Educause Security Discussion mailing list archives

Re: Ransomware Playbook


From: Frank Barton <bartonf () HUSSON EDU>
Date: Fri, 4 Oct 2019 08:35:39 -0400

I'm going to add my "Me Too!" to this thread. along with the obligatory
question: How many of us are going to Educause in just over a week? I think
this would be a great thing to chat about over a cuppa (coffee or $beverage
of choice)

as it stands right now, I am in the process of trying to build our library
of playbooks for various incident response scenarios, and to be completely
honest, I'm not even always sure what scenarios to plan for.

Frank

On Fri, Oct 4, 2019 at 8:16 AM Sol Bermann <solb () umich edu> wrote:

Always interested in seeing how I can improve what we have

On Thu, Oct 3, 2019, 11:51 PM Bingdong Li <bli () nshe nevada edu> wrote:

I’m interested too. Thank you!



Thank you.



Bing Li, PhD CISSP

Nevada System of Higher Education/System Computing Services

Phone (775)789-3703



*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *John Ramsey
*Sent:* Thursday, October 3, 2019 1:50 PM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* Re: [SECURITY] Ransomware Playbook



I have one and am happy to share!

Sent from my Verizon, Samsung Galaxy smartphone

Get Outlook for Android
<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2Fghei36&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260479382&sdata=VvCs706e1x4Io9IhsWSKJJ85csN4Kc0I8fztoZfhYwA%3D&reserved=0>


------------------------------

*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Kip Bates <
kbates () HOUSING UCSB EDU>
*Sent:* Thursday, October 3, 2019 4:34:08 PM
*To:* SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>
*Subject:* [SECURITY] Ransomware Playbook



Colleagues:

I am hoping that I can find someone or someplace that has made an effort
to develop a Ransomware Response playbook that they would not mind sharing.
I understand all the preparation that needs to occur prior to an attack but
I am looking for something that we can provide users, help desk folks,
technicians and such on what actions to take if (when) they experience a
ransomware attack. I have found a few on the web and I was wondering if
someone has adapted one of these for their institution or have developed
one that they think is particularly good.

Feel free to comment here or off-list.




Kip Bates

Associate Chief Information Security Officer

University of California, Santa Barbara



**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260479382&sdata=W%2BaQgrEonNgnlZwkJTbHfK1Rqj5DAA0IDnl13Mng%2Bms%3D&reserved=0>

=======================================================

This message has been analyzed by Deep Discovery Email Inspector.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260489380&sdata=b4l%2Fw1joQi9IozijuDOiBbx%2Bn6TIf2GMRWpiFjXmod4%3D&reserved=0>
PUBLIC RECORDS NOTICE: In accordance with NRS Chapter 239, this email and
responses, unless otherwise made confidential by law, may be subject to the
Nevada Public Records laws and may be disclosed to the public upon request.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community



-- 
Frank Barton, MBA
Security+, ACMT, MCP
IT Systems Administrator
Husson University

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: