Skip to content
CoRISE

Beyond Prevention: Detect, Contain and Recover from Ransomware

Assume compromise and define responsibility for detection, containment and trusted recovery.

1 min read
  • security
  • reliability
  • storage
Open table of contents

Conclusion

Assume compromise and define responsibility for detection, containment and trusted recovery.

Context

Where compromise cannot be excluded, decide in advance what to stop, what to preserve and which state to restore.

Design and verification scope

Assess the following responsibilities and boundaries when designing and verifying a configuration.

  • Prevent
  • Detect
  • Contain
  • Recover
  • Immutable backup
  • WORM
  • Blast radius
  • Recovery trust domains

Decision rationale

Use the relationship between Prevent and Recovery trust domains to compare the responsibilities of the selected approach and alternatives. Separate retained constraints from what the new boundary can change.

Trade-offs

Compare the implementation, maintenance and review work introduced by Detect with the control it provides. Include failure paths, operator effort and conditions in which the approach should not be adopted.

Limitations

Review attack scenarios, isolation decisions, backup deletion permissions and restore records. Retained backups are not proof of successful recovery.

These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.

Contact

Tell us about your engineering challenge.

Talk with CoRISE about the design, implementation and operation of your systems.

Start a Conversation