Introduction

It’s estimated a ransomware attack targets a business every 11 seconds. On a global scale, experts predict ransomware will cause $20 billion (USD) in damages in 2021. As a result, it’s no surprise that ransomware protection has become an urgent business imperative for organizations, large and small, around the world.

A robust ransomware protection plan must include both preventative and recovery measures. Preventative measures attempt to keep ransomware from getting into the IT environment in the first place. However, for those attacks that do get in, preventative measures are also designed to contain and eradicate the infection before it can cause widespread damage.  Because no preventative measures can be 100% successful in perpetuity, organizations must have recovery measures in place. Recovery measures need to provide organizations a reliable, easy-to-use, cost-effective way to fully recover their business-critical applications and data, so they can return their operations to a normal state as soon as possible after an attack.

This guide focuses on the recovery measures that organizations need to consider. Starting with a brief overview of VMware’s holistic approach to ransomware protection, the guide provides practical set-up and recovery steps for VMware Cloud DR that IT professionals responsible for disaster recovery (DR), business continuity, or cybersecurity can use to prepare their organization to better recover from an attack.

Reference:

Cybercrime To Cost The World $10.5 Trillion Annually By 2025

Cybercrime To Cost The World $10.5 Trillion Annually By 2025

Fighting Back Against Ransomware with VMware

The saying goes, “the best defense is a good offense”. To defend against ransomware, organizations need to go on the offensive and proactively implement measures that help them maintain their operations in the event of an attack. The VMware whitepaper, “Ransomware: Defense in Depth with VMware”, provides a comprehensive overview of how organizations can implement a robust ransomware protection plan with VMware solutions, following guidelines set out by the National Institute of Standards and Technology (NIST). It describes the five key stages of a ransomware protection cycle and the essential activities of each stage, detailed below:

STAGEESSENTIAL ACTIVITIES
IdentifyReview industry and vendor resiliency best practicesConduct vulnerability assessmentsEstablish incident responseAlign security processes with DR processes
PreventMap applicationsDefine service level agreements (SLAs) and the level of recovery granularity required (replication intervals)Set-up DR capabilitiesSet-up next-generation anti-virus (NGAV)
DetectDetect the threatInvestigateTriage the threatVisualize the attack sequence to understand the threat
RespondIsolate the threat Conduct proactive threat hunting to uncover other risksIdentify a recovery pointFailover to a clean isolated recovery environment
RecoverAudit and remediate systemsPrevent reinfectionFailback to a clean production siteReturn to a normal state of business

While VMware can help organizations address every stage, this guide drills down into stage five. It explores how organizations can utilize VMware Cloud DR—VMware’s comprehensive DRaaS solution for the critical recovery phase of the ransomware protection cycle.

Overview of VMware Cloud DR

VMware Cloud Disaster Recovery (DR) is an on-demand disaster recovery service which provides an easy-to-use Software-as-a-Service (SaaS) solution with cloud economics that keeps disaster recovery costs under control. VMware Cloud DR can be used to protect vSphere virtual machines (VMs) by replicating them to the cloud and recovering them, as needed, to a target VMware Cloud Software Defined Data Center (SDDC) on VMware Cloud on AWS. An organization can create the target “recovery” SDDC immediately prior to performing a recovery; it does not need to be provisioned to support replications in the steady state.

Some of the key capabilities of VMware Cloud DR include:

  • Secure, immutable backup copies: VMware’s backup copies are operationally air-gapped—the scale-out cloud filesystem is kept separate from the production environment, so ransomware leakage to the backup storage system is impossible. No existing data is ever overwritten, making the underlying log structured filesystem inherently immutable. For extra security, VMware provides separate authentication and role-based access control (RBAC) for the production environments.
  • Deep history of backup copies: VMware provides recovery point histories that are minutes, months, even years old to enable organizations to fully recover, even if ransomware has been in the environment for a long time.
  • On-demand creation of isolated recovery environments (IRE): VMware’s elastic cloud capacity can be used to easily provision greenfield, clean operating environments for validation, and later, recovery. These environments prevent reinfection during the validation process when administrators need to work with potentially compromised backups. They also buy organizations time, providing a clean recovery site they can rely on in the event of an attack, so they can remediate existing sites and perform appropriate forensics without having to rush to restore service. See Section 4.1 for more details.
  • Convenient, efficient, and iterative validations (rapid experiments): Instant VM power-on enables organizations to complete the critical, iterative process associated with identifying which recovery points, VMs, or data to restore into production. With VMware, organizations aren’t required to always copy data from the backup storage system to the primary storage system. See Section 4.2 for more details.
  • File and folder-level recovery capabilities: Organizations can use VMware Cloud DR to extract specific files or folders from more recent recovery points as part of the recovery process. This extraction can be performed without bringing the associated VM into inventory and powering it on. (coming soon)
  • At-scale recovery with highly automated DR workflows and orchestration: VMware’s powerful orchestration engine has tight integration to source environments, failover environments, and the scale-out cloud filesystem to enable the recovery of 100s of VMs at a time following a very prescriptive recovery plan.

Leave a Reply

Your email address will not be published. Required fields are marked *