Additionally, most Anti-Virus programs have the update contained in them as well, as a simple search will reveal. This infection could have been preventable if IT managers kept their operating systems updated.

How to Prevent

I don’t want to get on my soapbox again but, as proponents of businesses small and large, we have often stressed the most affordable ways to prevent hackers from gaining access and control of critical IT systems that are critical to the operations of any sized corporation. It is critical that stakeholders ensure that their IT managers are doing their jobs. There are ways to ensure that they are doing their jobs, one of them being vulnerability scanning.

Vulnerability Scans

A vulnerability scan is a very inexpensive way to get a look at your IT architecture and to determine how up-to-date and/or secure it is. By using a variety of open source or proprietary tools, a provider obtains access to your network (through your IT POC) and “scans” the network for missing updates, open ports and other areas where hackers may enter your network.

The reports are simple to read and demonstrate what vulnerabilities exist, allowing the business owner to make informed decisions and can determine if s/he is secure or not. Repeated scans offer the owner the ability to track the progress that their IT personnel are making on addressing these vulnerabilities.

Other areas where business owners and private citizens can increase their security:

Update and Update again: too often we ignore those “update” messages that come up on our computer. More importantly, when you see them, act.

Download File: This goes back to training and preventing your employees from clicking on those blue links of chaos that come in emails promising things that are just too good to be true (they aren’t). Ensure they are aware of simple social engineering approaches: changed email addresses, modified URLs, etc.

Use Anti-Virus Programs: AV programs usually get frowned upon. Most people rely on their computer firewalls to prevent viruses. AV programs are kept up-to-date. They usually include information from application and system providers on hacks that affect their programs.

Back up your system: Sometimes a business cannot control everyone that touches their IT systems and even the most rigorous training program will not prevent someone from downloading an infection. Back up your systems. Above all, store them off site and on a different system/server than the one your company operates on.

These simple tactics can help prevent such a calamity from affecting your business. Practice good IT and cyber hygiene and you have a stronger chance of surviving a global cyber-attack.

Latest Posts

A transparent image used for creating empty spaces in columns
There’s a moment in almost every scoping conversation where we ask something like, “Do you have a penetration test budget in mind?” And there’s a predictable pause on the other end. We understand why. The assumption most people make is that asking for a budget…
A transparent image used for creating empty spaces in columns
When clients schedule an internal network penetration test, one of the first questions we hear is some version of: “Can you do it after hours so it doesn’t disrupt anything?” It’s a reasonable instinct. The idea is that running a security test while employees are…
A transparent image used for creating empty spaces in columns
When something goes wrong with the internet connection, a printer won’t connect, or a new employee needs their laptop set up, you call your IT person. They fix it. Problem solved. It’s one of the more satisfying parts of running a business: having someone who…
A transparent image used for creating empty spaces in columns
There’s a story most small business owners tell themselves about cybersecurity. It goes something like this: hackers are out there targeting banks, hospitals, and major corporations. They’re after the big scores, millions of records, massive ransom payments, headline-grabbing breaches. A small business with 20 employees…
A transparent image used for creating empty spaces in columns
If you’ve purchased a cyber insurance policy, you’ve probably done something most small business owners haven’t. You recognized that a cyberattack is a real business risk, you did something about it, and now you have a document that says you’re covered. That peace of mind…
A transparent image used for creating empty spaces in columns
Let’s be honest about something that doesn’t get said often enough in polite compliance conversations: the healthcare industry has been getting away with inadequate data security for a very long time. Patients hand over their most sensitive personal information every time they walk through a…
contact

Our Team

This field is for validation purposes and should be left unchanged.
Name(Required)
On Load
Where? .serviceMM
What? Mega Menu: Services