Ransomware Response Checklist: Prevent It, Slow It, Survive It
This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack.
This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back.
Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one.
They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact.
Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from.
Chapter Markers:
00:00 – Encore intro & episode setup
00:01:37 – Show intro and banter
00:06:21 – Preventing the breach: phishing, droppers, and whitelisting
00:14:46 – Blocking lateral movement, RDP/SSH lockdown
00:20:28 – Detecting exfiltration and honeypot files
00:24:19 – What to do once you've been hit
00:25:58 – Building your incident response plan
00:30:43 – Decryption, ransom payments, and why it's not over yet
Welcome to another encore episode of the Backup Wrap-Up.
Speaker:This very popular episode looks at a three-part series of Reddit posts
Speaker:from a security specialist who finally agreed to write about ransomware after
Speaker:a bunch of people asked him to do that.
Speaker:What he put together ends up being a full ransomware response checklist,
Speaker:how to stop it from getting in in the first place, how to keep it from
Speaker:spreading once it does get in, and what to do if you actually get hit.
Speaker:This is, uh, exactly the process that we built into my latest
Speaker:book, Ransomware Response and Recovery, which is now available.
Speaker:If you've ever wondered whether your organization has the right pieces
Speaker:in place before, during, and after a ransomware attack, I think you'll
Speaker:get a lot of value from this episode.
Speaker:By the way, if this is your first time watching or listening to me, I'm W.
Speaker:Curtis Preston, AKA Mr. Backup.
Speaker:I've been obsessing over backup, recovery, and now cyber recovery for over 30 years.
Speaker:If that's your bag, then I'm your guy.
Speaker:You're not gonna find anyone more, uh, interested in backup than me.
Speaker:Ever since 1993 when I had to tell my boss that there were no backups of
Speaker:the database that we had just lost.
Speaker:Now I've written five O'Reilly books, a blog, and a podcast.
Speaker:Here, we turn unappreciated admins into cyber recovery heroes.
Speaker:This is the Backup Wrap-Up.
Speaker:Hi and welcome to Backup Central's podcast.
Speaker:I'm your host, W. Curtis Preston, AKA Mr. Backup.
Speaker:And I have with me, my delayed shipment consultant, Prasanna Malaiyandi.
Speaker:How's it going , Prasanna?
Speaker:I'm good.
Speaker:Curtis, wait, what's delayed.
Speaker:my, my, my flooring shipment, and I turn to you for.
Speaker:what I thought you received one.
Speaker:I did, but . I ordered a big shipment of flooring, and then I ordered
Speaker:a much smaller shipment and I did that in two shipments because I
Speaker:couldn't order all of it at once.
Speaker:And then I had to order like another 10% and the second shipment I received the
Speaker:second shipment like three weeks ago, I still haven't received the first shipment.
Speaker:And, I just turned to you for, you know, emotional support in this time of.
Speaker:Ridiculousness I'm not doing anything until the entire shipment
Speaker:comes in., it's just ridiculous.
Speaker:Maybe they ran out of
Speaker:the raw stuff.
Speaker:Yeah.
Speaker:Whatever.
Speaker:So this is why you're here.
Speaker:You're here to make me not so angry.
Speaker:That's why I said you're my delayed shipment consultant.
Speaker:All I know is it's not in my hot little hands and I'm not doing squat in my
Speaker:garage until I get the entire shipment.
Speaker:Just think though.
Speaker:How about delayed gratification?
Speaker:Once you finally get the
Speaker:Oh, This is the ultimate in delayed gratification.
Speaker:I've never had so much trouble spending money in my life.
Speaker:You're annoyed.
Speaker:it'll be
Speaker:#firstworldproblems.
Speaker:Take a deep breath.
Speaker:Yeah, good times.
Speaker:Good times.
Speaker:Rate us at ratethispodcast.com/restore, or just click on your favorite pod catcher.
Speaker:And, uh, click down to the bottom and give us some stars, or maybe even a comment.
Speaker:Talk about how much you love Prasanna's beard.
Speaker:I'm good with that.
Speaker:And how it's so much longer and darker than mine and.
Speaker:So I see.
Speaker:I sent you this post that I saw on Reddit, which it's well, it's
Speaker:actually a series of three posts from a Reddit user called snorkel42.
Speaker:Don't let his, snorkeling ID fool you the person knows what they're talking about.
Speaker:Yep.
Speaker:don't know.
Speaker:I don't know anything about this person.
Speaker:Other than that, they have, they post regularly in a subreddit
Speaker:called security cadence.
