July 20, 2026

Ransomware Response Checklist: Prevent It, Slow It, Survive It

Ransomware Response Checklist: Prevent It, Slow It, Survive It

This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack.

This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back.

Curtis Preston and Prasanna Malaiyandi dig into snorkel42's series, which breaks the whole problem into three parts: how to stop ransomware from getting in, how to slow it down if it does, and what to actually do once you've been hit. Curtis and Prasanna go section by section — covering phishing and dropper prevention, application whitelisting, blocking lateral movement between servers, locking down RDP and SSH, honeypot files for catching intruders in the act, and building a real incident response plan before you ever need one.

They also get into the messier parts most people don't talk about — what it's actually like to negotiate for a decryption key, why getting your data back isn't the end of the story, and why a ransomware attack is nothing like a normal disaster recovery scenario. Along the way, Curtis makes the case that most organizations already have the gaps this attacker needs — and that fixing them now is a lot cheaper than fixing them after the fact.

Whether you're building your first incident response plan or just want to stress-test the one you've already got, this episode gives you a practical, section-by-section framework to work from.

Chapter Markers:

00:00 – Encore intro & episode setup

00:01:37 – Show intro and banter

00:06:21 – Preventing the breach: phishing, droppers, and whitelisting

00:14:46 – Blocking lateral movement, RDP/SSH lockdown

00:20:28 – Detecting exfiltration and honeypot files

00:24:19 – What to do once you've been hit

00:25:58 – Building your incident response plan

00:30:43 – Decryption, ransom payments, and why it's not over yet

Speaker:

Welcome to another encore episode of the Backup Wrap-Up.

Speaker:

This very popular episode looks at a three-part series of Reddit posts

Speaker:

from a security specialist who finally agreed to write about ransomware after

Speaker:

a bunch of people asked him to do that.

Speaker:

What he put together ends up being a full ransomware response checklist,

Speaker:

how to stop it from getting in in the first place, how to keep it from

Speaker:

spreading once it does get in, and what to do if you actually get hit.

Speaker:

This is, uh, exactly the process that we built into my latest

Speaker:

book, Ransomware Response and Recovery, which is now available.

Speaker:

If you've ever wondered whether your organization has the right pieces

Speaker:

in place before, during, and after a ransomware attack, I think you'll

Speaker:

get a lot of value from this episode.

Speaker:

By the way, if this is your first time watching or listening to me, I'm W.

Speaker:

Curtis Preston, AKA Mr. Backup.

Speaker:

I've been obsessing over backup, recovery, and now cyber recovery for over 30 years.

Speaker:

If that's your bag, then I'm your guy.

Speaker:

You're not gonna find anyone more, uh, interested in backup than me.

Speaker:

Ever since 1993 when I had to tell my boss that there were no backups of

Speaker:

the database that we had just lost.

Speaker:

Now I've written five O'Reilly books, a blog, and a podcast.

Speaker:

Here, we turn unappreciated admins into cyber recovery heroes.

Speaker:

This is the Backup Wrap-Up.

Speaker:

Hi and welcome to Backup Central's podcast.

Speaker:

I'm your host, W. Curtis Preston, AKA Mr. Backup.

Speaker:

And I have with me, my delayed shipment consultant, Prasanna Malaiyandi.

Speaker:

How's it going , Prasanna?

Speaker:

I'm good.

Speaker:

Curtis, wait, what's delayed.

Speaker:

my, my, my flooring shipment, and I turn to you for.

Speaker:

what I thought you received one.

Speaker:

I did, but . I ordered a big shipment of flooring, and then I ordered

Speaker:

a much smaller shipment and I did that in two shipments because I

Speaker:

couldn't order all of it at once.

Speaker:

And then I had to order like another 10% and the second shipment I received the

Speaker:

second shipment like three weeks ago, I still haven't received the first shipment.

Speaker:

And, I just turned to you for, you know, emotional support in this time of.

Speaker:

Ridiculousness I'm not doing anything until the entire shipment

Speaker:

comes in., it's just ridiculous.

Speaker:

Maybe they ran out of

Speaker:

the raw stuff.

Speaker:

Yeah.

Speaker:

Whatever.

Speaker:

So this is why you're here.

Speaker:

You're here to make me not so angry.

Speaker:

That's why I said you're my delayed shipment consultant.

Speaker:

All I know is it's not in my hot little hands and I'm not doing squat in my

Speaker:

garage until I get the entire shipment.

Speaker:

Just think though.

Speaker:

How about delayed gratification?

Speaker:

Once you finally get the

Speaker:

Oh, This is the ultimate in delayed gratification.

Speaker:

I've never had so much trouble spending money in my life.

Speaker:

You're annoyed.

Speaker:

it'll be

Speaker:

#firstworldproblems.

Speaker:

Take a deep breath.

Speaker:

Yeah, good times.

