Develop the Intelligence Debriefing
2
Project 3, Step 9: SITREP #2
Team United Kingdom: Michael Arizieh, Julian Chandler, Justin Basagic, Ayman Gismalla Mohammed,
Oluwasegun “Saji” Ijiyemi
University of Maryland Global Campus
CMP 670 9047 Capstone in Cybersecurity (2231)
Prof. Thaddeus Janicki
Mar 9, 2023
Table of contents
Table of contents……………………………………………………………………………………………………………………2
Introduction…………………………………………………………………………………………………………………………..3
Security Incident Report - SITREP #2………………………………………………………………………………………4
Conclusion……………………………………………………………………………………………………………………………..5
References……………………………………………………………………………………………………………………………..7
Introduction
Malware known as ransomware keeps users from being able to utilize their machines (or recover information). After the attacker acquires illegal access by introducing malware into the victim's system, ransomware attacks are typically used to encrypt or destroy crucial data. In most cases, even if the ransom is turned over, the files are rarely unlocked, and access returned. To mitigate this situation, the most important files and data should always be kept in a current offline backup because of these reasons.
Security Incident Report - SITREP #2
Our UK team will discuss the early findings and lay out the steps our organization plans to take considering the mentioned indications in this study. In order to communicate incident data and obtain this report, the Five Eyes (FVEY) Alliance institutions can access US-CERT databases for more intricate details. Also, our UK team will describe any indicators, such as file system alterations, the timing of the occurrence, services, IP addresses, and other actions, that could be used by affected parties to search within their networks for the ransomware.
Conclusion
Ransom attacks can have negative impacts on businesses and organizations. It is essentially malware that disables the system and encrypts important files preventing access to critical data. Once the organization's file has been encrypted, information recovery may be challenging and time-consuming. In order to stop the attack from spreading, the cybersecurity team must contain it rapidly if an attack has been discovered on the enclave or system. Once hackers gain access to files, a ransom attack cannot be stopped by a security tool or system restoration, making them very dangerous.
One of the biggest hazards in the modern digital environment is ransomware. For companies, institutions, governments, and information security professionals, it is progressively becoming a risk and concern that is propagating more frequently. Ransomware has so drawn the attention of various hackers due to the possible cash benefits, which has fostered its accelerated growth. Moreover, ransomware has impacted the majority of financially established countries on a global scale. As a result, regular safety measures must be taken to backup important data and files, preferably at off-site locations.
References:
CyberChef. (n.d.). Crown Copyright 2016. https://cyberchef.org/
David, B. (2021, September 6). 5 Best Practices for Mitigating DDoS Attacks. Infosecurity Magazine. https://www.infosecurity-magazine.com/magazine-features/5-best-practices-mitigating-ddos/
Ransomware Guide | CISA. (n.d.). Cybersecurity and Infrastructure Security Agency CISA. https://www.cisa.gov/stopransomware/ransomware-guide
SITREP #2