Educause Security Discussion mailing list archives
Re: Ransomware Playbook
From: "Barton, Robert W." <bartonrt () LEWISU EDU>
Date: Thu, 3 Oct 2019 22:00:38 +0000
While I do agree every playbook HAS to be unique, I know from my perspective, there are various items I’m interested in hearing from others. - When and how do they communicate out. Social Media first, second or ever? Do you include a full communication plan in your playbook? - What sections (descriptive and operational) are there in various playbooks? I have 10 different sections…but somebody could have ones I don’t have that are good ideas. Sometimes I’ll like something as simple as the format and I’ll make a change in mine. - Where do people keep all these different documents? Paper as well as electronic? Should I be pushing more for a document management system (enterprise)? Are they using a web based system (I’m still fighting trust issues with management when you say ‘cloud’)? - Are others doing playbooks that are more ‘high level’ than mine? Why or why not? What can I learn from that? There are a few more things that I’ve thought up, but ABSOLUTELY the ‘meat’ will be different. Another playbook is a reference to learn from and not a tool you can use. Isn’t that why we are all here? Robert W. Barton Executive Director of Information Security and Policy Lewis University One University Parkway Romeoville, IL 60446-2200 815-836-5663 From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Jonathon Poling Sent: Thursday, October 3, 2019 4:17 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Ransomware Playbook A ransomware playbook, especially a prescriptive one, is going to be HIGHLY specific to your environment and PPT (People, Process, Tooling) and thus will require substantial (and unique) development and refinement for your specific organization. There's a reason so many org's (and entire counties/systems) fall victim to just paying the ransom, even when it's an inordinate amount of money. There is a lot to it, completely aside from properly testing and restoring backups. I only say this all because I've built a lot of specific playbooks running the gamut for a lot of clients in a variety of verticals over the years. This is definitely one of our most involved playbooks we help people build, as it involves a lot of non-technical preparation that is not readily apparent unless you've gone through it. This is one of those things you don't want to skimp on or necessarily even copy from what others are doing, as a lot of org's aren't building the comprehensive set of processes and procedures needed for properly protecting against, operating amidst, and recovering from such attacks. At any rate, just sharing my experience and hopefully some (useful) food for thought, whichever route you end up going. Jonathon On Thu, Oct 3, 2019 at 2:15 PM King, Ronald A. <raking () nsu edu<mailto:raking () nsu edu>> wrote: Me too, please. Ronald King Chief Information Security Officer Office of Information Technology (757) 823-2916 (Office) raking () nsu edu<mailto:raking () nsu edu> www.nsu.edu<http://www.nsu.edu/> @NSUCISO (Twitter) [NSU_logo_horiz_tag_4c - Smaller] From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Joey Rego Sent: Thursday, October 3, 2019 5:13 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] Ransomware Playbook I am interested as well. Thank you. Joey Rego Associate Director of Information Security Information Technology Lynn University 3601 N Military Trail Boca Raton, FL 33462 561-237-7982 www.lynn.edu<http://www.lynn.edu> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG<mailto:jramsey () STUDENTCLEARINGHOUSE ORG>> Sent: Thursday, October 3, 2019 4:50:20 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: Re: [SECURITY] Ransomware Playbook I have one and am happy to share! Sent from my Verizon, Samsung Galaxy smartphone Get Outlook for Android<https://urldefense.proofpoint.com/v2/url?u=https-3A__aka.ms_ghei36&d=DwMFAg&c=tSGu_Pc6mPnB6zIYTZr3Sw&r=PTnT2JXctjp4MTPziGqcrg&m=SynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI&s=wPjf0flvlyR164RzC6qod76IJztI6nHPHP-lEfY7Df4&e=> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Kip