THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, December 09, 2022
An inter-agency task force established to strengthen the nation's anti-ransomware activities provides recommendations on whether to pay the ransom and guidelines on preventing such attacks.
FREMONT, CA: Singapore claims to have produced a blueprint to battle the escalating ransomware threat and provide instructions on reducing such assaults. There is also advice on whether to comply with ransom requests and a reference kill chain for ransomware.
According to the Cyber Security Agency (CSA) statement, the extent and effect of ransomware dangers have considerably escalated, making them an urgent issue that all nations, including Singapore, must address. According to the government agency, it is inherently an international concern because attackers conduct their operations across countries and jurisdictional barriers to dodge prosecution. Ransomware has generated a criminal ecosystem, delivering illegal services ranging from unauthorised access to targeted networks to money laundering services.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
It emphasised the necessity of coordinating cybersecurity, law enforcement, and financial regulatory organisations and encouraging international cooperation to successfully address the threat.
Singapore formed an inter-agency task force at the beginning of the year, comprised of senior officials from several ministries and government organisations, including the CSA, Government Technology Agency, Ministry of Defense, Monetary Authority of Singapore, and Singapore Police Force.
The task force concentrated on three main outputs, including a reference model for a ransomware kill chain that would be used as the basis for coordinating and developing counter-ransomware solutions by government agencies. Additionally, it examined the nation's laws governing ransom payments and made recommendations for the operational strategies and tools required to combat ransomware successfully.
Starting with the phases before it is launched and when attackers obtain access to the targeted system and carry out preparatory procedures, such as data exfiltration and removal of backups, the kill chain defines the five stages of a ransomware attack. According to the design, stealth is key in this stage, and attackers have been known to complete it months before activation.
The report indicated that it emphasised the idea that prevention is better than cure and that the first aim should be to shorten the skill chain at the first two levels. Having a shared reference model of a ransomware kill chain will help governments communicate more effectively, share information more easily, compare best practices for preventing ransomware, and spot any weaknesses in current national security measures.
Additionally, the blueprint backed Singapore's position that paying ransoms should be highly discouraged. Doing so would exacerbate the ransomware issue since that was the attacker's primary goal.
Furthermore, paying the ransom did not ensure that the data would be unencrypted or would not be made public by the hackers. The task team warned that businesses that choose to pay the ransom risked being labelled as soft targets and attacked again.
More in News