5.4 KiB
Task5:
Scenario A ransomware attack has encrypted all files stored on Ghaymah Block Storage. Users can no longer access their files, and the attacker demands payment in exchange for the decryption key.
-
Emergency Response Plan (First 60 Minutes)
0–15 Minutes: Identification & Isolation Objectives • Confirm that a ransomware attack has occurred. • Prevent the malware from spreading. Actions • Disconnect affected virtual machines from the network. • Disable access to shared Block Storage volumes. • Block suspicious IP addresses using firewall rules. • Stop scheduled synchronization tasks. • Notify the security and incident response teams.
15–30 Minutes: Investigation Objectives Determine the scope of the attack. Actions • Review system and application logs. • Identify the ransomware entry point. • Determine which servers and storage volumes are affected. • Preserve logs and forensic evidence. • Check whether backups are intact.
30–45 Minutes: Containment & Eradication Objectives Remove the ransomware and stop further encryption. Actions • Isolate infected systems. • Scan all virtual machines with antivirus/EDR tools. • Remove malicious processes and scheduled tasks. • Rotate compromised credentials. • Patch exploited vulnerabilities.
45–60 Minutes: Recovery Preparation Objectives Prepare for service restoration. Actions • Verify the integrity of backups. • Restore critical services in a test environment.
• Validate restored data.
• Monitor systems for reinfection. Gradually return services to production. Timeline Summary Time Activity 0–15 min Detect attack and isolate affected systems 15–30 min Investigate logs and identify affected resources 30–45 min Remove ransomware and secure infrastructure 45–60 min Restore from backups and validate services
- Ghaymah Backup & Recovery Strategy
Recovery Point Objective (RPO) Definition: The maximum acceptable amount of data loss. Proposed Value: 15 minutes This means backups or snapshots should occur at least every 15 minutes for critical data.
Recovery Time Objective (RTO) Definition: The maximum acceptable downtime before services are restored. Proposed Value: 1 hour Critical applications should be operational again within one hour.
Backup Strategy Daily Incremental Backups Capture only changes made since the previous backup. Advantages: Faster , Less storage usage
Weekly Full Backup Create a complete copy of all Block Storage volumes. Advantages: Faster restoration, Simplified disaster recovery
Monthly Offline Backup Store a copy outside the production environment. Purpose: Protection against ransomware encrypting online backups.
3-2-1 Backup Rule The organization should follow the 3-2-1 backup strategy: • 3 copies of the data (one primary + two backups). • 2 different storage media (e.g., Block Storage and external storage/object storage). • 1 off-site or offline backup stored separately from the production environment.
- Comprehensive Prevention Plan Identity & Access Management (IAM) • Enable Multi-Factor Authentication (MFA). • Apply the Principle of Least Privilege. • Review user permissions regularly. • Rotate passwords and API keys.
Network Security • Enable firewalls. • Segment production and backup networks. • Restrict remote administration access. • Use VPN for administrative access.
Endpoint Security • Deploy Endpoint Detection and Response (EDR). • Keep operating systems and software patched. • Disable unnecessary services. • Enable application allow-listing where appropriate.
Backup Protection • Use immutable backups where possible. • Encrypt backup data. • Test backup restoration regularly. • Store backups in separate locations.
Container Security • Scan container images using Trivy before deployment. • Avoid running containers as root. • Store secrets securely. • Continuously monitor container activity.
Monitoring & Detection • Deploy a SIEM solution to centralize logs. • Configure alerts for: o Multiple failed logins. o Unusual file modifications. o Mass file encryption. o Privilege escalation attempts.
Security Awareness • Train employees to recognize phishing emails. • Conduct regular security awareness sessions. • Simulate phishing campaigns. • Define clear incident reporting procedures.
Conclusion A successful ransomware response depends on rapid detection, immediate isolation, reliable backups, and tested recovery procedures. By implementing layered security controls—including strong IAM, network segmentation, continuous monitoring, secure container practices, and a resilient backup strategy based on the 3-2-1 rule—organizations using Ghaymah Cloud can significantly reduce the impact of ransomware attacks and recover services efficiently.