Speaker:but he also posted he or she, I don't know if I mistaken
Speaker:mistakenly called the person.
Speaker:He, I apologize in advance for my misogeny,
Speaker:The, it was about ransomware and they are a specialist in the areas
Speaker:of security and many people had asked them to post stuff about ransomware
Speaker:and they had continually said, I don't want to post about ransomware.
Speaker:And can you imagine why that would be
Speaker:You're just propagate well, it's ransomware you get hit with, because
Speaker:there were a bunch of gaps before ransomware got hit and it's better
Speaker:to address the problem than trying to
Speaker:right.
Speaker:sort of the outcome.
Speaker:Yeah.
Speaker:So ransomware to this person is the symptom of a whole lot of bad things
Speaker:that you were already doing or not doing.
Speaker:And they've spent their career helping to make sure you do those things.
Speaker:But with the, I think two things, one is that obviously the ransomware attacks are
Speaker:getting to a fever pitch and then two.
Speaker:There is what we talked about on the previous episode, which was this concern
Speaker:about Russia and D w we did cover that.
Speaker:Didn't
Speaker:we?
Speaker:Yeah, we cover the Conti ransomware gang
Speaker:Yeah.
Speaker:Yeah.
Speaker:of the previous
Speaker:yeah, the Krebs on security post.
Speaker:Yep.
Speaker:That the concern is that the level of the fever pitch that we're experiencing
Speaker:might actually go through the roof.
Speaker:And so they said, Hey, I'm gonna finally, I'm fine.
Speaker:I'll post about ransomware, but even in their post about ransomware, it
Speaker:really wasn't that much about ransomware as much as it was about the things.
Speaker:no, that's not true.
Speaker:I'll take that back.
Speaker:it was here is the way ransomware works.
Speaker:And so I'd say the first one, I'd say of the three series,
Speaker:Yeah.
Speaker:The first one was about here's how to prevent it.
Speaker:Number one, like from getting in.
Speaker:The second was here's how to prevent it from doing more damage once it's in.
Speaker:And then the third one, it was okay.
Speaker:All right.
Speaker:You're totally screwed.
Speaker:You've got to reach for your backups.
Speaker:So that
Speaker:The one thing I would add to that is he also was careful saying, I
Speaker:don't want to just focus on the Conti ransomware and provide you steps to
Speaker:prevent that because there are so many other ransomware flavors out there.
Speaker:If you build something for just one.
Speaker:You're not going to be protecting yourself.
Speaker:Let's take a holistic approach.
Speaker:And like you said, let's
Speaker:good point.
Speaker:you prevent it from getting in?
Speaker:What, how do you prevent the spread of it?
Speaker:And then how do you recover?
Speaker:Yeah.
Speaker:Good point.
Speaker:The first one is called breach, I think is how he titled the first article.
Speaker:Right.
Speaker:So the phishing basically, they're saying that that is the number
Speaker:one way that you get ransomware.
Speaker:Yep.
Speaker:Someone accidentally clicking an email, opening up something,
Speaker:letting the attackers in, and they don't even know about it.
Speaker:So do you prevent your users from clicking on malicious links?
Speaker:now, it's interesting.
Speaker:This goes, yeah.
Speaker:Sorry.
Speaker:This goes somewhat against what, some of the advice of one of the
Speaker:guests that we had on the podcast, which was, they basically said,
Speaker:look, your people are going to click on stuff, stop relying on, I dunno.
Speaker:I dunno if it's against, but de-prioritized training and
Speaker:Yeah.
Speaker:phishing assessments, didn't you think.
Speaker:Yeah.
Speaker:So.
Speaker:This author does say can only help you so much?
Speaker:I think the couple things though, that he did mention is, you do need some level of
Speaker:training, but you need to make sure people don't feel like they're being punished.
Speaker:they do the wrong thing, right?
Speaker:You want that transparency.
Speaker:You want to be telling people it's okay for you to say that I clicked
Speaker:the wrong thing because then the IT team can try to evaluate what's
Speaker:going on and try to contain it.
Speaker:sooner they know the
Speaker:right.
Speaker:if say someone's afraid because they're going to get in trouble.
Speaker:They might be fired, It becomes taboo then no one's going to report it.
Speaker:And that's actually really bad.
Speaker:Yeah.
Speaker:they said to prioritize rewarding over punishment.
Speaker:make it known.
Speaker:Like you said, that it's okay to call in.
