How Organizations Can Protect Against Ransomware

How to Keep Ransomware From Wreaking Havoc in Your Organization

How to Keep Ransomware From Wreaking Havoc in Your Organization
Written By
Darryl K. Taft
Darryl K. Taft
Nov 1, 2016
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More


How to Keep Ransomware From Wreaking Havoc in Your Organization

1 - How to Keep Ransomware From Wreaking Havoc in Your Organization

Ransomware has become a real challenge for companies; if they don’t remain vigilant, they will be sure to fall victim to hackers. Here are some tips to keep your data safe.


Pay Attention

2 - Pay Attention

It’s really that simple. It doesn’t take a technical mastermind to carry out a hack—a cyber-attacker just needs to access basic data, usually available to the public online. The next time you get an email from so-and-so at whatever bank requesting an employee’s W2 form, stop. Forward the email to your direct manager or someone on your IT team. Think the email could be legit? Verify your hunch: Look at the domain name, website address and the sender’s name to make sure there are no typos or intentional misspellings.


Consider Your Employees to Be a Key Part of Your Defenses

3 - Consider Your Employees to Be a Key Part of Your Defenses

Organizations need to combine rigorous employee training with technology. While other delivery methods are used—botnets and USB sticks, for example—email is, and will remain for the foreseeable future, the primary delivery mechanism, given its low cost, ubiquity and difficulty to secure fully. That being said, organizations need staff to be aware of the different types of attacks they could find in their inbox, ransomware being a currently popular type. Employee awareness and training should be a continuous thing, not a once-a-year training. As employees click and browse through their inbox, they should be informed, warned and blocked as they go.


Advertisement

If It Seems Suspicious, It Probably Is

4 - If It Seems Suspicious, It Probably Is

If you receive an email that contains tracking information from a postal service but you aren’t expecting a shipment, stop. Don’t click the tracking URL because it’s really a malicious link disguised as something familiar. The same goes for emails containing attachments—these could contain malicious code.


Everyone’s a Target—but Some Have a Public Bull’s Eye

5 - Everyone's a Target—but Some Have a Public Bull's Eye

If you work in human resources, sales or communications, for example, it’s likely your name and contact information are listed on the company’s website. If this is the case, you need to be extra vigilant when it comes to practicing good security. Cyber-attackers will view you as an easy steppingstone to gain access to senior executives or company information. Be on the lookout for fraudulent emails, always.


Think Before You Share

6 - Think Before You Share

Here’s a wake-up call for you: Cyber-attacks are not random. They are well-researched and usually architected using information you share online. Personal details including where you work, your job title, who you’re friends with, and what you’re doing and when are plastered all over social media sites such as LinkedIn and Facebook. Hackers research these sites to gather intelligence on unsuspecting victims—this is called social engineering.


Don’t Be a Follower

7 - Don't Be a Follower

After everything you just learned, this one should be a no-brainer. If you receive an email from a bank or financial institution requesting your credentials, don’t click the link—it could be malicious. Even if the email is branded with what looks like legitimate logos and fonts, it could be a scam. Instead, type in the actual website address, verify the secure connection using “HTTPS,” then provide your details in a legitimate, secure environment.


Advertisement

Have Comprehensive Backup and Recovery Capabilities

8 - Have Comprehensive Backup and Recovery Capabilities

In the event an attack manages to breach their prevention, companies need to have a comprehensive backup and recovery plan in place, including for their email.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.