Things to do to protect from ransomware:
-
Backup
- Have multiple copies of backups. Local and online. Password protect backup on NAS
- Have shadow copies setup on servers. Not effective if server is hit directly but can help if shared folder on server is encrypted from workstation
-
Staff training
- Train staff not to open email and attachments from unknown users
- Staff should not open any attachments that are unusual
-
Antivirus
- Have an updated next gen anti-virus that checks what programs do, not just signatures.
-
Patching
- Keep windows and any other programs, ie acrobat reader, java, flash, fully updated to fix security vulnerabilities.
-
Firewalls
- Lock down firewalls to close any open ports that are not used.
-
Remote access
- Limit remote access to server and workstations. Make sure any users that need remote access have strong passwords. If terminal services are used connect through VPN or have secure connections.