Speaker:

Good times.

Speaker:

Rate us at ratethispodcast.com/restore, or just click on your favorite pod catcher.

Speaker:

And, uh, click down to the bottom and give us some stars, or maybe even a comment.

Speaker:

Talk about how much you love Prasanna's beard.

Speaker:

I'm good with that.

Speaker:

And how it's so much longer and darker than mine and.

Speaker:

So I see.

Speaker:

I sent you this post that I saw on Reddit, which it's well, it's

Speaker:

actually a series of three posts from a Reddit user called snorkel42.

Speaker:

Don't let his, snorkeling ID fool you the person knows what they're talking about.

Speaker:

Yep.

Speaker:

don't know.

Speaker:

I don't know anything about this person.

Speaker:

Other than that, they have, they post regularly in a subreddit

Speaker:

called security cadence.

Speaker:

but he also posted he or she, I don't know if I mistaken

Speaker:

mistakenly called the person.

Speaker:

He, I apologize in advance for my misogeny,

Speaker:

The, it was about ransomware and they are a specialist in the areas

Speaker:

of security and many people had asked them to post stuff about ransomware

Speaker:

and they had continually said, I don't want to post about ransomware.

Speaker:

And can you imagine why that would be

Speaker:

You're just propagate well, it's ransomware you get hit with, because

Speaker:

there were a bunch of gaps before ransomware got hit and it's better

Speaker:

to address the problem than trying to

Speaker:

right.

Speaker:

sort of the outcome.

Speaker:

Yeah.

Speaker:

So ransomware to this person is the symptom of a whole lot of bad things

Speaker:

that you were already doing or not doing.

Speaker:

And they've spent their career helping to make sure you do those things.

Speaker:

But with the, I think two things, one is that obviously the ransomware attacks are

Speaker:

getting to a fever pitch and then two.

Speaker:

There is what we talked about on the previous episode, which was this concern

Speaker:

about Russia and D w we did cover that.

Speaker:

Didn't

Speaker:

we?

Speaker:

Yeah, we cover the Conti ransomware gang

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

of the previous

Speaker:

yeah, the Krebs on security post.

Speaker:

Yep.

Speaker:

That the concern is that the level of the fever pitch that we're experiencing

Speaker:

might actually go through the roof.

Speaker:

And so they said, Hey, I'm gonna finally, I'm fine.

Speaker:

I'll post about ransomware, but even in their post about ransomware, it

Speaker:

really wasn't that much about ransomware as much as it was about the things.

Speaker:

no, that's not true.

Speaker:

I'll take that back.

Speaker:

it was here is the way ransomware works.

Speaker:

And so I'd say the first one, I'd say of the three series,

Speaker:

Yeah.

Speaker:

The first one was about here's how to prevent it.

Speaker:

Number one, like from getting in.

Speaker:

The second was here's how to prevent it from doing more damage once it's in.

Speaker:

And then the third one, it was okay.

Speaker:

All right.

Speaker:

You're totally screwed.

Speaker:

You've got to reach for your backups.

Speaker:

So that

Speaker:

The one thing I would add to that is he also was careful saying, I

Speaker:

don't want to just focus on the Conti ransomware and provide you steps to

Speaker:

prevent that because there are so many other ransomware flavors out there.

Speaker:

If you build something for just one.

Speaker:

You're not going to be protecting yourself.

Speaker:

Let's take a holistic approach.

Speaker:

And like you said, let's

Speaker:

good point.

Speaker:

you prevent it from getting in?

Speaker:

What, how do you prevent the spread of it?

Speaker:

And then how do you recover?

Speaker:

Yeah.

Speaker:

Good point.

Speaker:

The first one is called breach, I think is how he titled the first article.

Speaker:

Right.

Speaker:

So the phishing basically, they're saying that that is the number

Speaker:

one way that you get ransomware.

Speaker:

Yep.

Speaker:

Someone accidentally clicking an email, opening up something,

Speaker:

letting the attackers in, and they don't even know about it.

Speaker:

So do you prevent your users from clicking on malicious links?

Speaker:

now, it's interesting.

Speaker:

This goes, yeah.

Speaker:

Sorry.

Speaker:

This goes somewhat against what, some of the advice of one of the

Speaker:

guests that we had on the podcast, which was, they basically said,

Speaker:

look, your people are going to click on stuff, stop relying on, I dunno.

Speaker:

I dunno if it's against, but de-prioritized training and

Speaker:

Yeah.

Speaker:

phishing assessments, didn't you think.

Speaker:

Yeah.

Speaker:

So.

Speaker:

This author does say can only help you so much?

Speaker:

I think the couple things though, that he did mention is, you do need some level of

Speaker:

training, but you need to make sure people don't feel like they're being punished.

Speaker:

they do the wrong thing, right?

Speaker:

You want that transparency.

