Prevention is the best way to protect yourself from ransomware.
If you suspect that you’ve been infected with ransomware, immediately disconnect your device from the network.
Backup regularly. In addition to ransomware, systems are also exposed to other types of malware (viruses, trojans, spyware, etc.). It’s important to have backups in order to easily and quickly restore files. It’s equally important to test backups, to verify if they are being properly done and that they can correctly restored.
Storing a recent backup on a unit where files cannot be changed. Ransomware effects files that have write permission, including files that are stored on cloud folders (Dropbox, Google Drive, and One Drive, for instance), and external USB units, among other types of storage formats.
Using software that allows you to neutralize threats in real time, for instance, blocking access to websites that contain malicious code and analyzing downloaded files.
Don’t activate macros for files you’ve received via email. Malicious attachments are one of the main sources of ransomware infection. Perpetrators try to persuade users to activate macros so that they can be infected by ransomware.
Don’t click on links or visit websites from suspicious email messages. Typically, attackers incentivize users to make an impulsive action, such as opening a document or clicking on a link that may result in infection. To achieve this, they send email messages, posing as governmental agencies (for instance, the fiscal authorities), public safety (police or information services), or know companies (Paypal, Fedex, or DHL). The messages’ content is typically urgent and/or intimidating, demanding that immediate action from the user, such as opening a document or visiting a website to solve a false situation. Usually, to conduct these actions, the user has to install or execute some kind of software (which is later revealed to be malicious).
Show filename extensions. Some files that contain malicious code add extensions to the filenames, making them seem like inoffensive file extensions. By activating this option, you can easily view the type of file that you’re trying to open (for example: “invoice.pdf” becomes “invoice.pdf.exe”, in the event you’ve been sent an executable file).
Don’t use administrator/root permissions if unnecessary. A user without administrator permissions is sufficient to execute most of the device’s usual tasks. As such, even if the malicious code is executed, there is a chance of not having the necessary permissions to make damaging changes to the system.
Restricting write permissions on file servers whenever possible.
Installing the latest security updates for the operating system and other installed software.
Educate users regarding the threat and define a procedure for when they suspect of an email, pop-up, file, or program.
The best solution is to be prepared for a ransomware attack.