{"id":39564,"date":"2024-02-28T20:09:00","date_gmt":"2024-02-28T20:09:00","guid":{"rendered":"https:\/\/zpesystems.com\/?p=39564"},"modified":"2024-05-15T06:47:54","modified_gmt":"2024-05-15T13:47:54","slug":"what-to-do-if-youre-ransomwared-a-healthcare-example","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/","title":{"rendered":"What to do if You&#8217;re Ransomware&#8217;d: A Healthcare Example"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg&#8221; alt=&#8221;What to do if youre ransomwared&#8221; title_text=&#8221;What to do if youre ransomwared&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>This article was written by <a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe, CISSP<\/a>, a 30-year cybersecurity expert who&#8217;s helped major companies including Microsoft and Fortinet.<\/em><\/p>\n<p><span style=\"font-weight: 400;\">Ransomware gangs target the innocent and vulnerable. They <\/span><a href=\"https:\/\/therecord.media\/ransomware-saint-anthony-hospital-chicago\"><span style=\"font-weight: 400;\">hit a Chicago hospital<\/span><\/a><span style=\"font-weight: 400;\"> in December 2023, a <\/span><a href=\"https:\/\/lfpress.com\/news\/local-news\/windsor-hospital-still-months-away-from-full-cyberattack-recovery\"><span style=\"font-weight: 400;\">London hospital<\/span><\/a><span style=\"font-weight: 400;\"> in October the same year, and <\/span><a href=\"https:\/\/www.govtech.com\/education\/k-12\/new-jersey-hit-by-cyber-attacks-on-schools-hospitals\"><span style=\"font-weight: 400;\">schools and hospitals in New Jersey<\/span><\/a><span style=\"font-weight: 400;\"> as recently as January 2024. This is one of the biggest reasons I\u2019m committed to stopping these criminals by educating organizations on how to re-think and re-architect their approach to cybersecurity.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In previous articles, I discussed IMI (Isolated Management Infrastructure) and IRE (Isolated Recovery Environments), and how they could have quickly altered outcomes for <\/span><a href=\"https:\/\/zpesystems.com\/dissecting-the-mgm-cyberattack-lions-tigers-bears-oh-my\/\"><span style=\"font-weight: 400;\">MGM<\/span><\/a><span style=\"font-weight: 400;\">, <\/span><a href=\"https:\/\/zpesystems.com\/breaking-down-the-2023-ragnar-locker-cyberattacks\/\"><span style=\"font-weight: 400;\">Ragnar Locker<\/span><\/a><span style=\"font-weight: 400;\"> victims, and organizations affected by the <\/span><a href=\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\"><span style=\"font-weight: 400;\">MOVEit vulnerability<\/span><\/a><span style=\"font-weight: 400;\">. Using IMI and IRE, organizations find that the key to not only speedy recovery, but also to limiting the blast radius and attack persistence, is <\/span><b>isolation<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Why is isolation (not segmentation) key to ransomware recovery?<\/h1>\n<p><span style=\"font-weight: 400;\">The NIST framework for incident response has five steps: Identify, Protect, Detect, Respond, and Recover. It\u2019s missing a crucial step, however: Isolate. Stay tuned for a full breakdown of this in my next article. But the reason this is so critical is because attacks move at machine speed, and are very pervasive and persistent. If your management network is not fully isolated from production assets, the infection spreads to everything. Suddenly, you\u2019re locked out completely and looking at months of tedious recovery. For healthcare providers, this jeopardizes everything from patient care to regulatory compliance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Isolation is integral to building a <\/span><a href=\"https:\/\/zpesystems.com\/network-resilience-zs\/\"><span style=\"font-weight: 400;\">resilience system<\/span><\/a><span style=\"font-weight: 400;\">, or in other words, a system that gives you more than basic serial console\/out-of-band access and instead provides an entire infrastructure dedicated to keeping you in control of your systems \u2014 be it during a ransomware attack, ISP outage, natural disaster, etc. Because this infrastructure is physically and virtually isolated from production (no dependencies on production switches\/routers, no open management ports, etc.), it\u2019s nearly impossible for attackers to lock you out.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-39272 size-full\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/06\/A-diagram-showing-a-multi-layered-out-of-band-isolated-management-infrastructure.jpg\" alt=\"\" width=\"616\" height=\"661\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/06\/A-diagram-showing-a-multi-layered-out-of-band-isolated-management-infrastructure.jpg 616w, https:\/\/zpesystems.com\/wp-content\/uploads\/2022\/06\/A-diagram-showing-a-multi-layered-out-of-band-isolated-management-infrastructure-480x515.jpg 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 616px, 100vw\" \/><\/p>\n<p><span style=\"font-weight: 400;\">So, what really should you do if you\u2019re ransomware\u2019d? Let\u2019s walk through an example attack on a healthcare system, and compare the traditional DR (Disaster Recovery) response to the IMI\/IRE approach.