Speaker:

You want to be telling people it's okay for you to say that I clicked

Speaker:

the wrong thing because then the IT team can try to evaluate what's

Speaker:

going on and try to contain it.

Speaker:

sooner they know the

Speaker:

right.

Speaker:

if say someone's afraid because they're going to get in trouble.

Speaker:

They might be fired, It becomes taboo then no one's going to report it.

Speaker:

And that's actually really bad.

Speaker:

Yeah.

Speaker:

they said to prioritize rewarding over punishment.

Speaker:

make it known.

Speaker:

Like you said, that it's okay to call in.

Speaker:

We want you to call in, even if you messed up and then, and they also said consider

Speaker:

doing your own phishing assessments.

Speaker:

I read some of the comments and they talked about

Speaker:

that.

Speaker:

They had a thing where you got some.

Speaker:

You got some, it was some strikes and it was like 10 strikes.

Speaker:

It was like, you could click on 10 malicious emails.

Speaker:

And, and then it was the 10th.

Speaker:

When, and that they actually had a series of escalations where, it started

Speaker:

out, Hey, we really told you thing.

Speaker:

I think you can do both.

Speaker:

I think you can do both carrot and stick, Reward and punishment where yes.

Speaker:

You want to reward people for calling in.

Speaker:

Thank you for calling, I accidentally clicked . And then if the person

Speaker:

clicks doesn't know, because you did a phishing assessment, you do

Speaker:

a series of escalating things where that ultimately you can have a person.

Speaker:

And this was discussed in the comments, not necessarily that you

Speaker:

would fire somebody that, that keeps doing this, but you might say, okay,

Speaker:

this person cannot be trusted with a straight internet connection.

Speaker:

Yup.

Speaker:

All email from this person will be monitored.

Speaker:

Yeah.

Speaker:

They can only open email that's straight from our Exchange server

Speaker:

or whatever stuff like that.

Speaker:

So phishing was sort of one way that people get in.

Speaker:

But I think once they're in whichever mechanism it is, it's okay, how

Speaker:

do you detect that someone's in?

Speaker:

And I think Curtis, this is what you're going to say,

Speaker:

About this notion of droppers.

Speaker:

Yeah, I actually didn't know this part.

Speaker:

That's I was fascinated that basically that the actual phishing results in a very

Speaker:

small piece of software whose job it is to install the actual piece of software

Speaker:

Yeah.

Speaker:

and that he calls out a dropper.

Speaker:

Yep.

Speaker:

and so the idea is understand that's the way it works, that a piece of

Speaker:

code gets dropped in, and then that piece of code executes, and the only

Speaker:

purpose of that piece of code is to download the other piece of code.

Speaker:

And so they said that you could stop that.

Speaker:

You could say, you can't run arbitrary pieces of code

Speaker:

Yep.

Speaker:

in locations that are directly accessible by the end user, you know,

Speaker:

Or you could restrict

Speaker:

and

Speaker:

are allowed to run on a laptop for instance,

Speaker:

yes,

Speaker:

Whitelisting, I think whitelisting is it, I think it's the, the best.

Speaker:

The best way to stop stuff like this.

Speaker:

It's also the highest touch because it means that every new

Speaker:

application that anybody has to install, they have to get approval.

Speaker:

Yep.

Speaker:

think it's a way to guarantee legitimate applications have gone through some sort

Speaker:

of validation process, security review, et cetera, before it's being allowed

Speaker:

to be deployed in your environment

Speaker:

And then the next thing it talked about was that a random file running should

Speaker:

not be downloading files from the internet, That it should only be HTTP and

Speaker:

HTTPS is downloading from the internet.

Speaker:

And He said with exceptions, SFTP for example.

Speaker:

So he talked about, again, accessing that also possibly blocking bizarre TLDs right.

Speaker:

And unnecessary locations.

Speaker:

You could just simply say, listen, we don't have anything to do with Russia.

Speaker:

Why would we download anything from Russia?

Speaker:

And if there is somebody in our company that needs to download stuff

Speaker:

from Russia, they will be accepted.

Speaker:

That was a very running theme I heard was lock down everything and allow exceptions.

Speaker:

Yeah.

Speaker:

And, it was going to bring up two things.

Speaker:

One was what's a TLD for our listeners?

Speaker:

Oh, top level domain.

Speaker:

That's like.com or dot ransomware.

Speaker:

There is no dot

Speaker:

ransomware,

Speaker:

but.

Speaker:

And was it you, or was it one of our guests who were, who was talking about

Speaker:

how they worked at a company that completely locked down their network

Speaker:

and the network admin would never let them do their backups and everything

Speaker:

no, that was me.

Speaker:

Okay.

Speaker:

was me.

Speaker:

Yeah.

Speaker:

Yeah.

