© 2017 Unitrends 1#1 All-in-One Enterprise
Backup and Continuity
Ransomware: Why
Are Backup
Vendors Trying To
Scare You?
Mark Jordan, VP Technology
© 2017 Unitrends 2
It was the best of times, it was the
worst of times, it
was the age of wisdom, it was the
age of foolishness
© 2017 Unitrends 3
 St Louis Public Libraries
 Cannot return or borrow books, cannot access computer facilities in 16
branches
 City refuses to pay $35,000 ransom
 Will wipe and build from scratch, a solution that will take weeks
© 2017 Unitrends 4
 Bethlehem, NY Central School District
 5000 students, 800 staff
 Multiple ransomware attacks
 Quick, full recovery from backup, $0 ransom paid
© 2017 Unitrends 5
Source: Palo Alto Networks
© 2017 Unitrends 6
Ransomware took in $1-billion in 2016
© 2017 Unitrends 7
© 2017 Unitrends 8
Delta Airlines August 2016
Data Center Outage
Cost the Company
$150,000,000
Average Cost of a
Single Data Center Outage $730,000
© 2017 Unitrends 9
CryptoWorms – the future of
ransomware
• Self-propagating
• Find vulnerable network targets
• Targets unprotected executable files
• Avoids detection
Jigsaw – encrypts and deletes
• Starts deleting files if the ransom is
not paid
© 2017 Unitrends 10
Source: Singapore Computer Emergency Response
Team
© 2017 Unitrends 11
Sadly, sadly, the sun rose; it rose
upon no sadder sight than the
man of good abilities and good
emotions, incapable of their
directed exercise, incapable of his
own help
© 2017 Unitrends 12
© 2017 Unitrends 13
• Are you sending data to a shared network
drive?
• Are you using a cloud backup service?
• Do your backups sit on a Windows-based
target?
Backups are not necessarily safe
© 2017 Unitrends 14
© 2017 Unitrends 15
© 2017 Unitrends 16
Then tell the Wind and Fire where
to stop, but don't tell me
© 2017 Unitrends 17
Play Defense
Play Offense
Don’t forget about your backup players
© 2017 Unitrends 18
 Keep software up to date
 Use virus detection and antivirus prevention
 Educated users on security protocols such
 Avoid clicking untrusted emails and attachments
 Watch out for obvious and not so obvious file
extensions
Offense: Start With Basic Protection
© 2017 Unitrends 19
 Disable Active-X content in Microsoft offices apps
 Have firewalls block Tor, I2P and restrict ports
 Block active ransomware variants from calling home to encryption key
servers
 Block binaries from running from popular ransomware installation
paths (e.g. %TEMP%)
Defense: Be Proactive with counter-measures
© 2017 Unitrends 20
Backups are Crucial
© 2017 Unitrends 21
Backups are Crucial
• Backup your data
• Know your recovery objectives
• Have instant recovery
• Have multiple recovery points
• Get your data offsite
Test Recovery!
© 2017 Unitrends 22
How does Unitrends fit
into this story?
© 2017 Unitrends 23
All-in-One
Enterprise
Backup and
Continuity
Old World
• More vendors; more finger pointing, more management
• More work setting up and constantly tuning
• Limited continuity; little or no recovery assurance
• Windows deployment malware susceptible
• Fragmented & lower customer satisfaction; more worries
New World
• One vendor; one throat to choke
• Less work - rack, connect, and go
• Local & cloud continuity with recovery assurance
• More security; purpose-built hardened Linux
• Unified & higher customer satisfaction; more confidence
© 2017 Unitrends 24
Have Less:
The
Ruthless
Pursuit of
Simplicity
Old World New World
© 2017 Unitrends 25
Best
Customer
Satisfaction
: One
Support Call
for
Everything
Old World New World
© 2017 Unitrends 26
Unitrends
Cloud
Old World
• Third-party cloud vendors, limited or no DRaaS
• No recovery assurance, limited retention; more worries
• No SLAs, more worries, network bottlenecks
New World
• No finger-pointing; less management: single vendor
• Physical & virtual DRaaS
• Industry only physical & virtual recovery assurance
• Infinite retention available; more confidence
• 1 hour recovery SLA available; more confidence
• WAN optimized & Rapid Data Seeding
WAN
OpenVPN
w/Throttling
OR
© 2017 Unitrends 27
Confidence
from
Recovery
Assurance
Old World
• Praying that backups recovered successfully
• Scrambling during DR exercises
• Rarely, if ever, testing DR
• Spending hours creating manual DR reports
New World
• Fully automated, application-level testing and failover
• Proactively uncover recovery issues for physical & virtual
• Business-level DR compliance report automation
• Available for local, DR site, and Unitrends Cloud
© 2017 Unitrends 28
It is a far, far better thing that I do,
than I have ever done; it is a far,
far better rest that I go to than I
have ever known
© 2017 Unitrends 29
+Unitrends
@Unitrends
@Unitrends
@Unitrends
+Unitrends
@UnitrendsInc
© 2017 Unitrends 30
+Unitrends
@Unitrends
@Unitrends
@Unitrends
+Unitrends
@UnitrendsInc
Questions?