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>Ransomware in Healthcare: Disaster Recovery vs Isolated Recovery<\/h1>\n<p><span style=\"font-weight: 400;\">Suppose you\u2019re in charge of a hospital\u2019s network. MDIoT, patient databases, and DICOM storage are the crown jewels of your infrastructure. Suddenly, you discover ransomware has encrypted patient records and is likely spreading quickly to other crown jewel assets. The risks and potential fallout can\u2019t be understated. Millions of people are depending on you to protect their sensitive info, while the hospital is depending on you to help them avoid regulatory\/legal penalties and ensure they can continue operating.<\/span><\/p>\n<h3>The problem with Disaster Recovery<\/h3>\n<p><span style=\"font-weight: 400;\">Though the word \u2018recovery\u2019 is in the name, the DR approach is limited in its capacity to recover systems during an attack. Disaster Recovery typically employs a couple things:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Backups, which are copies of data, configurations, and code that are used to restore a production system when it fails.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Redundancy, which involves duplicating critical systems, services, and applications as a failsafe in the event that primaries go down (think cellular failover devices, secondary firewalls, etc.).<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">What happens when you activate your DR processes? It\u2019s highly likely that you won\u2019t be able to, and that\u2019s because the typical DR setup relies on the production network. There\u2019s no <\/span><b>isolation<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Think about it this way: your backup servers need direct access to the data they\u2019re backing up. If your file servers get pwned, your backup servers will, too. If your primary firewall gets hacked, your secondary will, too. The problem with backup and redundancy systems \u2014 and any system, for that matter \u2014\u00a0is that when they depend on the underlying infrastructure to remain operational, they\u2019re just as susceptible to outages and attacks. It\u2019s like having a reserve parachute that depends on the main parachute.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">And what about the rest of your systems? You just discovered the attack has encrypted your servers and is quickly bringing operations to a crawl. How are you going to get in and fight back? What if you try to log into your management network, only to find that you\u2019re locked out? All of your tools, configurations, and capabilities have been compromised.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is why CISA, the FBI, US Navy, and other agencies recommend implementing Isolated Management Infrastructure.<\/span><\/p>\n<h3>IMI and IRE guarantee you can fight back against ransomware<\/h3>\n<p><span style=\"font-weight: 400;\">You discover that the ransomware has spread. Not only has it encrypted data and stopped operations, but it has also locked you out of your own management network and is affecting the software configurations throughout the hospital. This is where IMI (Isolated Management Infrastructure) and IRE (Isolated Recovery Environment) come in.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Because IMI is physically separate from affected systems, it guarantees management access so teams can set up communication and a temporary \u2018war room\u2019 for incident response. The IRE can then be created using a combination of cellular, compute, connectivity, and power control (see diagram for design and steps). Docker containers should be used to bring up each step.<\/span><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-39571 size-full\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/IRE-Tools-and-protocol.png\" alt=\"Diagram showing a chart containing the systems and open-source tools that can be deployed for an Isolated Recovery Environment\" width=\"1867\" height=\"1080\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/IRE-Tools-and-protocol.png 1867w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/IRE-Tools-and-protocol-1280x740.png 1280w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/IRE-Tools-and-protocol-980x567.png 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/IRE-Tools-and-protocol-480x278.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1867px, 100vw\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Image: The infrastructure and incident response protocol involved in the Isolated Recovery Environment. These products were chosen from free or open source projects that have proven to be very useful in each of these stages of recovery. These can be automated in pieces for each phase, and then be brought down via Docker container to eliminate the risk of leakage or risk during each phase.