Speaker:

that was, I was a client of mine where they had internal firewalls and that's an

Speaker:

example of, going to the extreme of, now you're preventing core business functions,

Speaker:

Yeah,

Speaker:

right?

Speaker:

but

Speaker:

they also talked about local firewalls, Which is what we were just talking

Speaker:

about, that the, and we're going to get to that more in the next section is,

Speaker:

so they're just looking, he's looking

Speaker:

for ways to stop the dropper from getting yeah, exactly.

Speaker:

Yeah.

Speaker:

thought was an interesting point I'd never thought about is he does have a point

Speaker:

about they block newly created domains.

Speaker:

Which I thought that had been dormant for a while and then are now active,

Speaker:

which I thought was very interesting because it's something I had never

Speaker:

thought about, but it totally makes sense.

Speaker:

Usually when you get ransomware, These actors, they spin up domains and they

Speaker:

start communicating, using that domain.

Speaker:

So yeah, you could have a policy to just block these domains.

Speaker:

So they can't actually reach back out to the

Speaker:

Right.

Speaker:

to be able to download from the dropper, the actual exploit.

Speaker:

code

Speaker:

Right.

Speaker:

And, and they said they weren't aware of anything.

Speaker:

Where that you can do this for free, but there are tools that are

Speaker:

available to help you do This right.

Speaker:

There's

Speaker:

remember, what are the D D.

Speaker:

what were the initials?

Speaker:

The DNS

Speaker:

DDI.

Speaker:

yeah, And I think that goes to some of that as well.

Speaker:

Where it's like, Hey, if you have some of those controls in place, can now

Speaker:

prevent unauthorized access to domains.

Speaker:

They should not be having access to.

Speaker:

Exactly.

Speaker:

And then they started talking about preventing lateral movement inside.

Speaker:

Think about the ways that people need to move within your organization and

Speaker:

allow that, but block all other movement, Lateral movement between servers and I

Speaker:

think, again, going back to that company, that was a perfect example of, they had

Speaker:

blocked all lateral movement between all servers and I couldn't get my job done.

Speaker:

They're only problem w and they should have done that.

Speaker:

And, they were forward thinking in that regard, but you do need

Speaker:

to allow exceptions for things like backup, That is definitely a

Speaker:

server to server lateral movement.

Speaker:

Yeah.

Speaker:

And it's also other simple things.

Speaker:

Like one of them was your favorite topic, right?

Speaker:

Locking down RDP and SSH.

Speaker:

yes.

Speaker:

then lock it down.

Speaker:

SMB is the same way as well for vCenter, right?

Speaker:

Figuring out what actually needs access and what.

Speaker:

to be available to the internet.

Speaker:

And one of the points he made is you should just assume that

Speaker:

your inner internal network is as hostile as internet access.

Speaker:

So once an exploit happens, you can't trust anything internally.

Speaker:

They were also, I, I didn't necessarily agree with this one here.

Speaker:

And that was it's time to kill monolithic file servers.

Speaker:

Now I don't have a problem with the file server.

Speaker:

It's just, I think when they mean monolithic file server, they're just

Speaker:

saying a file server where everybody in the company can access all the data.

Speaker:

I would agree there

Speaker:

Yep.

Speaker:

that's doing that, in a

Speaker:

company of more than three people is

Speaker:

isolate to

Speaker:

yeah.

Speaker:

that need access.

Speaker:

You use ACLs, make sure the people who need access have access and

Speaker:

then monitor who's accessing what.

Speaker:

So they made a specific example of just because accounts receivable gets attacked,

Speaker:

something shouldn't happen to payroll.

Speaker:

these are both finance functions, but they're separate financial functions

Speaker:

and they should have their own areas.

Speaker:

Yeah.

Speaker:

and this is another one that I harp on is about protecting privileged credentials.

Speaker:

And

Speaker:

don't just

Speaker:

he says,

Speaker:

on your forehead, Curtis.

Speaker:

They recommended implementing, things like LAPS, which I had to look up, which stands

Speaker:

for local administrator password solution.

Speaker:

setting a different random password for the common local admin account

Speaker:

on every computer in the domain.

Speaker:

So you don't use one password for everything.

Speaker:

And then MFA, I think every system, every privileged account needs to have

Speaker:

MFA and, I'm sorry, that's a pain.

Speaker:

I, I use it all the time, but it what is

Speaker:

but wait, why do you need a privileged account?

Speaker:

You should.

Speaker:

Here's the thing.

Speaker:

Most times you should probably not need privileged accounts, so you do not need

Speaker:

to access your privileged accounts.

Speaker:

Agreed, but they have to exist.

Speaker:

And so you have to lock them down this way.

Speaker:

I think what you're saying is MFA, shouldn't be that big of a deal for you.

Speaker:

If you set up modern administration.

Speaker:

yeah.

Speaker:

And you should rarely be using that.

