As we begin the journey into 2024, ransomware and cybersecurity remains top of mind for organizations. And the expanding use of cloud and SaaS applications doesn’t negate that challenge. To dig into this topic more, VMblog reached out to industry expert, Nick Harrahill of Spin.AI, an experienced cyber security and business leader with industry experience leading security teams and building programs at enterprise companies. Nick is credentialed in both cyber security (CISSP) and privacy (CIPP/US).
VMblog: What are the key vulnerabilities in cloud systems that make them susceptible to ransomware attacks?
Nick Harrahill: The cloud-based systems used in today’s digital workforces increasingly rely on software-as-a-service (SaaS) to provide employees with tools, such as word processing, data management, productivity support, collaboration, and more. Third-party SaaS applications can gain OAuth access to businesses’ data stored on the cloud in office suites like Google Workspace and Microsoft 365, which can be exploited by bad actors through ransomware attacks. Frequently, these bad actors will embed ransomware in a phishing email that tricks the employee into granting it OAuth access. A company’s cloud system can be vulnerable because of the large number of SaaS users they have across multiple applications.
VMblog: How does the increasing use of SaaS applications influence the cybersecurity landscape, especially in terms of ransomware threats?
Harrahill: The more SaaS applications in use by a company, the more opportunities for an attacker to exploit them in ransomware attacks. Additionally, the more applications, the more complex the cloud environment becomes – so you have to be more vigilant in monitoring for threats, addressing weak points, and planning for a response. To aid teams in addressing these increasingly difficult environments, many are looking to AI tools capable of real-time ransomware threat detection. These tools should not only monitor threats but also rebuke attackers’ access and be able to restore data and operations with minimal downtime.
VMblog: Can you describe the typical process of a ransomware attack in a cloud environment?
Harrahill: Ransomware can enter a cloud environment just like it hits on-premise environments. It begins with an employee subscribing to an app containing malicious code, which gains OAuth access to data stored in cloud office suites like Microsoft 365 and Google Workspace. These apps provide hackers with editing permissions giving them the green light to encrypt company data. Attackers then make their demands. After the ransom is paid, they may or may not provide a decryption key. Without the key, it is nearly impossible to restore the corrupted data unless you have a backup. However, until admins revoke bad actors’ OAuth access, the data can easily be encrypted again.
VMblog: What are the best practices for businesses to protect their cloud data from ransomware?
Harrahill: Best practices are a mix of preventive and proactive measures. That means regular employee education and training, security-forward policies – including password management, as well as using tools that provide real-time threat detection scans, source-blockers against attackers, infected file detection and restoration, plus automatic notifications for administration. Four cloud data protection best practices include:
- Assuming Zero Trust – Access to important data should only be granted to users who have successfully verified their identity and confirmed the security of their device.
- Segment Your Cloud Systems – Understand which SaaS apps have access to what information and how important that information is and be able to isolate those attacks and prevent the spread of damage.
- Monitor SaaS app activity – time-to-act depends on spotting threats as quickly as possible and mitigating the damage.
- Backup and data restoration processes – not just thorough backups, but efficient restoration processes that ensure timely recovery. These should be regularly tested for their efficacy to measure the time to recover.
VMblog: How has the approach to defending against ransomware evolved with the growth of cloud computing?
Harrahill: The general motivation behind ransomware attacks, SaaS and otherwise, is more or less the same – to withhold mission-critical data until a payment is extracted. What’s changed is the sophistication of these attacks and the cybersecurity countermeasures that have been developed in response. Advanced threat detection systems leveraging machine learning and AI have become central, providing proactive defense by predicting potential attacks. Additionally, the adoption of robust access control measures, like identity and access management (IAM) solutions, and the Zero Trust security model, where trust is never assumed, further mitigates risks. Finally, continuous security monitoring and real-time analytics allow for swift detection and response, helping to fortify the overall defense strategy against ransomware in cloud environments.
VMblog: In the context of cloud security, how important is user education in preventing ransomware attacks?
Harrahill: Employee awareness is your first defense against SaaS ransomware attacks. As direct users of SaaS apps, your employees should understand how to identify potential threats, take preventative action and relay that information to colleagues and admin. Every worker needs base knowledge of ransomware attacks – SaaS and otherwise – to make smart day-to-day decisions. To fully understand how pervasive ransomware attacks are across industries, we’ve created a ransomware tracker for continuous monitoring.
VMblog: What are the challenges in detecting and mitigating ransomware in a cloud environment?
Harrahill: Detecting and mitigating ransomware in a cloud environment poses several unique challenges. Here are a few:
- Shared Responsibility Model: In cloud environments, security is often a shared responsibility between the cloud service provider and the client. Understanding the demarcation of responsibilities can be complex, and there may be areas where security oversight is less clear.
- Visibility and Control: Cloud environments can limit visibility and control over network operations and data. This can make it harder to detect ransomware activities, such as unusual data access or movement, which are critical indicators of a ransomware attack.
- Scale and Complexity: Cloud environments are often more dynamic and scalable than traditional IT environments. This complexity can make it difficult to monitor and analyze security logs effectively, which is essential for detecting ransomware.
- API Security: Cloud environments heavily rely on APIs for various services. These APIs, if not properly secured, can be exploited by attackers to initiate ransomware attacks.
- Rapid Elasticity and Resource Provisioning: The ability of cloud environments to rapidly scale and provision resources can be exploited by ransomware to spread quickly across multiple assets.
To address these challenges, it’s important for organizations to implement robust security measures, including regular security audits, employee training, effective incident response plans, and up-to-date backup and recovery procedures. Additionally, leveraging advanced security tools and services offered by cloud providers and security vendors can enhance protection against ransomware.
##