Speaker:We want you to call in, even if you messed up and then, and they also said consider
Speaker:doing your own phishing assessments.
Speaker:I read some of the comments and they talked about
Speaker:that.
Speaker:They had a thing where you got some.
Speaker:You got some, it was some strikes and it was like 10 strikes.
Speaker:It was like, you could click on 10 malicious emails.
Speaker:And, and then it was the 10th.
Speaker:When, and that they actually had a series of escalations where, it started
Speaker:out, Hey, we really told you thing.
Speaker:I think you can do both.
Speaker:I think you can do both carrot and stick, Reward and punishment where yes.
Speaker:You want to reward people for calling in.
Speaker:Thank you for calling, I accidentally clicked . And then if the person
Speaker:clicks doesn't know, because you did a phishing assessment, you do
Speaker:a series of escalating things where that ultimately you can have a person.
Speaker:And this was discussed in the comments, not necessarily that you
Speaker:would fire somebody that, that keeps doing this, but you might say, okay,
Speaker:this person cannot be trusted with a straight internet connection.
Speaker:Yup.
Speaker:All email from this person will be monitored.
Speaker:Yeah.
Speaker:They can only open email that's straight from our Exchange server
Speaker:or whatever stuff like that.
Speaker:So phishing was sort of one way that people get in.
Speaker:But I think once they're in whichever mechanism it is, it's okay, how
Speaker:do you detect that someone's in?
Speaker:And I think Curtis, this is what you're going to say,
Speaker:About this notion of droppers.
Speaker:Yeah, I actually didn't know this part.
Speaker:That's I was fascinated that basically that the actual phishing results in a very
Speaker:small piece of software whose job it is to install the actual piece of software
Speaker:Yeah.
Speaker:and that he calls out a dropper.
Speaker:Yep.
Speaker:and so the idea is understand that's the way it works, that a piece of
Speaker:code gets dropped in, and then that piece of code executes, and the only
Speaker:purpose of that piece of code is to download the other piece of code.
Speaker:And so they said that you could stop that.
Speaker:You could say, you can't run arbitrary pieces of code
Speaker:Yep.
Speaker:in locations that are directly accessible by the end user, you know,
Speaker:Or you could restrict
Speaker:and
Speaker:are allowed to run on a laptop for instance,
Speaker:yes,
Speaker:Whitelisting, I think whitelisting is it, I think it's the, the best.
Speaker:The best way to stop stuff like this.
Speaker:It's also the highest touch because it means that every new
Speaker:application that anybody has to install, they have to get approval.
Speaker:Yep.
Speaker:think it's a way to guarantee legitimate applications have gone through some sort
Speaker:of validation process, security review, et cetera, before it's being allowed
Speaker:to be deployed in your environment
Speaker:And then the next thing it talked about was that a random file running should
Speaker:not be downloading files from the internet, That it should only be HTTP and
Speaker:HTTPS is downloading from the internet.
Speaker:And He said with exceptions, SFTP for example.
Speaker:So he talked about, again, accessing that also possibly blocking bizarre TLDs right.
Speaker:And unnecessary locations.
Speaker:You could just simply say, listen, we don't have anything to do with Russia.
Speaker:Why would we download anything from Russia?
Speaker:And if there is somebody in our company that needs to download stuff
Speaker:from Russia, they will be accepted.
Speaker:That was a very running theme I heard was lock down everything and allow exceptions.
Speaker:Yeah.
Speaker:And, it was going to bring up two things.
Speaker:One was what's a TLD for our listeners?
Speaker:Oh, top level domain.
Speaker:That's like.com or dot ransomware.
Speaker:There is no dot
Speaker:ransomware,
Speaker:but.
Speaker:And was it you, or was it one of our guests who were, who was talking about
Speaker:how they worked at a company that completely locked down their network
Speaker:and the network admin would never let them do their backups and everything
Speaker:no, that was me.
Speaker:Okay.
Speaker:was me.
Speaker:Yeah.
Speaker:Yeah.
Speaker:that was, I was a client of mine where they had internal firewalls and that's an
Speaker:example of, going to the extreme of, now you're preventing core business functions,
Speaker:Yeah,
Speaker:right?
Speaker:but
Speaker:they also talked about local firewalls, Which is what we were just talking
Speaker:about, that the, and we're going to get to that more in the next section is,
Speaker:so they're just looking, he's looking
Speaker:for ways to stop the dropper from getting yeah, exactly.
Speaker:Yeah.
Speaker:thought was an interesting point I'd never thought about is he does have a point
Speaker:about they block newly created domains.