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Without diving too far into the technicalities, the IRE enables you to recover survivable data, restore software configurations, and prevent reinfection. Here are some things you can do (and should do) in this scenario, courtesy of the IRE:<\/span><\/p>\n<h4>Establish your war room<\/h4>\n<p><span style=\"font-weight: 400;\">You can\u2019t fight ransomware if you can\u2019t securely communicate with your team. Use the IRE to create offline, break-the-glass accounts that are not attached to email. This allows you to communicate and set up ticketing for forensics purposes.<\/span><\/p>\n<h4>Isolate affected systems<\/h4>\n<p><span style=\"font-weight: 400;\">There\u2019s no use running antivirus if reinfection can occur. Use the IRE to take offline the switch that connects the backup and file servers. Isolate these servers from each other and shut down direct backup ports. Then, you can remote-in (KVM, iKVM, iDRAC) to run antivirus and EDR (Endpoint Detection and Response).<\/span><\/p>\n<h4>Restore data and device images<\/h4>\n<p><span style=\"font-weight: 400;\">The key is to have backup data at its most current, both for patient data and device\/software configurations. Because the IRE provides an isolated environment, and you\u2019ve already pulled your backups offline, you can gradually restore data, re-image devices, and restore configurations without risking reinfection. The IRE ensures devices \u201ckeep away\u201d from each other until they can be cleansed and recovered.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.25.0&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>Things You&#8217;ll Need To Build The IMI and IRE<\/h2>\n<h3>Network Automation Blueprint<\/h3>\n<p><span style=\"font-weight: 400;\">We\u2019ve created a comprehensive blueprint that shows how to implement the architecture for IMI and IRE. Don\u2019t let the name fool you. The Network Automation Blueprint covers everything from establishing a dedicated management network, to automating deployment of services for ransomware recovery. Get your PDF copy now at the link below.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/network-automation-blueprint\/&#8221; button_text=&#8221;Download blueprint&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.25.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Gen 3 Console Servers To Replace End-of-Life Gear<\/h3>\n<p><span style=\"font-weight: 400;\">It&#8217;s nearly impossible to build the IMI or deploy the IRE using older console servers. That&#8217;s because these only give you basic remote access and a hint of automation capabilities. You&#8217;ll still need the ability to run VMs and containers. Gen 3 console servers let you do all of the things for IMI and IRE, like full control plane\/data plane separation, hosting apps, and deploying VMs\/containers on-demand. They&#8217;ve also been validated by Synopsys and have built-in security features I&#8217;ve been talking about for years. Check out the link below for resources about Gen 3 and how we&#8217;ll help you upgrade.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/replace-discontinued-console-servers-with-zpe-systems-complete-products-services-solution\/&#8221; button_text=&#8221;Upgrade to Gen 3&#8243; _builder_version=&#8221;4.25.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>Get in touch with me!<\/h2>\n<p><span style=\"font-weight: 400;\">I\u2019d love to talk with you about IMI, IRE, and resilience systems. These are becoming more crucial to operational resilience and ransomware recovery, and countries are passing new regulations that will require these approaches. Get in touch with me via social media to talk about this!<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe &#8211; CISSP on LinkedIn<\/a><\/li>\n<li><a href=\"https:\/\/twitter.com\/how2cloud?lang=en\">@how2cloud on X &#8211; James Cabe<\/a><\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity expert James Cabe discusses what to do if you&#8217;re on the receiving end of a ransomware attack, including isolating systems.<\/p>\n","protected":false},"author":5,"featured_media":39566,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[98,103,156,101,93,82,97,81,112,134],"tags":[],"class_list":["post-39564","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-logging","category-improve-network-security","category-micro-segmentation","category-minimize-impact-of-disruptions","category-network-automation","category-out-of-band-management","category-user-management","category-virtualization","category-zero-touch-provisioning","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What to do if You&#039;re Ransomware&#039;d: A Healthcare Example<\/title>\n<meta name=\"description\" content=\"Cybersecurity expert James Cabe discusses what to do if you&#039;re on the receiving end of a ransomware attack, including isolating systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What to do if You&#039;re Ransomware&#039;d: A Healthcare Example\" \/>\n<meta property=\"og:description\" content=\"Cybersecurity expert James Cabe discusses what to do if you&#039;re on the receiving end of a ransomware attack, including isolating systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2024-02-28T20:09:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-15T13:47:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/\",\"url\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/\",\"name\":\"What to do if You're Ransomware'd: A Healthcare Example\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg\",\"datePublished\":\"2024-02-28T20:09:00+00:00\",\"dateModified\":\"2024-05-15T13:47:54+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"Cybersecurity expert James Cabe discusses what to do if you're on the receiving end of a ransomware attack, including isolating systems.