Speaker:

And then very last on the list and I would have put it first, it's just

Speaker:

me and that was patching your stuff.

Speaker:

How many times does that come up on the podcast?

Speaker:

When we talk about

Speaker:

Yeah.

Speaker:

Yeah, exactly.

Speaker:

So the next one is about.

Speaker:

It's okay, so you got some ransomware.

Speaker:

Let's talk about the things that they're going to try to do.

Speaker:

The very first thing they listed was deleting of shadow copies.

Speaker:

And so I, and really shadow copies are basically like he's talking

Speaker:

about windows shadow copies.

Speaker:

right?

Speaker:

Like VSS.

Speaker:

copies.

Speaker:

Yup.

Speaker:

And so there is a tool here, which I had never heard of called raccine.

Speaker:

And it stops you from deleting shadow copies.

Speaker:

He said it stops everybody from deleting them.

Speaker:

So just realize that if you've got some regular thing that regularly deletes

Speaker:

shadow copies, it'll break that, but it looks it's something on github.

Speaker:

So it's, it's an open source tool.

Speaker:

And just reading that briefly, I think many backup tools when you're backing up

Speaker:

windows applications uses shadow copy.

Speaker:

So be careful if you are using that because you may not

Speaker:

be able to do your backups.

Speaker:

Yeah, that's a good question.

Speaker:

I would differentiate between shadow copies made just for the purposes

Speaker:

of backups and shadow copies that are made and then left there.

Speaker:

I don't know if there's like a different.

Speaker:

I know that when you make a snapshot, you say why you're making the snapshot.

Speaker:

Yeah.

Speaker:

but agreed that this is not something that you're just going

Speaker:

to download and just implement,

Speaker:

Yeah.

Speaker:

might break all your backups.

Speaker:

what it might do is it might allow you to create that snapshot, but

Speaker:

then it leaves all those snapshots around and let you delete them.

Speaker:

and you might get an error on your backup because you can't,

Speaker:

it can't delete the snapshot.

Speaker:

yeah.

Speaker:

your production could run out of space and then your app dies.

Speaker:

And then what's the next one

Speaker:

here?

Speaker:

the next one is common theme for us.

Speaker:

when we talk about ransomware, less about the actual encrypting of data.

Speaker:

It's the fact that these ransomware actors, especially the Conti group,

Speaker:

they like to exfiltrate your data and steal sensitive data, and then hold you

Speaker:

hostage and be like, Hey, you want to pay?

Speaker:

Then you have to pay twice once for the decryption key.

Speaker:

And then once to make sure we don't publish your data.

Speaker:

sometimes they will still go and publish your data.

Speaker:

Right.

Speaker:

So in this post, he talks about how can you make sure you

Speaker:

can detect data exfiltration?

Speaker:

And he talks about everything from, if you have, if you understand network

Speaker:

patterns, you could look for anomalies.

Speaker:

can also look at other tools.

Speaker:

To see when data is actually being read and sent.

Speaker:

there's some interesting tools that he talked about.

Speaker:

One that I never thought about, which was this mechanism called,

Speaker:

from things called Canary tokens,

Speaker:

right.

Speaker:

it basically creates a false file.

Speaker:

And any time someone accesses it, it generates a token and sends it home.

Speaker:

And then it'll send you an email, say, Hey, by the way,

Speaker:

someone accessed this file.

Speaker:

So you can

Speaker:

Right.

Speaker:

get notified of, Hey, someone's accessing something, which they

Speaker:

probably normally never should be.

Speaker:

Because most of this

Speaker:

Yeah.

Speaker:

software and data exfiltration, it's just programmatically reading, like

Speaker:

scanning folders, reading files, Trying to figure out what to send.

Speaker:

And they mentioned both commercial solutions and open source solutions.

Speaker:

Like the one you mentioned, they also mentioned something called,

Speaker:

Zeke, which, And that it analyzes NetFlow, but there are commercial

Speaker:

tools, which we've mentioned on here.

Speaker:

and I'd like to get, I'd like to get more of those companies on here.

Speaker:

And their recommendation was the same as mine, which is looking

Speaker:

for something that uses behavioral analytics to determine what is,

Speaker:

and is not a normal file transfer,

Speaker:

Yep.

Speaker:

should be able to spot a massive, exfiltration attack..

Speaker:

And then the response against encryption, they talked about the EDR

Speaker:

XDR, which is I had to look that up.

Speaker:

I was not in my, so this is what,

Speaker:

did we say?

Speaker:

that meant,

Speaker:

detection and response.

Speaker:

Okay.

Speaker:

The idea is that if you've got, if you've got the money to put something

Speaker:

on each laptop that basically looks at and stops, massive file modifications,

Speaker:

it would detect and stop those.

Speaker:

And then same thing with the honeypot.

