Educause Security Discussion mailing list archives

Re: Ransomware Playbook


From: "Barton, Robert W." <bartonrt () LEWISU EDU>
Date: Fri, 4 Oct 2019 14:01:12 +0000

I will be there.  Hit me up off list if you have time.

Robert W. Barton
Executive Director of Information Security and Policy
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Frank Barton
Sent: Friday, October 4, 2019 7:36 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

I'm going to add my "Me Too!" to this thread. along with the obligatory question: How many of us are going to Educause 
in just over a week? I think this would be a great thing to chat about over a cuppa (coffee or $beverage of choice)

as it stands right now, I am in the process of trying to build our library of playbooks for various incident response 
scenarios, and to be completely honest, I'm not even always sure what scenarios to plan for.

Frank

On Fri, Oct 4, 2019 at 8:16 AM Sol Bermann <solb () umich edu<mailto:solb () umich edu>> wrote:
Always interested in seeing how I can improve what we have

On Thu, Oct 3, 2019, 11:51 PM Bingdong Li <bli () nshe nevada edu<mailto:bli () nshe nevada edu>> wrote:
I’m interested too. Thank you!

Thank you.

Bing Li, PhD CISSP
Nevada System of Higher Education/System Computing Services
Phone (775)789-3703

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of John Ramsey
Sent: Thursday, October 3, 2019 1:50 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

I have one and am happy to share!
Sent from my Verizon, Samsung Galaxy smartphone
Get Outlook for 
Android<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2Fghei36&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260479382&sdata=VvCs706e1x4Io9IhsWSKJJ85csN4Kc0I8fztoZfhYwA%3D&reserved=0>

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Kip Bates <kbates () HOUSING UCSB EDU<mailto:kbates () HOUSING UCSB EDU>>
Sent: Thursday, October 3, 2019 4:34:08 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: [SECURITY] Ransomware Playbook

Colleagues:

I am hoping that I can find someone or someplace that has made an effort to develop a Ransomware Response playbook that 
they would not mind sharing. I understand all the preparation that needs to occur prior to an attack but I am looking 
for something that we can provide users, help desk folks, technicians and such on what actions to take if (when) they 
experience a ransomware attack. I have found a few on the web and I was wondering if someone has adapted one of these 
for their institution or have developed one that they think is particularly good.

Feel free to comment here or off-list.


Kip Bates
Associate Chief Information Security Officer
University of California, Santa Barbara


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260479382&sdata=W%2BaQgrEonNgnlZwkJTbHfK1Rqj5DAA0IDnl13Mng%2Bms%3D&reserved=0>

=======================================================

This message has been analyzed by Deep Discovery Email Inspector.


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cbli%40NSHE.NEVADA.EDU%7Cb01d4110af3a4866ec3f08d748435016%7C8ff9d11a9e074150ac216eedccccc3d3%7C0%7C0%7C637057326260489380&sdata=b4l%2Fw1joQi9IozijuDOiBbx%2Bn6TIf2GMRWpiFjXmod4%3D&reserved=0>
PUBLIC RECORDS NOTICE: In accordance with NRS Chapter 239, this email and responses, unless otherwise made confidential 
by law, may be subject to the Nevada Public Records laws and may be disclosed to the public upon request.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


--
Frank Barton, MBA
Security+, ACMT, MCP
IT Systems Administrator
Husson University

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

This message (including any attachments) is intended only for
the use of the individual or entity to which it is addressed and
may contain information that is non-public, proprietary,
privileged, confidential, and exempt from disclosure under
applicable law or may constitute as attorney work product.
If you are not the intended recipient, you are hereby notified
that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at (815)-836-5950 and
(i) destroy this message if a facsimile or (ii) delete this message
immediately if this is an electronic communication.

Thank you.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: