fbpx
Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Penetration Testing

          Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Ransomware Victim Shows Why Transparency In Attacks Matters

Ransomware Victim Shows Why Transparency In Attacks Matters

As devastating ransomware attacks continue to have far-reaching consequences, companies still try to hide the attacks rather than be transparent. Below we highlight a company’s response to an attack that should be used as a model for all future disclosures.

On May 5th, green energy tech provider Volue suffered a Ryuk ransomware attack that impacted some of their front-end customer platforms.

Since then, Volue has been transparent about the cyberattack by providing webcasts, daily updates, and the email addresses and phone numbers for their CEO and CFO for questions about the attack.

In addition, the company states they have shared all indicators of compromise with KraftCert, a Norwegian Computer Emergency Response Team, to alert other companies and law enforcement.

Volue’s transparency is in stark contrast to the disclosures typically seen in ransomware attacks and should be used as a model for future disclosures.

This transparency has not gone unnoticed by cybersecurity professionals who are commending Volue’s response to the attack.

Also Read: What You Should Know About The Data Protection Obligation Singapore

Many are comparing Volue’s transparency to Norsk Hydro’s, another Norwegian company who also garnered respect for how they handled a 2019 LockerGoga ransomware attack.

While BleepingComputer would usually cover Volue’s ransomware attack, they have been so transparent and detailed that we have nothing further to add.

Transparency looks better, not worse

Transparency protects your customers and employees, inspires confidence in your company, and aids law enforcement, yet few companies choose to be transparent.

Instead, almost every ransomware victim first tries to hide an attack out of fear that it could cause reputational or legal harm.

Ultimately, the true nature of the attack is revealed after a malware sample or note is found, or the ransomware gangs publish data stolen during the attack.

Employees of breached companies have told BleepingComputer that their employers denied an attack or that data was stolen until the ransomware gangs publicly released the files.

By not being transparent from the beginning, the victim’s customers, employees, and business partners are put at greater risk as they are not provided ample warning as to what was stolen.

Being transparent also allows breached companies to assist law enforcement in their investigations and prevent further attacks.

Finally, transparency inspires confidence with your employees, customers, and investors that the company is responding correctly to the attack and that there is nothing to worry about.

Companies urged to report ransomware attacks

The FBI has urged victims to report ransomware attacks so they can receive fresh IOCs (indicators of compromise) about a ransomware operation.

When an organization is attacked, it is crucial for law enforcement to quickly receive known IP addresses, files, and domains used by the attackers to be immediately analyzed and used as part of their investigations.

The longer a business waits to provide law enforcement with IOCs, the less useful they become as the attackers hide their traces or remote sites are shut down.

Also Read: The Difference Between GDPR And PDPA Under 10 Key Issues

Why let the ransomware gangs control the narrative when you can control it yourself by being transparent?

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us