Speaker:

I liked the idea with the creating an entire separate file server that has

Speaker:

all the same file names, but just with junk data, watch for anybody doing

Speaker:

anything there and then report on.

Speaker:

Yeah.

Speaker:

And the interesting thing is when he was talking about honeypots, I didn't

Speaker:

know, this is, he was like, oh yeah.

Speaker:

And then to make it more realistic, you, there are a couple things you can do.

Speaker:

You can map those device shares to actual endpoint devices.

Speaker:

So they show up there because if I'm a ransomware program and I'm just

Speaker:

looking at all the devices attached, I don't know if it's real or not.

Speaker:

And the question came up, Hey, how do you hide it from your end users?

Speaker:

Because you don't want your end users clicking on it as well.

Speaker:

And there are registry commands in Windows, so you can actually hide them.

Speaker:

So your users don't actually see those drives.

Speaker:

And instead he suggested you actually bookmarked.

Speaker:

Shared drive letters with these honeypot shared drives because ransomware,

Speaker:

programs are either going to start from a and work alphabetically or

Speaker:

start from Z and come backwards, to see what drives are available.

Speaker:

And then they'll just start looking that way.

Speaker:

so put a honeypot at a and put a honeypot at z.

Speaker:

Yup.

Speaker:

I like

Speaker:

it.

Speaker:

were some really interesting things that he talked about.

Speaker:

And we can only cover a little bit here.

Speaker:

I just would highly recommend anybody that's interested in this, which should

Speaker:

be everybody go read this thread.

Speaker:

It's really well-written thread

Speaker:

It's like how to

Speaker:

and.

Speaker:

and how to protect yourself.

Speaker:

And then

Speaker:

we get to the

Speaker:

Yeah.

Speaker:

Your favorite Curtis.

Speaker:

Yeah.

Speaker:

Get up on the third?

Speaker:

one.

Speaker:

Sorry, what is the third one about by the way?

Speaker:

Oh, the third one basically it's you've been infected.

Speaker:

What are we going to do?

Speaker:

Worst case scenario you've been infected and it's spread, and now

Speaker:

you need to reach for your backups.

Speaker:

So they mentioned go to the incident response plan.

Speaker:

And of course that assumes that you have one, which we've said

Speaker:

that you need to have one, right?

Speaker:

Yep.

Speaker:

we've mentioned repeatedly that a ransomware attack is

Speaker:

not the same as a disaster.

Speaker:

There are elements that I'd say a disaster is a subset of.

Speaker:

typical DR response is a subset of a ransomware attack response.

Speaker:

Think people get confused because in the end you're trying

Speaker:

to do the same things, your

Speaker:

Yeah.

Speaker:

up.

Speaker:

But I think the steps and the number of people, the different types of

Speaker:

people involved are significantly different between just a normal

Speaker:

DR. Versus a ransomware recovery.

Speaker:

simplistically to me, the biggest difference between, responding to

Speaker:

a ransomware attack and a disaster, it'd be the equivalent of if you're

Speaker:

doing a DR and you've had a flood step number one is drain the data center,

Speaker:

right?

Speaker:

Get all the water out of the data center.

Speaker:

a ransomware attack is you're trying to drain the data center while you have

Speaker:

a person standing there with a fire hose, it's filling up your datacenter.

Speaker:

Right?

Speaker:

that's the difference between a disaster recovery and a ransomware recovery is that

Speaker:

they are actively still attacking you.

Speaker:

And you're actively experiencing the disaster at the same time as

Speaker:

you're trying to recover from it.

Speaker:

And so they've got a good thing here on what should be

Speaker:

in an incident response, right?

Speaker:

Some things you have to have in your incident response plan

Speaker:

got eight things about right.

Speaker:

Procedures and policies and an incident firm.

Speaker:

you need, you basically get professionals, retain them now, right?

Speaker:

Oh, by the way, I just gotta throw out a really hilarious thing from,

Speaker:

my granddaughter Lily yesterday.

Speaker:

So we have a friend, a mutual friend that was in a car accident a while back.

Speaker:

not seriously injured, but injured enough that there is a

Speaker:

lawsuit that our, that's going on.

Speaker:

And Lily said, she, she mentioned that I couldn't, she couldn't pick

Speaker:

her up because, she was with her, she was with her lawyer and then she

Speaker:

looks at me, we were just walking and then she's do I have a lawyer?

Speaker:

I was like, no, I don't think you have a lawyer.

Speaker:

You don't need a lawyer right now.

Speaker:

but you're right.

Speaker:

Most people don't even think about that.

Speaker:

Like even in like everyday, like normal situations, it's if I, God forbid

Speaker:

get arrested, Who am I going to call?

Speaker:

It's

Speaker:

Yeah.

Speaker:

And so w what they're saying here is, go find who you're going to hire

Speaker:

and get them on retainer.

Speaker:

Ghostbusters?

