Don’t let your NAS data be “hijacked” – here’s how to protect it from ransomware attacks
The recent ransomware attack on QNAP-branded NAS has made more than one owner of this data storage solution nervous. A NAS (network-attached storage) is a server that functions as a repository for files and data. It is, in itself, a computer with its own operating system, and in case of data deletion (accidental or not) it can serve as protection, but if it is compromised it becomes an additional problem. It is impossible to be 100% safe from malware, but here are some tips to minimise its likelihood. 1. Update your software Although it may seem like a basic thing to do, it is necessary to always use the latest available software version of the operating system. This way, the only security flaws that malware writers can exploit are those that have not yet been discovered by the manufacturer, the so-called “zero-day” flaws. To make this more bearable, it is best to configure the NAS to perform updates automatically. If you are not in favour of automatic updates, it would be advisable to have an alert enabled on your mobile phone to indicate when there are updates. 2. Do not use the administrator user Keeping the NAS up to date prevents many attacks, but there are other ways in which ransomware can access the NAS. One common way to use the NAS is as a network drive. If a computer on the network has been infected with ransomware and is authenticated as an administrator on the NAS, it has the ability to remotely encrypt the entire drive. It is true that using the administrator user is not very common...
Spain suffers 40,000 cyber-attacks a day: administrations and SMEs, among the most vulnerable targets
Since the beginning of the year, and comparing data with previous years, cyber-attacks seem to have multiplied in Spain. Last March, the cloud security company Datos101 published a report with the following results: in one year, cyber-attacks have grown by 125% in Spain, bringing the number of daily cyber-attacks to 40,000. The report came weeks after the Spanish Public Employment Service (SEPE) saw its data and computers blocked by the RYUK ransomware. Last week, three months later, the Ministry of Labour was again attacked by ransomware. How well protected are public entities? According to the National Cryptologic Centre (part of the CNI), only six websites of the General State Administration have a Certificate of Conformity of the National Security Scheme (ENS) granted by an accredited certification body. However, Samuel Parra, data protection specialist and CEO of the specialised company Égida, told Nius Diario: “Being ENS-certified is a guarantee, important, yes, but it does not mean that you have 100% IT security because it does not exist, neither in Spain nor anywhere else in the world. This is why it is perfectly compatible for an administration to be the victim of an attack and also to be certified in the ENS. However, non-certified administrations are going to be more vulnerable”. Cyberkidnapping for millions in bitcoins Last May, the United States suffered a cyber-attack that led to the hijacking of the oil pipeline linking Texas and New York. The cybercriminals used a ransomware-type virus to steal all of the company’s data, crippling its operations. Following the pattern of ransomwares, they demanded a ransom to unlock the data, and received 75 bitcoins...
Cybersecurity: the final competitive advantage
During the last months, the number of pieces of news related to cyberattacks has grown exponentially. According to the UN, every 39 seconds a cyber-attack takes place in the world, a most worrying figure. Moreover, the number of malicious emails has grown by 600% in the last year. The targets of these cyber-attacks are Ibex 35 companies, SMEs, public corporations… The reality is that these attacks are by no means new, neither in terms of the techniques used nor the objectives they pursue. According to Hiscox Cyber Readiness Report 2020, the average cost per cyberattacks in Spain in 2020 was 66.800€ and it’s nearly half a million in the case of bigger companies. Apart from that, that cost is 30% higher if compared to the average of other countries. Why are cyberattacks profitable in Spain? The main reason why experts think that cyber criminality is profitable in Spain is because there is not enough company culture related to cybersecurity, both among managing and rank-and-file employees. It’s true that the budget for cybersecurity is increasing lately, but nevertheless IT teams are not yet provided with sufficient resources to undertake investments in security infrastructure, nor for the recruitment of cyber-security experts. As a consequence, the attacks that would be easily detected with the proper tools are succeeding in attacking the company. The most common attacks are: phishing (fraudulent emails that steal information or install malwares), those that exploit social engineering techniques (deceiving employees to make payments or providing confidential information) and ransomware (what happened to Everis, extorting through the theft of critical data). The effect of the COVID-19 in cybersecurity Because...


Recent Comments