How Do I Survive a Ransomware Attack?

Who Does Ransomware Target?

Ransomware attacks are no longer affecting enterprises only. They’re spreading to organizations of all sizes, maturities, and even across industries. Why? It’s profitable.

Many mid-market businesses have a false sense of security that ransomware attacks only happen to big corporations with millions to pay in ransom. But both enterprise and mid-market companies have valuable data attackers can hold for ransom.

How Do I Protect My Business?

(LINK) Protect your business using the 5 Ps of Preparedness approach:

  1. Program. Work with IT to align your cybersecurity program with your ransomware strategy to minimize the operational and financial impact of a ransomware incident.
  2. Policy. Work with leadership and the board to create a policy that explains how you will approach ransomware, including if your business will attempt to make a payment.
  3. Plan. Your plan should be concise, comprehensive, and simple. Who will provide external support, who will you empower to make decisions, and who will execute your plan?
  4. People. Identify strategic partners within your organization and external parties and clearly define their roles, inform them of their responsibility, and document their contact information.
  5. Practice. Consistently test your ransomware strategy to understand your ability to organize, execute, and improve response capabilities. This will ensure your preparedness.

What is the Ransomware Lifecycle?

Understand the ransomware lifecycle to prepare for and resolve it as quickly as possible. 

  1. Infection. Ransomware finds its way into corporate assets through phishing emails, a misconfigured cloud asset, and the exploitation of your open vulnerabilities.
  2. Communication. Ransomware communicates back to its control network, where attackers determine how they’ll attack your network.
  3. Discovery. Built-in mechanisms discover specific types of sensitive information for ransom, identify defensive measures, and help attackers maximize their impact.
  4. Data exfiltration and backup destruction. Ransomware components silently corrupt and disable backups and steal sensitive information.
  5. Encryption. Attackers silently and selectively encrypt your data, making your systems and data useless without decryption.
  6. Ransom demand. Ransomware attackers make ransom demands (typically in Bitcoin) to get your data back.
  7. Negotiation. Some ransomware attackers will negotiate.
  8. Decryption. You can pay the ransom to get the decryption keys, but there’s no guarantee attackers won’t leak or re-encrypt your data.

Top 3 Initial Infection Vectors

  • Phishing emails
  • Remote Desktop Protocol (RDP) exploitation
  • Software vulnerabilities exploitation

How Can Technology Help?

Apply a zero-trust security strategy to empower your security teams and leadership to move faster and more securely. At its core, zero trust believes we should not inherently trust any interaction, at any level. It focuses on setting up systems and applications that protect themselves from every other system, allowing them to defend against attacks by minimizing the impact of any single compromise or attack. 

NIST CSF

Five areas of the NIST CSF to include if your cybersecurity and ransomware strategy:

  1. Identify. Operationalized identification, detection, and classification of critical and sensitive data
  2. Protect. Data and individual asset protection that prevent known threats and attack patterns
  3. Detect. Operationalized cyber attack and malicious software detection
  4. Respond. Integrated technology platforms that detect ransomware rapidly to contain it
  5. Recover. Recovery strategy that can scale

Conclusion

Are you prepared to defend against ransomware attacks? At Lightstream, we have helped customers build effective strategies to empower them to fight against ransomware attacks, and we can do the same for you.

We’ll assess your current strategies, build upon them, and help you mitigate as much risk as possible by preparing for and setting up the proper technologies to fight ransomware attacks.



How Do I Migrate to AWS?

Why you should move to the AWS cloud?

Modernize your infrastructure and drive business transformation, respond quickly to ever changing demands from employees and customers, boost innovation…

Modern operational practices improve results :

  • 20% average infrastructure cost savings
  • 69% reduction in unplanned downtime
  • 43% fewer security incidents per year

Migration & Transfer on AWS – Migrate to AWS and see business results faster

Clearly, migrating to AWS is good for business. But successful migrations take planning and expertise, as well as an understanding of the challenges you’re likely to face as part of the process. By understanding those challenges, the pitfalls that can result when they aren’t fully addressed, and the possible solutions to smooth your way forward, you’ve taken the first step on your cloud migration journey.

How do I migrate to the cloud?

What is the AWS MAP process?

Use the MAP (Migration Acceleration Program) to assess, mobilize, migrate and modernize (How do I migrate?):

AWS wants you to have a great experience, so we provide assessment tools that help determine if you’re ready to migrate to the cloud (cloud readiness)

Conclusion:

Ready to migrate to AWS? We’re here to help you migrate to the cloud
Lightstream is an AWS Advanced Consulting Partner → our AWS-certified engineers and architects have years of experience assisting and driving migrations of all sizes.