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg\",\"width\":1200,\"height\":627,\"caption\":\"Image of James Cabe along with the article title, What to do if You're Ransomware'd\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What to do if You&#8217;re Ransomware&#8217;d: A Healthcare Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"What to do if You're Ransomware'd: A Healthcare Example","description":"Cybersecurity expert James Cabe discusses what to do if you're on the receiving end of a ransomware attack, including isolating systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/","og_locale":"en_US","og_type":"article","og_title":"What to do if You're Ransomware'd: A Healthcare Example","og_description":"Cybersecurity expert James Cabe discusses what to do if you're on the receiving end of a ransomware attack, including isolating systems.","og_url":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/","og_site_name":"ZPE Systems","article_published_time":"2024-02-28T20:09:00+00:00","article_modified_time":"2024-05-15T13:47:54+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/","url":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/","name":"What to do if You're Ransomware'd: A Healthcare Example","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg","datePublished":"2024-02-28T20:09:00+00:00","dateModified":"2024-05-15T13:47:54+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"Cybersecurity expert James Cabe discusses what to do if you're on the receiving end of a ransomware attack, including isolating systems.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg","width":1200,"height":627,"caption":"Image of James Cabe along with the article title, What to do if You're Ransomware'd"},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/what-to-do-if-youre-ransomwared-a-healthcare-example\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"What to do if You&#8217;re Ransomware&#8217;d: A Healthcare Example"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-300x157.jpg",300,157,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-1024x535.jpg",1024,535,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-1080x627.jpg",1080,627,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-1080x564.jpg",1080,564,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared.jpg",1200,627,false],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-980x512.jpg",980,512,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2024\/02\/What-to-do-if-youre-ransomwared-480x251.jpg",480,251,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/\" rel=\"category tag\">Data Logging<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/\" rel=\"category tag\">Improve Network Security<\/a> <a href=\"https:\/\/zpesystems.com\/category\/micro-segmentation\/\" rel=\"category tag\">Micro-segmentation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/minimize-impact-of-disruptions\/\" rel=\"category tag\">Minimize Impact of Disruptions<\/a> <a href=\"https:\/\/zpesystems.com\/category\/increase-productivity\/network-automation\/\" rel=\"category tag\">Network Automation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/out-of-band-management\/\" rel=\"category tag\">Out of Band Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/user-management\/\" rel=\"category tag\">User Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/simplify-branch-infrastructure\/virtualization\/\" rel=\"category tag\">Virtualization<\/a> <a href=\"https:\/\/zpesystems.com\/category\/streamline-deployments\/zero-touch-provisioning\/\" rel=\"category tag\">Zero Touch Provisioning (ZTP)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"Cybersecurity expert James Cabe discusses what to do if you're on the receiving end of a ransomware attack, including isolating systems.","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/39564","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=39564"}],"version-history":[{"count":8,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/39564\/revisions"}],"predecessor-version":[{"id":40859,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/39564\/revisions\/40859"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/39566"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=39564"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=39564"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=39564"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}