Speaker:Which I thought that had been dormant for a while and then are now active,
Speaker:which I thought was very interesting because it's something I had never
Speaker:thought about, but it totally makes sense.
Speaker:Usually when you get ransomware, These actors, they spin up domains and they
Speaker:start communicating, using that domain.
Speaker:So yeah, you could have a policy to just block these domains.
Speaker:So they can't actually reach back out to the
Speaker:Right.
Speaker:to be able to download from the dropper, the actual exploit.
Speaker:code
Speaker:Right.
Speaker:And, and they said they weren't aware of anything.
Speaker:Where that you can do this for free, but there are tools that are
Speaker:available to help you do This right.
Speaker:There's
Speaker:remember, what are the D D.
Speaker:what were the initials?
Speaker:The DNS
Speaker:DDI.
Speaker:yeah, And I think that goes to some of that as well.
Speaker:Where it's like, Hey, if you have some of those controls in place, can now
Speaker:prevent unauthorized access to domains.
Speaker:They should not be having access to.
Speaker:Exactly.
Speaker:And then they started talking about preventing lateral movement inside.
Speaker:Think about the ways that people need to move within your organization and
Speaker:allow that, but block all other movement, Lateral movement between servers and I
Speaker:think, again, going back to that company, that was a perfect example of, they had
Speaker:blocked all lateral movement between all servers and I couldn't get my job done.
Speaker:They're only problem w and they should have done that.
Speaker:And, they were forward thinking in that regard, but you do need
Speaker:to allow exceptions for things like backup, That is definitely a
Speaker:server to server lateral movement.
Speaker:Yeah.
Speaker:And it's also other simple things.
Speaker:Like one of them was your favorite topic, right?
Speaker:Locking down RDP and SSH.
Speaker:yes.
Speaker:then lock it down.
Speaker:SMB is the same way as well for vCenter, right?
Speaker:Figuring out what actually needs access and what.
Speaker:to be available to the internet.
Speaker:And one of the points he made is you should just assume that
Speaker:your inner internal network is as hostile as internet access.
Speaker:So once an exploit happens, you can't trust anything internally.
Speaker:They were also, I, I didn't necessarily agree with this one here.
Speaker:And that was it's time to kill monolithic file servers.
Speaker:Now I don't have a problem with the file server.
Speaker:It's just, I think when they mean monolithic file server, they're just
Speaker:saying a file server where everybody in the company can access all the data.
Speaker:I would agree there
Speaker:Yep.
Speaker:that's doing that, in a
Speaker:company of more than three people is
Speaker:isolate to
Speaker:yeah.
Speaker:that need access.
Speaker:You use ACLs, make sure the people who need access have access and
Speaker:then monitor who's accessing what.
Speaker:So they made a specific example of just because accounts receivable gets attacked,
Speaker:something shouldn't happen to payroll.
Speaker:these are both finance functions, but they're separate financial functions
Speaker:and they should have their own areas.
Speaker:Yeah.
Speaker:and this is another one that I harp on is about protecting privileged credentials.
Speaker:And
Speaker:don't just
Speaker:he says,
Speaker:on your forehead, Curtis.
Speaker:They recommended implementing, things like LAPS, which I had to look up, which stands
Speaker:for local administrator password solution.
Speaker:setting a different random password for the common local admin account
Speaker:on every computer in the domain.
Speaker:So you don't use one password for everything.
Speaker:And then MFA, I think every system, every privileged account needs to have
Speaker:MFA and, I'm sorry, that's a pain.
Speaker:I, I use it all the time, but it what is
Speaker:but wait, why do you need a privileged account?
Speaker:You should.
Speaker:Here's the thing.
Speaker:Most times you should probably not need privileged accounts, so you do not need
Speaker:to access your privileged accounts.
Speaker:Agreed, but they have to exist.
Speaker:And so you have to lock them down this way.
Speaker:I think what you're saying is MFA, shouldn't be that big of a deal for you.
Speaker:If you set up modern administration.
Speaker:yeah.
Speaker:And you should rarely be using that.
Speaker:And then very last on the list and I would have put it first, it's just
Speaker:me and that was patching your stuff.
Speaker:How many times does that come up on the podcast?
Speaker:When we talk about
Speaker:Yeah.
Speaker:Yeah, exactly.
Speaker:So the next one is about.
Speaker:It's okay, so you got some ransomware.
Speaker:Let's talk about the things that they're going to try to do.