We’ll assess how ready you are to migrate to AWS and plan a course of action.

LIGHTSTREAM Joins MICROSOFT INTELLIGENT SECURITY ASSOCIATION as a Managed Security Service Provider

Lightstream is a member of MISA

Salt Lake City, UT (March 29, 2022) — Lightstream,   a managed security solutions provider, is pleased to announce their membership in the Microsoft Intelligent Security Association (MISA). MISA is an ecosystem of independent software vendors and managed security service providers that have integrated their security solutions with Microsoft to better defend against a world of increasingly sophisticated, fast-moving threats.

Lightstream was nominated to MISA as a managed security service  provider (MSSP) for their Managed Detection and Response solutions with Microsoft 365  and Microsoft’s cloud security offerings. This membership strengthens Lightstream’s relationship with Microsoft and broadens the range of high value solutions that drive increased customer value.

Jim Cassel, Co-CEO of Lightstream, shares

It is a privilege to be nominated to the Microsoft Intelligent Security Association and join the top security partners as we align in our commitment to cybersecurity. The timing is paramount as organizations globally will continue to face growing cybersecurity attacks and data breaches in today’s complex environments. Lightstream has the advantage of MISA support to extend, develop and improve cutting-edge security solutions to customers globally.

“Microsoft Intelligent Security Association members leverage Microsoft’s security products to better defend against cyber security threats with identity and access management, threat protection, information protection, and security management,” says Rob Lefferts, Corporate Vice President, Microsoft Defender.

Lightstream Managed Security Services elevates customer success by rapidly improving security outcomes while meeting complex compliance requirements and continually optimizing desired business outcomes. Lightstream’s security and threat protection solution suite offers include Defender for Microsoft 365, Defender for Cloud, Defender for Endpoint, Defender for Cloud Apps, Defender for Identity and XDR capabilities. Lightstream also offers a comprehensive portfolio of cloud, endpoint, and on-premises risk mitigation solutions  focused on operational, technical, and financials risk.

To learn more, visit Microsoft Intelligent Security Association.

For information on Lightstream services and solutions, visit Lightstream.tech

About Lightstream

Lightstream provides full-service cloud, connectivity, and security solutions to enterprises worldwide with a focus on managed services for all three, as well as cloud infrastructure implementation, security, and support.

Lightstream has been named multiple times as a Palo Alto Networks Public Cloud Partner of the Year, and is an AWS Security Competency Partner, an AWS Advanced Consulting Partner, and a Microsoft Cloud Platform Gold Partner with Security Competency. Visit us at http://www.lightstream.tech or LinkedIn.

Media Contact

Daniel Davenport / dan.davenport@lightstream.tech

 

 

 

Tepco Glass Migrates to Azure, Increasing Reliability and Setting the Stage for Future IT Modernization

Faced with aging on-premises servers and an unsupported operating system, Tepco Glass moves all applications to Microsoft Azure with help from Lightstream.

Business Challenge

Tepco Glass is one of the top glass and glazing contractors in the United States. Founded in 1982, the Dallas-based company specializes in commercial glazing and architectural design, as well as the installation of curtain walls, window walls, storefronts, entrances, motor operable windows, glass railings, and other façade enclosures.

When the COVID-19 pandemic hit, the construction industry stalled. Many projects were postponed, delayed, or canceled. And the global slowdown cascaded to suppliers and contractors, including Tepco, negatively affecting revenues and cash flow.

Although business was slow and cash flow was tight, Tepco’s business did not stop. The company continued to operate, serving its customers and addressing operational challenges. One challenge they faced involved the company’s IT infrastructure.

Tepco’s core business applications ran on Windows Server 2008 R2 servers located in the company’s small data center in Dallas. The hardware was over five years old, and Tepco’s IT manager was concerned that the aging hardware could lead to equipment failures. In addition, Windows Server 2008 R2 had reached end of life, and the company was no longer receiving support from Microsoft.

Solution

Company executives knew they needed to address the issues. But given the economic realities during the pandemic—business slowdown, a global microchip shortage, and supply chain constraints—they did not want to incur a large capital outlay to purchase new hardware and upgrade to a supported operating system.

They decided to explore the cloud. Moving to the cloud would eliminate the need to refresh hardware. And Microsoft offered an added incentive: if they migrated their Windows Server 2008 R2 environments to Microsoft Azure, the company would receive an additional 36 months of extended security updates for free.

The solution seemed viable, but the company wanted to ensure that it would work. Tepco’s IT manager knew one of Lightstream’s account executives from a previous working relationship, and reached out for help.

