ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Building resilience to ransomware

teissTalk host Geoff White was joined by Dean Sapp, VP, Information Security, Risk and Compliance, Filevine; and Jacqueline Hanson-Kotei, Senior Manager, Enterprise Information Security & Governance, MTN Ghana; and Milos Pesic, Vice President of InfoSec & CyberSec, Vertofx.

 

 

Views on news

 

Over fifty per cent of ransomware attacks come via legitimate business partners, typically through unprotected emails (phishing) – the three other most “popular” exploits being stolen credentials, the exploitation of vulnerabilities and botnets. Four-fifth of breaches is committed by organised criminals, and therefore external threat actors pose four times more risk than internal attacks.

 

Building resilience pre- and post-breach

 

It’s equally important to build resilience into your security posture and incident response. Assessing and testing your resilience is key when preparing for attacks but it’s also important to demonstrate resilience in how you deal with a breach once it’s occurred.

 

The two are closely connected as pre-breach will dictate what and how fast you can achieve post-breach. If you have been attacked, in the US, it’s a good idea to get external legal counsel, as you want all the information that has been disclosed by the investigation to be legally privileged, so you’ll have the right to decide which documents are to be used in the litigation against threat actors or to protect your brand.

 

It’ll allow you to have a thorough investigation, find the root cause, as well as implement your disaster recovery and business continuity plans, and THEN determine who you’re going to notify in which jurisdictions. Without a legal counsel on board, if you’re sued, they can request any of your records and you can’t prevent them from disclosing information that they decide to. As having everything backed up would be rather costly, you have to prioritise what you need duplicates of.

 

 

Although. from a security perspective, companies shouldn’t pay ransoms, ironically, sometimes those who decide to pay a ransom get better IT support (even post-breach) from the criminals than they would, for example, from the government.

 

Often, they can also negotiate a better ransom and improve their security posture with the money they’ve saved. However, after negotiating with them and recovering your data, you need to ensure that all your backdoors have been removed, otherwise they may come back and attack you again or sell your vulnerabilities to another group.

 

Your post-breach resilience should naturally focus on your crown jewels and funds, and if something actually happens to them, you need secondary and third-level measures in place too. As cyber criminals’ methods evolve, you need to move too to adapt to them.

 

A crisis communication management plan is also essential when preparing for cyber incidents involving your legal, marketing, IT etc teams.

 

Back-up strategies differ from system to system. If you have a replicated system, you obviously need no back-ups. However, if you do have them, you’ll also have to carry out restoration tests on back-ups to make sure they aren’t corrupted or damaged in any way. Sometimes you need a bit of luck too.  During the NotPetya attack, a key piece of Maersk’s data was wiped out on seven mirrored servers and only survived on a system in Ghana due to a blackout that shut down the datacentre before it could be infected. Remember that if a breach happens, you’ll have to communicate to your stakeholders where your back-ups are.

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543