Speaker:The very first thing they listed was deleting of shadow copies.
Speaker:And so I, and really shadow copies are basically like he's talking
Speaker:about windows shadow copies.
Speaker:right?
Speaker:Like VSS.
Speaker:copies.
Speaker:Yup.
Speaker:And so there is a tool here, which I had never heard of called raccine.
Speaker:And it stops you from deleting shadow copies.
Speaker:He said it stops everybody from deleting them.
Speaker:So just realize that if you've got some regular thing that regularly deletes
Speaker:shadow copies, it'll break that, but it looks it's something on github.
Speaker:So it's, it's an open source tool.
Speaker:And just reading that briefly, I think many backup tools when you're backing up
Speaker:windows applications uses shadow copy.
Speaker:So be careful if you are using that because you may not
Speaker:be able to do your backups.
Speaker:Yeah, that's a good question.
Speaker:I would differentiate between shadow copies made just for the purposes
Speaker:of backups and shadow copies that are made and then left there.
Speaker:I don't know if there's like a different.
Speaker:I know that when you make a snapshot, you say why you're making the snapshot.
Speaker:Yeah.
Speaker:but agreed that this is not something that you're just going
Speaker:to download and just implement,
Speaker:Yeah.
Speaker:might break all your backups.
Speaker:what it might do is it might allow you to create that snapshot, but
Speaker:then it leaves all those snapshots around and let you delete them.
Speaker:and you might get an error on your backup because you can't,
Speaker:it can't delete the snapshot.
Speaker:yeah.
Speaker:your production could run out of space and then your app dies.
Speaker:And then what's the next one
Speaker:here?
Speaker:the next one is common theme for us.
Speaker:when we talk about ransomware, less about the actual encrypting of data.
Speaker:It's the fact that these ransomware actors, especially the Conti group,
Speaker:they like to exfiltrate your data and steal sensitive data, and then hold you
Speaker:hostage and be like, Hey, you want to pay?
Speaker:Then you have to pay twice once for the decryption key.
Speaker:And then once to make sure we don't publish your data.
Speaker:sometimes they will still go and publish your data.
Speaker:Right.
Speaker:So in this post, he talks about how can you make sure you
Speaker:can detect data exfiltration?
Speaker:And he talks about everything from, if you have, if you understand network
Speaker:patterns, you could look for anomalies.
Speaker:can also look at other tools.
Speaker:To see when data is actually being read and sent.
Speaker:there's some interesting tools that he talked about.
Speaker:One that I never thought about, which was this mechanism called,
Speaker:from things called Canary tokens,
Speaker:right.
Speaker:it basically creates a false file.
Speaker:And any time someone accesses it, it generates a token and sends it home.
Speaker:And then it'll send you an email, say, Hey, by the way,
Speaker:someone accessed this file.
Speaker:So you can
Speaker:Right.
Speaker:get notified of, Hey, someone's accessing something, which they
Speaker:probably normally never should be.
Speaker:Because most of this
Speaker:Yeah.
Speaker:software and data exfiltration, it's just programmatically reading, like
Speaker:scanning folders, reading files, Trying to figure out what to send.
Speaker:And they mentioned both commercial solutions and open source solutions.
Speaker:Like the one you mentioned, they also mentioned something called,
Speaker:Zeke, which, And that it analyzes NetFlow, but there are commercial
Speaker:tools, which we've mentioned on here.
Speaker:and I'd like to get, I'd like to get more of those companies on here.
Speaker:And their recommendation was the same as mine, which is looking
Speaker:for something that uses behavioral analytics to determine what is,
Speaker:and is not a normal file transfer,
Speaker:Yep.
Speaker:should be able to spot a massive, exfiltration attack..
Speaker:And then the response against encryption, they talked about the EDR
Speaker:XDR, which is I had to look that up.
Speaker:I was not in my, so this is what,
Speaker:did we say?
Speaker:that meant,
Speaker:detection and response.
Speaker:Okay.
Speaker:The idea is that if you've got, if you've got the money to put something
Speaker:on each laptop that basically looks at and stops, massive file modifications,
Speaker:it would detect and stop those.
Speaker:And then same thing with the honeypot.
Speaker:I liked the idea with the creating an entire separate file server that has
Speaker:all the same file names, but just with junk data, watch for anybody doing
Speaker:anything there and then report on.
Speaker:Yeah.
Speaker:And the interesting thing is when he was talking about honeypots, I didn't
Speaker:know, this is, he was like, oh yeah.