© 2017 Unitrends 31
Thank You

Ransomware: Why Are Backup Vendors Trying To Scare You?

  • 1.
    © 2017 Unitrends1#1 All-in-One Enterprise Backup and Continuity Ransomware: Why Are Backup Vendors Trying To Scare You? Mark Jordan, VP Technology
  • 2.
    © 2017 Unitrends2 It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness
  • 3.
    © 2017 Unitrends3  St Louis Public Libraries  Cannot return or borrow books, cannot access computer facilities in 16 branches  City refuses to pay $35,000 ransom  Will wipe and build from scratch, a solution that will take weeks
  • 4.
    © 2017 Unitrends4  Bethlehem, NY Central School District  5000 students, 800 staff  Multiple ransomware attacks  Quick, full recovery from backup, $0 ransom paid
  • 5.
    © 2017 Unitrends5 Source: Palo Alto Networks
  • 6.
    © 2017 Unitrends6 Ransomware took in $1-billion in 2016
  • 7.
  • 8.
    © 2017 Unitrends8 Delta Airlines August 2016 Data Center Outage Cost the Company $150,000,000 Average Cost of a Single Data Center Outage $730,000
  • 9.
    © 2017 Unitrends9 CryptoWorms – the future of ransomware • Self-propagating • Find vulnerable network targets • Targets unprotected executable files • Avoids detection Jigsaw – encrypts and deletes • Starts deleting files if the ransom is not paid
  • 10.
    © 2017 Unitrends10 Source: Singapore Computer Emergency Response Team
  • 11.
    © 2017 Unitrends11 Sadly, sadly, the sun rose; it rose upon no sadder sight than the man of good abilities and good emotions, incapable of their directed exercise, incapable of his own help
  • 12.
  • 13.
    © 2017 Unitrends13 • Are you sending data to a shared network drive? • Are you using a cloud backup service? • Do your backups sit on a Windows-based target? Backups are not necessarily safe
  • 14.
  • 15.
  • 16.
    © 2017 Unitrends16 Then tell the Wind and Fire where to stop, but don't tell me
  • 17.
    © 2017 Unitrends17 Play Defense Play Offense Don’t forget about your backup players
  • 18.
    © 2017 Unitrends18  Keep software up to date  Use virus detection and antivirus prevention  Educated users on security protocols such  Avoid clicking untrusted emails and attachments  Watch out for obvious and not so obvious file extensions Offense: Start With Basic Protection
  • 19.
    © 2017 Unitrends19  Disable Active-X content in Microsoft offices apps  Have firewalls block Tor, I2P and restrict ports  Block active ransomware variants from calling home to encryption key servers  Block binaries from running from popular ransomware installation paths (e.g. %TEMP%) Defense: Be Proactive with counter-measures
  • 20.
    © 2017 Unitrends20 Backups are Crucial
  • 21.
    © 2017 Unitrends21 Backups are Crucial • Backup your data • Know your recovery objectives • Have instant recovery • Have multiple recovery points • Get your data offsite Test Recovery!
  • 22.
    © 2017 Unitrends22 How does Unitrends fit into this story?
  • 23.
    © 2017 Unitrends23 All-in-One Enterprise Backup and Continuity Old World • More vendors; more finger pointing, more management • More work setting up and constantly tuning • Limited continuity; little or no recovery assurance • Windows deployment malware susceptible • Fragmented & lower customer satisfaction; more worries New World • One vendor; one throat to choke • Less work - rack, connect, and go • Local & cloud continuity with recovery assurance • More security; purpose-built hardened Linux • Unified & higher customer satisfaction; more confidence
  • 24.
    © 2017 Unitrends24 Have Less: The Ruthless Pursuit of Simplicity Old World New World
  • 25.
    © 2017 Unitrends25 Best Customer Satisfaction : One Support Call for Everything Old World New World
  • 26.
    © 2017 Unitrends26 Unitrends Cloud Old World • Third-party cloud vendors, limited or no DRaaS • No recovery assurance, limited retention; more worries • No SLAs, more worries, network bottlenecks New World • No finger-pointing; less management: single vendor • Physical & virtual DRaaS • Industry only physical & virtual recovery assurance • Infinite retention available; more confidence • 1 hour recovery SLA available; more confidence • WAN optimized & Rapid Data Seeding WAN OpenVPN w/Throttling OR
  • 27.
    © 2017 Unitrends27 Confidence from Recovery Assurance Old World • Praying that backups recovered successfully • Scrambling during DR exercises • Rarely, if ever, testing DR • Spending hours creating manual DR reports New World • Fully automated, application-level testing and failover • Proactively uncover recovery issues for physical & virtual • Business-level DR compliance report automation • Available for local, DR site, and Unitrends Cloud
  • 28.
    © 2017 Unitrends28 It is a far, far better thing that I do, than I have ever done; it is a far, far better rest that I go to than I have ever known
  • 29.
    © 2017 Unitrends29 +Unitrends @Unitrends @Unitrends @Unitrends +Unitrends @UnitrendsInc
  • 30.
    © 2017 Unitrends30 +Unitrends @Unitrends @Unitrends @Unitrends +Unitrends @UnitrendsInc Questions?
  • 31.
  • 32.