How a routine Cyber Essentials Plus assessment helped thwart a serious ransomware attack

As a Cyber Essentials Certification Body, we conduct audits on businesses as part of the Cyber Essentials Plus process, in order to verify that the controls they claim to have in place are there, and ultimately make sure they’re not leaving themselves open to cyber attack. This third party verification is the major difference between Cyber Essentials Plus and the entry level Cyber Essentials certification.

We were recently approached by an organisation we won’t name (for obvious reasons) to help them achieve Cyber Essentials Plus. We were conducting a vulnerability scan as part of the audit, when we were horrified to discover the presence of Petya Ransomware installed across all the devices in our sample set, including the servers.  The scan also identified some major areas of weakness that may well have been the reason the ransomware was able to infect their network.  In this blog, we’ll explore what ransomware is, who is most at risk of a ransomware attack and what to do if you become a victim. 

What is ransomware? 

As the name suggests, ransomware is a type of malware that encrypts all your files or threatens to publish your data on the internet, unless a ransom is paid.  Unlike some malware that may be working away as a background process on your device, a victim will be in no doubt that they’re suffering a ransomware attack, as their screen display becomes something similar to this:    

It is an incredibly frightening scenario to find yourself in. The above example informs the victim that their files have been encrypted. But it also delivers two further threats: ‘If you don’t pay within a certain time frame, the ransom will increase’, and ‘if you don’t pay within a certain time frame, your files will be deleted’.   

“The worst 3 weeks of my life”

In 2019, operations at Offix Group in Switzerland were plunged into chaos when all the computers were encrypted and taken offline by a ransomware attack.  Martin Kelterborn, Chief Executive, describes the experience as ‘the worst 3 weeks of my life’.  They watched live as all their product pictures across their websites were encrypted one by one.  With 230 employees but no computers to process the tens of thousands of orders, the boss declared the company was ‘dead and out of business.’

It was the Ryuk ransomware gang that were responsible. They demanded a payment of 45 Bitcoin, which at the time equated to around half a million dollars.  Paying the ransom was considered, but as they had destroyed so much of the system, Offix chose to rebuild the system from scratch – which cost about the same.   

Colonial Pipeline Ransomware Attack 

Very recently, the Colonial Pipeline in the US made headlines. They had been targeted by a cyber-criminal gang known as DarkSide. This attack is described as one of the most significant cyber-attacks on critical national infrastructure in history, although the attackers claimed that this was not the intention – they merely sought to make money.    

Unbeknown to the attackers, the physical infrastructure of the fuel pipelines including pressure sensors, thermostats, valves and pumps that are used to monitor and control the flow of diesel, petrol and jet fuel across hundreds of miles of piping, and even the use of a ‘smart pig’ (pipeline inspection gauge) robot that scuttles through its pipes checking for problems, are all connected to a central network and controlled entirely by computers rather than people – which is why the pipeline itself became vulnerable to malicious cyber-attacks.

The organisation responded by taking the whole system offline. This affected the fuel supply across its 5,500 mile pipeline. It usually carries 2.5 million barrels per day on the East Coast of USA.  This resulted in fuel prices rising and a number of states declaring a state of emergency.  Scenes reminiscent of our Lockdown ‘toilet paper crisis’ were familiar across the US, as citizens scrabbled to protect themselves from the hardships that would follow if they should not be able to fuel their vehicles.  

Fortunately, after 6 days Colonial restarted operations. However, it warned that ‘it could take several days for the product delivery supply chain to return to normal’.  So we should be mindful that the impact of a ransomware attack can have serious implications right down through the supply chain.   

Too close to home 

As mentioned earlier, Securious came face to face with Petya Ransomware during a Cyber Essentials Plus audit.  The business required Cyber Essentials Plus for a contract and they provided answers that they believed to be correct without checking to make sure.  “Are all of your devices running supported operating systems?”  “Yes” – or so they thought…

Audit day arrived, we deployed the internal vulnerability scanners, and the disaster began unfolding.  We very quickly noted the presence of unsupported operating systems, which immediately constituted an automatic failure of the entire audit.  If this wasn’t bad enough, upon further inspection we found Petya Ransomware present on all devices.  The trigger for the attack, was for one device to reboot – this was a terrifying position to be in.  We immediately ceased the audit, removed our scanners, and informed the business of their critically precarious position.

They called in an incident response team. They ran ransomware removal software, and are busy updating their Operating Systems hoping to be on track for their Cyber Essentials audit again soon. 

What a nightmare for this company – yet this is actually a huge win for the Cyber Essentials audit, because it ensured this issue was found and could be resolved before the worst happened. This poor business, wildly busy with other important matters, were winging their Cyber Essentials Plus. They didn’t understand why the questions were important and said what was required to be compliant without checking it was true. I’m so glad that we discovered the ransomware before triggering the attack. And I’m sure the business will pay more attention to their Cyber Security the future. 

Defending against ransomware 

What would you do if you were a victim of a ransomware attack?  Would you pay the ransom to retrieve access to your systems?  Or… what?   If you do pay the ransom, you should be mindful that: 

  • The attackers may still not unencrypt your files after they receive payment – I mean… why would you trust these people? 
  • The ransomware will still be present on your devices, which means you’re likely to be targeted again in the future. 
  • Your money will be financing criminal gangs. 

If the ransomware attack is a threat to publish confidential data on the Internet, the National Cyber Security Centre offer advice on how to protect bulk personal data, taking you through steps to identify what you are protecting, who has access to this data and how you can protect it.

Adopting a Defence in Depth approach including:   

  • Only running supported operating systems and applications 
  • Keeping devices up-to-date with patching 
  • Having strong passwords 
  • Deploying a robust Anti-Virus (some include Ransomware detection) 
  • Using non-admin accounts for day-to-day business 
  • Ensuring Firewalls are enabled and configured correctly. 
  • Further protection can be added by filtering to allow only certain file types and/or using Allowed / Deny lists to allow / block certain websites. 

But there is something important that you could do, that Cyber Essentials actually doesn’t cover… 

Make Regular Backups 

Create regular back-ups and keep them separately from your main network to be prepared for a ransomware attack.  Ideally, keep multiple copies of your back-ups offsite or in a cloud service designed for this, as ransomware gangs increasingly target backups in order to increase their chances of payment.   

Prepare for an incident  

Given the catastrophe that can quickly unfold if an organisation ceases to have access to their systems, ensure that you know how to restore from a back-up – this can be a lengthy process and may still cause significant disruption to an organisation.  Create an Incident Response Plan, to help clarify the roles and responsibilities of staff and what processes will be followed.  The National Cyber Security Centre provide a service to assist with this called “Exercise in a Box” , which will help you identify how resilient your organisation is to a cyber-attack, and also to practise your response in a safe environment.    

The best form of defence

I think we can conclude that the best form of defence against a ransomware attack is simply being ready for one. They can have a catastrophic impact on your business and beyond, as demonstrated by the Colonial Pipeline example above. Preparing for it by thinking through what you’ll do should the worst happen, and ensuring you have usable backups separate from your main systems should stand you in good stead to recover swiftly. And of course, keeping your software up-to-date (along with staying on track with the other key controls that Cyber Essentials covers) should help reduce the chances of an attack happening in the first place. And remember that if you want real peace of mind, Cyber Essentials Plus includes third party verification of your systems, so you can be sure you’re in good shape.