Speaker:And then to make it more realistic, you, there are a couple things you can do.
Speaker:You can map those device shares to actual endpoint devices.
Speaker:So they show up there because if I'm a ransomware program and I'm just
Speaker:looking at all the devices attached, I don't know if it's real or not.
Speaker:And the question came up, Hey, how do you hide it from your end users?
Speaker:Because you don't want your end users clicking on it as well.
Speaker:And there are registry commands in Windows, so you can actually hide them.
Speaker:So your users don't actually see those drives.
Speaker:And instead he suggested you actually bookmarked.
Speaker:Shared drive letters with these honeypot shared drives because ransomware,
Speaker:programs are either going to start from a and work alphabetically or
Speaker:start from Z and come backwards, to see what drives are available.
Speaker:And then they'll just start looking that way.
Speaker:so put a honeypot at a and put a honeypot at z.
Speaker:Yup.
Speaker:I like
Speaker:it.
Speaker:were some really interesting things that he talked about.
Speaker:And we can only cover a little bit here.
Speaker:I just would highly recommend anybody that's interested in this, which should
Speaker:be everybody go read this thread.
Speaker:It's really well-written thread
Speaker:It's like how to
Speaker:and.
Speaker:and how to protect yourself.
Speaker:And then
Speaker:we get to the
Speaker:Yeah.
Speaker:Your favorite Curtis.
Speaker:Yeah.
Speaker:Get up on the third?
Speaker:one.
Speaker:Sorry, what is the third one about by the way?
Speaker:Oh, the third one basically it's you've been infected.
Speaker:What are we going to do?
Speaker:Worst case scenario you've been infected and it's spread, and now
Speaker:you need to reach for your backups.
Speaker:So they mentioned go to the incident response plan.
Speaker:And of course that assumes that you have one, which we've said
Speaker:that you need to have one, right?
Speaker:Yep.
Speaker:we've mentioned repeatedly that a ransomware attack is
Speaker:not the same as a disaster.
Speaker:There are elements that I'd say a disaster is a subset of.
Speaker:typical DR response is a subset of a ransomware attack response.
Speaker:Think people get confused because in the end you're trying
Speaker:to do the same things, your
Speaker:Yeah.
Speaker:up.
Speaker:But I think the steps and the number of people, the different types of
Speaker:people involved are significantly different between just a normal
Speaker:DR. Versus a ransomware recovery.
Speaker:simplistically to me, the biggest difference between, responding to
Speaker:a ransomware attack and a disaster, it'd be the equivalent of if you're
Speaker:doing a DR and you've had a flood step number one is drain the data center,
Speaker:right?
Speaker:Get all the water out of the data center.
Speaker:a ransomware attack is you're trying to drain the data center while you have
Speaker:a person standing there with a fire hose, it's filling up your datacenter.
Speaker:Right?
Speaker:that's the difference between a disaster recovery and a ransomware recovery is that
Speaker:they are actively still attacking you.
Speaker:And you're actively experiencing the disaster at the same time as
Speaker:you're trying to recover from it.
Speaker:And so they've got a good thing here on what should be
Speaker:in an incident response, right?
Speaker:Some things you have to have in your incident response plan
Speaker:got eight things about right.
Speaker:Procedures and policies and an incident firm.
Speaker:you need, you basically get professionals, retain them now, right?
Speaker:Oh, by the way, I just gotta throw out a really hilarious thing from,
Speaker:my granddaughter Lily yesterday.
Speaker:So we have a friend, a mutual friend that was in a car accident a while back.
Speaker:not seriously injured, but injured enough that there is a
Speaker:lawsuit that our, that's going on.
Speaker:And Lily said, she, she mentioned that I couldn't, she couldn't pick
Speaker:her up because, she was with her, she was with her lawyer and then she
Speaker:looks at me, we were just walking and then she's do I have a lawyer?
Speaker:I was like, no, I don't think you have a lawyer.
Speaker:You don't need a lawyer right now.
Speaker:but you're right.
Speaker:Most people don't even think about that.
Speaker:Like even in like everyday, like normal situations, it's if I, God forbid
Speaker:get arrested, Who am I going to call?
Speaker:It's
Speaker:Yeah.
Speaker:And so w what they're saying here is, go find who you're going to hire
Speaker:and get them on retainer.
Speaker:Ghostbusters?
Speaker:going to call?
Speaker:And, and they got a policy, oh, a policy.
Speaker:This is interesting policy for informing partners and customers and the media.
Speaker:Right?
Speaker:Decision-makers right.