Speaker:

going to call?

Speaker:

And, and they got a policy, oh, a policy.

Speaker:

This is interesting policy for informing partners and customers and the media.

Speaker:

Right?

Speaker:

Decision-makers right.

Speaker:

All of that stuff.

Speaker:

This should all be decided upfront.

Speaker:

You should be deciding that now.

Speaker:

I don't know how many times we can say that.

Speaker:

Yep.

Speaker:

And then they talk about restoring your data.

Speaker:

Restoring your data.

Speaker:

we

Speaker:

And I think how they said alright, three posts in and we

Speaker:

can finally talk about backups.

Speaker:

Yeah.

Speaker:

It's interesting here.

Speaker:

And he talks about, the typical call-out is that ransomware's

Speaker:

going to target your backups.

Speaker:

Yep.

Speaker:

And so you need some sort of immutable backup solution.

Speaker:

he does also talk and I know Curtis, you're probably going to

Speaker:

have concerns with this, right?

Speaker:

That you don't have to be offsite to protect your backups properly.

Speaker:

He mentions that you could use strict network segmentation or other mechanisms

Speaker:

to ensure separation, which would protect you in the case of ransomware, but

Speaker:

may not protect you from all disasters

Speaker:

yeah.

Speaker:

could occur.

Speaker:

Agreed.

Speaker:

and, and I don't, I don't have an issue with that, Obviously, I'll say obviously

Speaker:

I work at a service-based backup company.

Speaker:

And we see that as the easy it's easy peasy.

Speaker:

All our backups are off site.

Speaker:

I'm not against, you know, as a backup expert, I'm not against onsite backups.

Speaker:

There's a lot of good reasons for an onsite copy, but I completely agree

Speaker:

with this person that you have to protect that onsite copy from attacks.

Speaker:

And there are a lot of very common backup designs, incredibly common backup designs

Speaker:

that do not that the default installation of those products do not protect you.

Speaker:

Right.

Speaker:

And I, and I'll, I don't wanna, I don't wanna pick on our friends at

Speaker:

Veeam, but that's a perfect example.

Speaker:

The guys from Veeam came on here and they explained to you, if you

Speaker:

listen, if you haven't seen those episodes, go back and listen to them.

Speaker:

Uh, about, you know, when they talked about the, the Conti ransomware attacks

Speaker:

and how you can configure your Veeam backups to protect against that.

Speaker:

My concern is that most of their customers are not listening to this podcast, by

Speaker:

the way, they're more than welcome.

Speaker:

All 700,000 Veeam customers are more than welcome to come listen to the podcast.

Speaker:

But if you just do the default installation and you don't take their

Speaker:

recommendations on how to further protect your data, it's no different

Speaker:

than any of the other products, right?

Speaker:

So

Speaker:

Read

Speaker:

you've got to stop doing that.

Speaker:

Read the manual, read the best practices.

Speaker:

Call Rickatron.

Speaker:

Rickatron'll sort, you out and.

Speaker:

So he talks about that.

Speaker:

He also talks about testing, your backups.

Speaker:

I'm editing right now, like literally in I'm in the middle of editing

Speaker:

the podcast, the episode of the restore test gone horribly wrong.

Speaker:

backup.

Speaker:

It's going to be a great episode.

Speaker:

The.

Speaker:

Yeah, Schrodinger's backup.

Speaker:

Exactly.

Speaker:

That's going to, if, yeah, if you haven't heard that episode

Speaker:

go back and listen to it.

Speaker:

it's a

Speaker:

great,

Speaker:

episode.

Speaker:

of the article

Speaker:

And

Speaker:

to it,

Speaker:

then he,

Speaker:

Yeah.

Speaker:

yes, he does.

Speaker:

did he actually refer to Shrodinger's

Speaker:

backup Schrodinger's backup

Speaker:

Yeah.

Speaker:

HInging your company's

Speaker:

and this one?

Speaker:

backup thought experiment is a terrible idea.

Speaker:

Don't do that.

Speaker:

Nice.

Speaker:

and then why don't you talk about the decryption part?

Speaker:

Yeah.

Speaker:

So I guess the final part right.

Speaker:

Is you've been hit with encryption, right?

Speaker:

now what do you do?

Speaker:

And most cases, it's.

Speaker:

You can try to get, if you're lucky, there might be a free

Speaker:

decryptor out there for your data.

Speaker:

It's just going to take a very long time.

Speaker:

And if you do pay the ransom and you have to understand that paying the ransom may

Speaker:

be illegal to some of these groups, right?

Speaker:

They'll give you back a decryption key.

Speaker:

Hopefully it'll work.

Speaker:

It's not, it's in the ransomware.

Speaker:

Group's best interest not to cheat you there, but you're

Speaker:

taking a risk there as well.

Speaker:

And then finally,

Speaker:

Okay.

