2022-03-31-埃森哲-Ransomware_reoriented_20页_4mb
报告摘要
Ransomware Reoriented: From Technical Problem to Business Crisis
Key Messages
- Ransomware is viewed by many organizations purely as a technical/security challenge, rather than a business risk impacting operations, reputation, and finances.
- Traditional crisis management must evolve to address ransomware disruption effectively, integrating business, legal, and technical perspectives.
- A holistic understanding and business-led approach to ransomware response and recovery is crucial for quicker recovery.
Key Challenges
- Evolution of Threat: Traditional incident response plans are inadequate for modern ransomware that causes widespread disruption and system damage beyond simple file encryption.
- Communication Complexity: Existing crisis communication strategies lack the agility required for rapidly evolving attacks and need to address diverse stakeholder audiences effectively.
- Borderless Impact: Ransomware affects not just the primary organization but also customers, suppliers, third-party vendors, financial holdings, and M&A targets globally.
- Low Awareness/Poor Preparation: Critical business processes and dependencies are often poorly understood, hindering effective crisis management. Leadership communication/experience during crises is also often lacking.
Response Recommendations
- Integrated Business/Security Approach: Develop response plans balancing security efforts with business strategy and priorities.
- Clear Decision Framework: Define processes and accountability for critical decisions (e.g., paying ransom) based on business impact analysis.
- Robust Crisis Communication: Create agile, industry-specific communication plans to manage internal and external stakeholders transparently during evolving events.
- Holistic Recovery Planning: Prioritize restoration of critical business systems and processes over purely technical ones based on business value and dependencies.
- Executive Involvement: Engage business leaders in response planning, tabletop exercises, and real-time decision-making.
- Continuous Improvement: Regularly test and refine incident response and business continuity plans.
Practical Steps
- Enhance Preparedness: Understand the business value chain and prioritize critical operations.
- Define Agile Communication Strategy: Develop and validate plans considering technical and business aspects.
- Engage Executives: Involve C-suite/bod in response strategy and testing through realistic simulations.
Conclusion
Ransomware is a complex, business-level crisis requiring a coordinated response across the entire enterprise, focusing on effective crisis management to enhance resilience and minimize long-term impact.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载