Speaker:All of that stuff.
Speaker:This should all be decided upfront.
Speaker:You should be deciding that now.
Speaker:I don't know how many times we can say that.
Speaker:Yep.
Speaker:And then they talk about restoring your data.
Speaker:Restoring your data.
Speaker:we
Speaker:And I think how they said alright, three posts in and we
Speaker:can finally talk about backups.
Speaker:Yeah.
Speaker:It's interesting here.
Speaker:And he talks about, the typical call-out is that ransomware's
Speaker:going to target your backups.
Speaker:Yep.
Speaker:And so you need some sort of immutable backup solution.
Speaker:he does also talk and I know Curtis, you're probably going to
Speaker:have concerns with this, right?
Speaker:That you don't have to be offsite to protect your backups properly.
Speaker:He mentions that you could use strict network segmentation or other mechanisms
Speaker:to ensure separation, which would protect you in the case of ransomware, but
Speaker:may not protect you from all disasters
Speaker:yeah.
Speaker:could occur.
Speaker:Agreed.
Speaker:and, and I don't, I don't have an issue with that, Obviously, I'll say obviously
Speaker:I work at a service-based backup company.
Speaker:And we see that as the easy it's easy peasy.
Speaker:All our backups are off site.
Speaker:I'm not against, you know, as a backup expert, I'm not against onsite backups.
Speaker:There's a lot of good reasons for an onsite copy, but I completely agree
Speaker:with this person that you have to protect that onsite copy from attacks.
Speaker:And there are a lot of very common backup designs, incredibly common backup designs
Speaker:that do not that the default installation of those products do not protect you.
Speaker:Right.
Speaker:And I, and I'll, I don't wanna, I don't wanna pick on our friends at
Speaker:Veeam, but that's a perfect example.
Speaker:The guys from Veeam came on here and they explained to you, if you
Speaker:listen, if you haven't seen those episodes, go back and listen to them.
Speaker:Uh, about, you know, when they talked about the, the Conti ransomware attacks
Speaker:and how you can configure your Veeam backups to protect against that.
Speaker:My concern is that most of their customers are not listening to this podcast, by
Speaker:the way, they're more than welcome.
Speaker:All 700,000 Veeam customers are more than welcome to come listen to the podcast.
Speaker:But if you just do the default installation and you don't take their
Speaker:recommendations on how to further protect your data, it's no different
Speaker:than any of the other products, right?
Speaker:So
Speaker:Read
Speaker:you've got to stop doing that.
Speaker:Read the manual, read the best practices.
Speaker:Call Rickatron.
Speaker:Rickatron'll sort, you out and.
Speaker:So he talks about that.
Speaker:He also talks about testing, your backups.
Speaker:I'm editing right now, like literally in I'm in the middle of editing
Speaker:the podcast, the episode of the restore test gone horribly wrong.
Speaker:backup.
Speaker:It's going to be a great episode.
Speaker:The.
Speaker:Yeah, Schrodinger's backup.
Speaker:Exactly.
Speaker:That's going to, if, yeah, if you haven't heard that episode
Speaker:go back and listen to it.
Speaker:it's a
Speaker:great,
Speaker:episode.
Speaker:of the article
Speaker:And
Speaker:to it,
Speaker:then he,
Speaker:Yeah.
Speaker:yes, he does.
Speaker:did he actually refer to Shrodinger's
Speaker:backup Schrodinger's backup
Speaker:Yeah.
Speaker:HInging your company's
Speaker:and this one?
Speaker:backup thought experiment is a terrible idea.
Speaker:Don't do that.
Speaker:Nice.
Speaker:and then why don't you talk about the decryption part?
Speaker:Yeah.
Speaker:So I guess the final part right.
Speaker:Is you've been hit with encryption, right?
Speaker:now what do you do?
Speaker:And most cases, it's.
Speaker:You can try to get, if you're lucky, there might be a free
Speaker:decryptor out there for your data.
Speaker:It's just going to take a very long time.
Speaker:And if you do pay the ransom and you have to understand that paying the ransom may
Speaker:be illegal to some of these groups, right?
Speaker:They'll give you back a decryption key.
Speaker:Hopefully it'll work.
Speaker:It's not, it's in the ransomware.
Speaker:Group's best interest not to cheat you there, but you're
Speaker:taking a risk there as well.
Speaker:And then finally,
Speaker:Okay.
Speaker:Once you've actually decrypted your data.
Speaker:You've gone back up and running.
