southhamster Posted November 13, 2020 Posted November 13, 2020 We find sSophos central really useful here. You can or set ban to notify all sorts of things. 1
Zammo Posted November 13, 2020 Posted November 13, 2020 Well not really but hey ho. He's right The most common methods of deploying ransomware include: Spam / phishing emails – 67% Lack of cyber security training – 36% Weak passwords / access management – 30% Poor user practices / gullibility – 25% Malicious websites / web ads – 16% Other – 16% https://www.safetydetectives.com/blog/ransomware-statistics/ https://purplesec.us/resources/cyber-security-statistics/ransomware/#:~:text=New%20ransomware%20variants%20grew%2046,ransomware%20attack%20every%2014%20seconds.
mrcrazy04 Posted November 15, 2020 Posted November 15, 2020 The NCSC recommends using an application Allow List (I.e. application whitelisting) using AppLocker. Controlling what can be run on user workstations will make it much harder for an attacker to gain a foothold, reducing the risk of compromise of your estate. This is particularly the case with ransomware, as others have mentioned. NCSC has published some AppLocker rules that will allow most software to function. You’ll probably want to add additional rules for Chrome and Teams - I’d suggest allowing the digital signature and all name. The list of rules is here - https://www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/eud-security-guidance-windows-10-1809#applockerconfig. The most recent guidance is much shorter, so doesn’t list out the policies; but does include a set of GPOs you can download - https://www.ncsc.gov.uk/collection/mobile-device-guidance/platform-guides/windows-10 2
TechMonkey Posted November 16, 2020 Posted November 16, 2020 He's right The most common methods of deploying ransomware include: Spam / phishing emails – 67% Lack of cyber security training – 36% Weak passwords / access management – 30% Poor user practices / gullibility – 25% Malicious websites / web ads – 16% Other – 16% https://www.safetydetectives.com/blog/ransomware-statistics/ https://purplesec.us/resources/cyber-security-statistics/ransomware/#:~:text=New%20ransomware%20variants%20grew%2046,ransomware%20attack%20every%2014%20seconds. Odd stats, as I don't accept "lack of cyber security training" as a deployment method. Had a look though and Sophos figures show 29% for file download/email link so will half concede the overall point. Though that shows more that filtering would help most. Bad communication on my part though as I was more railing against the reductionist argument.
paulkerton Posted November 16, 2020 Posted November 16, 2020 Is it not helpful for the teachers to be able to install software? Surely with good AV and other protection it should be fine? Do we really need to be preventing the odd bit of occasional other use by teacher's kids? Is that likely to do any harm? A happier workforce is a more productive workforce, no? Just playing devils advocate. Your thinking is sound, but at one point I had 15% of a server's space filled with people's personal photos and holiday snaps. As much as I can appreciate a good bikini photo, by the same breath I prefer space for the kids work! 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now