Contact Us

Continuity Insights Management Conference

Are Ransomware Events Considered in your Operational Resilience Plans for Third Party Service Providers?

The Federal Bureau of Investigation (FBI), Cybersecurity & Infrastructure Security Agency (CISA), and the U.S. Department of the Treasury have released a joint Cybersecurity Advisory (CSA) to provide information on Maui ransomware. They believe North Korean state-sponsored cyber actors have used Maui ransomware since at least May 2021 to target Healthcare and Public Health (HPH) Sector organizations.

Maui ransomware utilizes a hybrid encryption approach to render its victim’s files useless. Maui is designed for manual execution by the threat actor, allowing its operators to specify which files to encrypt and target the most important assets on a network.

The updated CSA highly discourages paying ransoms as it does not guarantee files will be recovered and may pose sanctions risks. The CSA encourages entities to adopt and improve cybersecurity practices and report ransomware attacks to law enforcement.

To ensure appropriate oversight activities, we’ve identified five key steps to incorporate into your risk management plans:

Continuity Insights

Similar Articles

BCM Staff Development and Maintaining BCM Staff Readiness

Your BIAs are up to date. Your plans are perfect, down to the last detail. You’ve trained your executives, your business partners, the rank and file. But what about your …

Webinar Announcement: New Date Scheduled

As Hurricane Florence poses imminent danger to our families, friends, and colleagues in the Carolinas and Virginia, we felt that it was in the best interests of everyone to postpone …

OnSolve Releases New Organizational Resilience Checklist/Infographic for Security Professionals

In an era of rising risk and uncertainty, security professionals are all but guaranteed to face one or more critical events at some point—from severe weather and civil unrest to …

Leave a Comment

Share to...