Speaker:There's nothing that prevents them from either coming back
Speaker:and attacking you again, if you haven't fixed anything right.
Speaker:Or the next group coming back.
Speaker:Cause that's another common thing is one group gets in encrypts your data.
Speaker:Another group figures out a different mechanism because they
Speaker:know now that you're willing to pay.
Speaker:And so they might come after you as well.
Speaker:So
Speaker:And then.
Speaker:decrypted, it's not the end of the story.
Speaker:And then the there's a what's next and all of these words, and this is a
Speaker:really long series of posts, which I highly recommend you go look through.
Speaker:There's one part where they typed in all caps, and this is it right when
Speaker:you're done, whatever you did restore, pay the ransom, whatever it is.
Speaker:It's not over, you clearly have a serious gap in your defenses.
Speaker:You need to find these and fix them.
Speaker:And then this is all caps and you need to understand that those gaps are bigger
Speaker:than just whatever the initial breach vector was as highlighted in parts one
Speaker:and two of this series, there are several opportunities to stop a ransomware
Speaker:breach before it gets to this point.
Speaker:there, there was some other.
Speaker:It was another one that I read, somebody, they said, if I was at a company that had
Speaker:a highly, I think it was actually in here.
Speaker:If I was at a company that a highly publicized breach does this hurt my
Speaker:chances of getting a job and the author of this article didn't think so, because they
Speaker:basically said you now have experience
Speaker:Yep.
Speaker:and,
Speaker:was actually at the end of this article is where he wrote about that.
Speaker:Yeah.
Speaker:He's yeah.
Speaker:right,
Speaker:you should actually show that you've gone through this because for a lot
Speaker:of people it's just theoretical.
Speaker:They've never experienced it.
Speaker:It's like you Curtis.
Speaker:I can sit here and talk about like how to back up your data, how to restore
Speaker:your data, ideally how it should be done.
Speaker:But I've never cut my teeth in a production environment, trying to do a
Speaker:restore with people, yelling at me over my shoulder or watching over my shoulder.
Speaker:Right.
Speaker:You have, and I think that's the difference, right?
Speaker:Is you
Speaker:Yeah.
Speaker:that experience because trial by fire.
Speaker:Yeah, I, you just reminded me of, and I know I've told this story before, but not
Speaker:everybody's listening to every episode.
Speaker:My, one of my favorite restore stories was back at my first big job.
Speaker:And we had somebody in the NOC that was coordinating the various things that
Speaker:were happening of this big restore.
Speaker:And we had another guy that was in the data center that
Speaker:was actually doing things and.
Speaker:He was talking to the person who was on the phone in the NOC.
Speaker:And he didn't know that he was on speaker.
Speaker:And so he said, he's oh, so you know where you are.
Speaker:I'm in the NOC.
Speaker:He goes, oh, so I suppose you have Tom and Tom standing on
Speaker:your left and right shoulder.
Speaker:And he was referring to our boss's boss and our boss's boss.
Speaker:And, the, that would be Tom Thomaides and Tom Lackey.
Speaker:And they were indeed standing both on his left and right shoulder.
Speaker:And they said that when he said that, oh, so you have Tom and Tom standing
Speaker:on your left and right shoulder.
Speaker:He said they just both took one step back.
Speaker:but it's true, right?
Speaker:It's a stressful thing everyone's watching to make sure it goes perfect.
Speaker:And, we wish you all the best of luck.
Speaker:I continue to be concerned about our friends over there in the Ukraine.
Speaker:And, we wish them the best of luck and.
Speaker:You should also be concerned about the potential ramifications that
Speaker:all of that has on continued further attacks on your data center and read
Speaker:this article, read every word of this article, not just this summary and,
Speaker:Read the three
Speaker:read all three parts and we'll put links to it in the show description
Speaker:so that you can easily find it.
Speaker:Cause finding stuff on Reddit is not necessarily easy.
Speaker:Thanks again Prasanna for your wise, shipping advice and, a
Speaker:good commentary on this as well.
Speaker:Yeah
Speaker:well.
Speaker:anytime Curtis and I hope I know, normally when we talk about
Speaker:ransomware, you get very depressed.
Speaker:So I, it feels like this isn't a depressing article.
Speaker:It feels like here are things you should be doing.
Speaker:So
Speaker:it feels
Speaker:Here are things that you should do now.
Speaker:Yeah,
Speaker:Yeah, absolutely.
Speaker:all right, thanks to the listeners.
Speaker:we'd be nothing without you remember to subscribe