The first step was to assess the plan. Lightstream linked Tepco’s VMware environment to Azure Migration to evaluate the feasibility of moving it to Azure. This showed that the migration was viable and that Tepco could save money over the long term. Tepco’s executives were pleased with the findings and approved the project.

Over a period of 12 weeks, Lightstream experts worked with Tepco to plan, configure, and test their Azure environment. Finally, when all testing had been completed and issues resolved, Lightstream moved all of Tepco’s core applications from on-premise servers into the new environment. For ongoing support and optimization of their Azure environment, Tepco will use Lightstream Cloud Managed Services (CMS).

Business Outcomes

Increased Reliability and Availability

Tepco Glass has four locations—two in Dallas, one in Carrollton, Texas, and one in Oklahoma City—as well as other remote users who need access to applications. The Dallas headquarters is located in a section of the Dallas area that doesn’t have the most reliable power or internet service. Consequently, when the headquarters site suffered a power or internet outage, no one could connect from any locations, and their business was disrupted.

By moving all applications to Azure, Tepco no longer has this problem. Even if the Dallas location experiences an outage, users from the other sites are not affected. They can continue working without interruption.

Shift to a Consumption-based Operating Model

Tepco no longer maintains on-premise server hardware. By moving to Azure, they eliminated the need for large capital outlays in the future to address product upgrades and hardware refreshes. And they now have a more predictable operating expense model for IT.

Better Positioned for Future IT Modernization

Tepco is no longer limited by their data center environment. With all server infrastructure now in Azure, they have more flexibility, making it simpler for them to pursue future modernization efforts like virtual desktop infrastructure (VDI) and others. For example, with all workload in Azure, they don’t need to buy high-end gaming computers for people to do product designs anymore—the heavy processing can now be done in the cloud.

Ongoing Infrastructure Management and Cloud Optimization

By moving to Azure, Tepco no longer has to worry about infrastructure management. Lightstream Cloud Managed Services supports the company’s infrastructure, ensuring servers are patched and maintained, and oversees the company’s Azure environment to make sure it is optimized both for cost and performance.

Lightstream Names Joe Vadakkan as Global Executive Vice President for Sales and Engineering

Cloud security veteran and key strategist joins emerging service provider to drive growth

Salt Lake City, UT, January 19, 2022– Lightstream, a leader in cloud security, digital transformation and managed services, today announced the hiring of Joe Vadakkan as the company’s new executive vice president for global sales and engineering. As an IT, cloud and security thought leader, Joe will lead Lightstream’s global cloud security engineering and sales organization to drive execution of customers’ cloud security strategies and elevate their innovation at scale.

“Joe is a prominent industry veteran with extensive leadership experience in cloud security sales and innovation, having driven many of the industry’s successful, secure digital transformations,” said Lightstream Co-CEO, Jim Cassell. “I’m excited to welcome him to Lightstream’s executive team, and I look forward to working with him on our mission to enable our global customers to progressively innovate and grow effectively with Lightstream’s cloud security solutions.”

“We are very excited to have Joe join the Lightstream team,” stated Rod Stout, Co-CEO of Lightstream. “His unique ability to help customers realize value and achieve desired business outcomes is unparalleled. With his in-depth knowledge in partner distribution strategies and his success in building and growing world class organizations, Joe will help Lightstream bring continuous value to its customers and achieve our growth objectives.”

Joe has over 20 years of technical and business leadership experience in the areas of global infrastructure and security, most recently having served in a strategic services leadership role at Optiv, a pure play cybersecurity firm. Prior to that, he was responsible for building and running Optiv’s cloud security organization. He has also held leadership roles and provided strategic guidance for startups, venture capital and private equity firms and Fortune 2000 companies.

“I am very excited to join the Lightstream team and look forward to taking the company’s technology and services innovation to the next level to fuel future growth,” said Joe. “Lightstream has a great business model and a talented team that are fast movers on solving customer needs. I believe it is uniquely positioned to accelerate secure client innovation through its Lightstream Connect platform for Microsoft Azure, AWS and Google and integration with a security partner ecosystem that enables it to compete in today’s global market.”

About Lightstream

Lightstream provides full-service cloud, connectivity, and security solutions to enterprises worldwide with a focus on managed services for all three, as well as cloud infrastructure implementation, security, and support.

Lightstream has been named multiple times as a Palo Alto Networks Public Cloud Partner of the Year, and is an AWS Security Competency Partner, an AWS Advanced Consulting Partner, and a Microsoft Cloud Platform Gold Partner with Security Competency. Visit us at http://www.lightstream.tech or LinkedIn.

Media Contact

Cynthia Lawton / cynthia.lawton@lightstream.tech / 843-300-8445