Speaker:

Once you've actually decrypted your data.

Speaker:

You've gone back up and running.

Speaker:

There's nothing that prevents them from either coming back

Speaker:

and attacking you again, if you haven't fixed anything right.

Speaker:

Or the next group coming back.

Speaker:

Cause that's another common thing is one group gets in encrypts your data.

Speaker:

Another group figures out a different mechanism because they

Speaker:

know now that you're willing to pay.

Speaker:

And so they might come after you as well.

Speaker:

So

Speaker:

And then.

Speaker:

decrypted, it's not the end of the story.

Speaker:

And then the there's a what's next and all of these words, and this is a

Speaker:

really long series of posts, which I highly recommend you go look through.

Speaker:

There's one part where they typed in all caps, and this is it right when

Speaker:

you're done, whatever you did restore, pay the ransom, whatever it is.

Speaker:

It's not over, you clearly have a serious gap in your defenses.

Speaker:

You need to find these and fix them.

Speaker:

And then this is all caps and you need to understand that those gaps are bigger

Speaker:

than just whatever the initial breach vector was as highlighted in parts one

Speaker:

and two of this series, there are several opportunities to stop a ransomware

Speaker:

breach before it gets to this point.

Speaker:

there, there was some other.

Speaker:

It was another one that I read, somebody, they said, if I was at a company that had

Speaker:

a highly, I think it was actually in here.

Speaker:

If I was at a company that a highly publicized breach does this hurt my

Speaker:

chances of getting a job and the author of this article didn't think so, because they

Speaker:

basically said you now have experience

Speaker:

Yep.

Speaker:

and,

Speaker:

was actually at the end of this article is where he wrote about that.

Speaker:

Yeah.

Speaker:

He's yeah.

Speaker:

right,

Speaker:

you should actually show that you've gone through this because for a lot

Speaker:

of people it's just theoretical.

Speaker:

They've never experienced it.

Speaker:

It's like you Curtis.

Speaker:

I can sit here and talk about like how to back up your data, how to restore

Speaker:

your data, ideally how it should be done.

Speaker:

But I've never cut my teeth in a production environment, trying to do a

Speaker:

restore with people, yelling at me over my shoulder or watching over my shoulder.

Speaker:

Right.

Speaker:

You have, and I think that's the difference, right?

Speaker:

Is you

Speaker:

Yeah.

Speaker:

that experience because trial by fire.

Speaker:

Yeah, I, you just reminded me of, and I know I've told this story before, but not

Speaker:

everybody's listening to every episode.

Speaker:

My, one of my favorite restore stories was back at my first big job.

Speaker:

And we had somebody in the NOC that was coordinating the various things that

Speaker:

were happening of this big restore.

Speaker:

And we had another guy that was in the data center that

Speaker:

was actually doing things and.

Speaker:

He was talking to the person who was on the phone in the NOC.

Speaker:

And he didn't know that he was on speaker.

Speaker:

And so he said, he's oh, so you know where you are.

Speaker:

I'm in the NOC.

Speaker:

He goes, oh, so I suppose you have Tom and Tom standing on

Speaker:

your left and right shoulder.

Speaker:

And he was referring to our boss's boss and our boss's boss.

Speaker:

And, the, that would be Tom Thomaides and Tom Lackey.

Speaker:

And they were indeed standing both on his left and right shoulder.

Speaker:

And they said that when he said that, oh, so you have Tom and Tom standing

Speaker:

on your left and right shoulder.

Speaker:

He said they just both took one step back.

Speaker:

but it's true, right?

Speaker:

It's a stressful thing everyone's watching to make sure it goes perfect.

Speaker:

And, we wish you all the best of luck.

Speaker:

I continue to be concerned about our friends over there in the Ukraine.

Speaker:

And, we wish them the best of luck and.

Speaker:

You should also be concerned about the potential ramifications that

Speaker:

all of that has on continued further attacks on your data center and read

Speaker:

this article, read every word of this article, not just this summary and,

Speaker:

Read the three

Speaker:

read all three parts and we'll put links to it in the show description

Speaker:

so that you can easily find it.

Speaker:

Cause finding stuff on Reddit is not necessarily easy.

Speaker:

Thanks again Prasanna for your wise, shipping advice and, a

Speaker:

good commentary on this as well.

Speaker:

Yeah

Speaker:

well.

Speaker:

anytime Curtis and I hope I know, normally when we talk about

Speaker:

ransomware, you get very depressed.

Speaker:

So I, it feels like this isn't a depressing article.

Speaker:

It feels like here are things you should be doing.

Speaker:

So

Speaker:

it feels

Speaker:

Here are things that you should do now.

Speaker:

Yeah,

Speaker:

Yeah, absolutely.

Speaker:

all right, thanks to the listeners.

Speaker:

we'd be nothing without you remember to subscribe