
Ransomware is one of the most serious security threats businesses face today.
It calls for an equally robust response, far beyond cautioning users about suspicious emails. A multi-layered approach is required to reduce exposure to ransomware attacks and to recover encrypted data more quickly and effectively.
Citrix Workspace solutions provide an integrated and flexible framework to secure apps, data, and networks from malware infections of all kinds.
By publishing virtual web browsers and email clients with Citrix Virtual Apps, IT can isolate endpoints from the corporate network and ensure that infected hosts are unable to spread ransomware further or place more company data at risk.
Furthermore, Citrix Endpoint Management enables secure mobility through containerisation to protect data on smartphones and tablets.
Citrix Content Collaboration captures file versions in real time, ensuring that a clean version is always available to replace a file that has been encrypted by ransomware.
In this way, IT can protect the business and its data, minimise disruptions, and avoid rewarding hackers for their illicit activity.
Why a Multi-Layered Approach Matters
Prevent digital extortion by introducing a multi-layered approach. This helps reduce exposure and recover encrypted data more quickly and effectively.
Recent years have seen the internet flooded with ransomware variants such as:
- Cryptolocker
- Locky
- KeRanger
- CryptoWall
- TeslaCrypt
Initially targeting consumers, these scripts increasingly target organisations with highly sensitive and high-value data, including:
- Healthcare providers
- Banks
- Legal firms
- Financial institutions
How Ransomware Works
Once activated by an unwitting user, ransomware contacts a command-and-control server to obtain a unique AES encryption key.
It then encrypts critical files found on:
- Local drives
- Network drives
- Cloud-connected storage
At that point, the data is under the control of the hacker, who demands payment to recover it or prevent disclosure.
The ransom may range from hundreds of Rands for individual consumers to many thousands for businesses.
Payments are often demanded in Bitcoin, making the response even more challenging.
The Business Impact of Ransomware
As an illicit business model, ransomware is as effective as it is simple, reportedly earning hundreds of millions of dollars for the CryptoWall script alone.
For victim organisations, recovering access to data and systems can literally be a matter of life and death.
One example is a hospital where electronic medical records (EMR), CT scan systems, documentation, laboratory systems, and pharmacy functions become unavailable.
Targeted companies across every industry, including:
- Education
- Utilities
- Retail
- Finance
- Government
can face equally severe consequences.
These organisations may lose access to:
- Email systems
- Payroll systems
- Customer information
- Production data
- Critical operational systems
Why Paying the Ransom Is Not the Answer
Even without the countdown timer displayed by most ransomware variants, the urgency of a response is clear.
Paying the ransom, typically in Bitcoin through a self-service process, is an unattractive option.
Doing so:
- Creates additional cost
- Rewards criminal activity
- Encourages future attacks
Citrix solutions enable four highly effective measures for reducing exposure to ransomware and keeping apps and data accessible to authorised users rather than hackers.
Virtualisation, enterprise mobility management, and enterprise file synchronisation help protect computers, tablets, smartphones, and other endpoints against ransomware infections while enabling rapid recovery if a breach occurs.
Four Ways Citrix Helps Reduce Ransomware Exposure
1. Secure Web Access
Shield web application users from infection and keep sensitive data off the endpoint by publishing virtualised, sandboxed, and hardened browsers instead of relying on locally installed browsers.
2. Secure Email Access
Prevent email-borne ransomware from compromising endpoints by publishing a virtualised, sandboxed, and hardened email client.
3. Protect Mobile Devices
Protect mobile devices using:
- Containerisation
- Encryption
- Blacklists and whitelists
- Device compliance checks
4. Recover Encrypted Data Faster
Ensure rapid recovery of ransomware-encrypted data through a secure and robust enterprise file synchronisation and sharing service.
Emerging Threats
Reports have begun to surface of “boneidleware”, malware that imitates ransomware and demands payment but deletes data rather than encrypting it.
This leaves victims who pay with nothing recovered.
Refusing to pay can be even worse.
IT teams may be forced to shut down systems and networks quickly to stop ransomware from spreading. This creates significant disruption while encrypted data is restored from backups.
Even then, the encrypted data remains in the hands of the attacker, who may attempt to profit through sale or disclosure.
A Better Approach to Ransomware Protection
The traditional approach to ransomware protection focuses on:
- User education
- Anti-malware solutions
- Frequent backups
- Keeping Bitcoin available as a last resort
While these measures are sensible, they are no longer enough.
Numerous high-profile incidents have demonstrated that a stronger, system-wide approach is required.
The goal should be to keep data out of harm’s way entirely.
Citrix has long helped customers secure applications, data, and systems through a secure architecture supported by:
- Secure access control
- Secure mobility
- Data protection
- Risk management
- Business continuity
As ransomware threats continue to grow, Citrix provides solutions and best practices that help prevent breaches and ensure data remains available even when attacks occur.
We strongly recommend the following four components of Citrix Workspace as essential elements of a complete enterprise security and data protection strategy.