Bfore.AI Blog, Blog
Deploy Zero Trust and XDR to fight ransomware! | Bfore.AI
Ransomware cyber-attacks have continued to make news by crippling organizations such as Nexeya, Damart and recently the Corbeil-Essonnes hospital.
Ransomware is an ever-evolving form of malware designed to encrypt files on a device, rendering the files and systems that depend on them unusable. Malicious actors then demand a ransom in exchange for decryption. The rise of ransomware has inspired the creation of a myriad of techniques that attackers can use to achieve their goals.
Without claiming to be exhaustive, two security architectural approaches can be used to combat ransomware: the Zero Trust architecture model and extended detection and response (XDR).
Why can Zero Trust and XDR help limit the impact of ramsomware?
It is often believed that good security is difficult to achieve because malicious actors only need one thing to succeed, while security practitioners must succeed or fail at everything. This is not the case. Launching a successful ransomware attack goes through several steps. In fact, it’s so complicated that multiple teams must work together to pull it off.
First, bad actors choose a target. Then, they subscribe to a Ransomware-as-a-Service organization that specializes in creating software for ransomware attacks. They infiltrate the organization, either by guessing a user’s password, tricking a user into clicking on a suspicious link, or exploiting a vulnerability in the organization’s software. The full series of steps make up the main categories of MITRE’s ATT&CK framework. By interrupting any of these steps, the ransomware attack fails.

Using the ATT&CK framework allows teams to identify vulnerabilities to map their attack surface. It can help teams hunt for threats to detect attacks in progress before they cause damage. It can help a company discuss vulnerabilities with peer organizations that have been set up to protect critical infrastructure. It can also help security teams collaborate with security tool or service providers, as well as law enforcement, to discover weaknesses that led to an attack.

Zero Trust explicitly verifies identity and access and assumes that an access violation has occurred
The Zero Trust architecture model is a set of architectural principles that allow an environment to be locked down by reducing the attack surface. The key ideas of the Zero Trust architecture model are:
- Consider that the perimeter does not exist (it never really did). Don’t assume that someone should be trusted just because they have already entered the network.
- Verify users before allowing them to use services or access data, and verify the integrity of a device before allowing it to connect to the network.
- Don’t assume that users will always do the right thing. Instead, require verified access rights for every service request.
- Rather than trying to track bad actors through the system, put up barriers that will slow them down.
For these principles to work in practice, two things must happen:
- First, an identity and access management (IAM) product must be in place to enable authentication (strong through MFA) of users and their rights or permissions. Without this, there will be no source of truth to determine whether or not a particular request has been authorized.
- Second, segment the network. This will slow down an attack. Lateral movement within the organization sets up payloads and allows for data theft and encryption. Segmenting the network blocks these elements of attack.
XDR collects threat data from previously siloed security tools to facilitate and accelerate response
XDR aggregates information about possible attack elements (e.g., indicators of compromise [IoC]) with network traffic logs, strange endpoint behaviors, cloud and software-as-a-service (SaaS) requests, and server events for analysis.
The power of XDR is that it goes beyond security information and event management (SIEM), which aggregates log data, to include correlation, analysis, and machine learning (ML) augmented modeling. These elements form the basis for an effective response.
Deploying an XDR solution (which can detect multiple attack elements) with a Zero Trust architecture (which hardens the infrastructure against malicious attacks) can significantly improve survivability against ransomware.
- So deploy an IAM tool.
- Use multi-factor authentication (MFA), at least for high-privilege accounts.
- Segment the network.
- And implement an XDR tool for the security operations center (SOC).
Your day-to-day business life will be much calmer, more predictable and less hectic.


Prevent the next Cyber Threat
Bfore.AI patented AI technology combined with hyperscale observation infrastructure and modern APIs augment our customers security postures with Predictions.
Discover Predictive Cyber-Security
Book a live demo with our specialist to discover how Bfore.AI helps organization fight cyber threats with their patented technology.