Bates <kbates () HOUSING UCSB EDU<mailto:kbates () HOUSING UCSB EDU>> Sent: Thursday, October 3, 2019 4:34:08 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: [SECURITY] Ransomware Playbook Colleagues: I am hoping that I can find someone or someplace that has made an effort to develop a Ransomware Response playbook that they would not mind sharing. I understand all the preparation that needs to occur prior to an attack but I am looking for something that we can provide users, help desk folks, technicians and such on what actions to take if (when) they experience a ransomware attack. I have found a few on the web and I was wondering if someone has adapted one of these for their institution or have developed one that they think is particularly good. Feel free to comment here or off-list. Kip Bates Associate Chief Information Security Officer University of California, Santa Barbara ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fwww.educause.edu-252Fcommunity-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Ceeb9effb345442318b0a08d748429912-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637057323178918904-26sdata-3DjUWrk2Wt4Gr-252BBW9ZZXxvxCnl0II1IpaYOvaKgjB5XWY-253D-26reserved-3D0&d=DwMFAg&c=tSGu_Pc6mPnB6zIYTZr3Sw&r=PTnT2JXctjp4MTPziGqcrg&m=SynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI&s=wRiqkwHXt6Jf5tWQ1QiT68gVcu1m5m3M9X1VAYqNvJ4&e=> ======================================================= This message has been analyzed by Deep Discovery Email Inspector. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=tSGu_Pc6mPnB6zIYTZr3Sw&r=PTnT2JXctjp4MTPziGqcrg&m=SynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI&s=fKkuKv3i6k7W-LRIBSa1iIePP8_8E9PyJhCtYBo-r1U&e=> This email is intended for the designated recipient only, and may be confidential, non-public, proprietary, protected by the attorney/client or other privilege. Unauthorized reading, distribution, copying or other use of this communication is prohibited and may be unlawful. Receipt by anyone other than the intended recipients should not be deemed a waiver of any privilege or protection. If you are not the intended recipient or if you believe that you have received this email in error, please notify the sender immediately and delete all copies from your computer system without reading, saving, or using it in any manner. Although it has been checked for viruses and other malicious software, malware, we do not warrant, represent or guarantee in any way that this communication is free of malware or potentially damaging defects. All liability for any actual or alleged loss, damage, or injury arising out of or resulting in any way from the receipt, opening or use of this email is expressly disclaimed. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, notify us immediately by telephone at (815)-836-5950 and (i) destroy this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Ransomware Playbook Kip Bates (Oct 03)
- Re: Ransomware Playbook John Ramsey (Oct 03)
- Re: Ransomware Playbook White, Ryan (Oct 03)
- Re: Ransomware Playbook Sara Hariri (Oct 03)
- Re: Ransomware Playbook Gupta, Ravi K (Oct 03)
- Re: Ransomware Playbook Margie Muthukumaru (Oct 03)
- Re: Ransomware Playbook Woodson, Mr. Rick (Oct 03)
- Re: Ransomware Playbook White, Ryan (Oct 03)
- Re: Ransomware Playbook John Ramsey (Oct 03)
- Re: Ransomware Playbook Joey Rego (Oct 03)
- Re: Ransomware Playbook King, Ronald A. (Oct 03)
- Re: Ransomware Playbook Jonathon Poling (Oct 03)
- Re: Ransomware Playbook Barton, Robert W. (Oct 03)
- Re: Ransomware Playbook Hagan, Sean (Oct 03)
- Re: Ransomware Playbook Dan Wasson (Oct 03)
- Re: Ransomware Playbook Barton, Robert W. (Oct 03)
- Re: Ransomware Playbook John Ruggirello (Oct 04)
- Re: Ransomware Playbook John Ramsey (Oct 04)
- Re: Ransomware Playbook Jeremy Livingston (Oct 04)
- Re: Ransomware Playbook Barton, Robert W. (Oct 04)
- Re: Ransomware Playbook Frank Barton (Oct 04)
- Re: Ransomware Playbook John Ramsey (Oct 04)
- Re: Ransomware Playbook Jeremy Livingston (Oct 04)