Follow us on Twitter!
Blog Header Logo
DG&A's Transportation Consulting Blog
Posted by on in Ransomware
  • Font size: Larger Smaller
  • Hits: 1210
  • 0 Comments
  • Print

How to Protect Logistics and Transportation Organizations from Ransomware Attacks

b2ap3_thumbnail_dreamstime_l_89526664.jpg

Ransomware is a computer virus that takes over the target device, restricts the owner’s access, and demands the victim to pay a ransom to get their device back. Modern ransomware can steal files, target locally-stored backups, spread through the network, and even bring large organizations to a standstill.

The device can get infected through a malicious email, a spoofed website, or in many other ways. Then, the attackers may scan the device for something valuable or, if pressed for time, start encrypting everything at once. After encrypting the data, the ransomware will display a ransomware note with detailed instructions on how to create a cryptocurrency wallet and send Bitcoin to the attackers’ address.

In Canada, two of the most recent high profile ransomware attacks have been to the Toronto Transit Commission (the largest public transportation network in Canada’s largest city) that knocked down some of its communications system and a provincewide disruption of health-care services in Newfoundland and Labrador that affected thousands of appointments and procedures, including those involving COVID-19 testing. The annual Canadian Internet Registration Authority (CIRA) Cybersecurity Survey says nearly 70 per cent of Canadian organizations facing a ransomware attack last year paid the demands to avoid downtime, reputational damage, and other costs.

In 2021, ransomware has increased to thousands of attacks per day and is predicted to cost businesses over $20 billion. Many successful attacks may be left undisclosed.

Logistics and transportation was ranked the seventh most likely to be hit by a ransomware attack, among 35 identified industries, according to a new study from Nordlocker (nordlocker.com). The study was based on an analysis of 1,200 companies hit by cyber extortion between 2020 and 2021.

The 59 transportation and logistics companies affected range from industry leaders, such as one of the biggest European shipping companies with a fleet of 230 ships, to small enterprises, such as a household moving company in Montana, US. The findings raise the question:

Why do cyber criminals prioritize the logistics and transportation industry?

The Nordlocker report suggests that “the logistics and transportation business could be enticing to cyber racketeers because of the core position this industry occupies on the world stage. ‘The interconnected nature of logistics to businesses all over means that, in the event of a ransomware attack, not only does the company’s reputation get questioned but also numerous supply chains get disrupted, exerting mounting pressure to pay the demanded ransom,’ says Oliver Noble, a cybersecurity expert at Nordlocker, an encrypted cloud service provider. In addition, the industry’s relatively traditional business model, which is in large part yet to include up-to-date cybersecurity solutions, could incentivize hackers towards certain companies.”

How can a company protect itself from a Ransomware attack?

Here are some tips from Chris Thomas, Vice President, Industrial at Darktrace (darktrace.com).

Gain complete visibility into your entire digital infrastructure. From IoT devices to on-prem servers, for a successful security strategy, you need to understand how your technology is communicating, as well as where and why.

Organization-wide mandatory security training. All employees need basic security hygiene and to employ precautionary protocols like implementing multi-factor authentication and using VPNs.

Implement security tools. Security technologies like autonomous detection and response and segmentation that can identify and contain cyber-threats can give security teams time to remediate the attack before it can spread laterally throughout the business and cause significant disruption and financial damage.

Identify vulnerabilities. Whether through red-teaming or not, organizations need to identify their vulnerable areas and patch them as soon as possible to remediate those risks. Organizations should be consistently updating their software and hardware when possible, but continuously monitoring devices will ensure unpatched or unknown vulnerabilities are covered, too.

Regularly back up and encrypt data. This process will protect your data in the worst-case scenario that your organization’s data was stolen or held for ransom.

Oliver Noble offered some easy-to-implement cybersecurity tactics to serve your business as defense:

Make sure your employees use strong and unique passwords to connect to your systems. Better yet, implement multi-factor authentication.

Secure your email by training your staff to identify signs of phishing, especially when an email contains attachments and links.

Adopt zero-trust network access, meaning that every access request to digital resources by a member of staff should be granted only after their identity has been appropriately verified.

Mr. Noble added that even though big companies have a higher probability to offer hackers larger ransoms, small companies are not safe either. “Small enterprises usually do not have the same cybersecurity checks in place as larger businesses, making them an easier target for ransomware attacks. That being said, major companies are still the preferred targets, as their deeper pockets and higher stakes make them more likely to pay up,” the expert noted.

NordLocker states that it is the world’s first end-to-end file encryption tool with a private cloud. It was created by the cybersecurity experts behind NordVPN – one of the most advanced VPN service providers in the world. NordLocker is available for Windows and macOS.

Darktrace’s mission is to empower organizations to stop the disruption that cyber-threats can cause, across digital infrastructures everywhere. Darktrace AI enables organizations of all industry sectors to build up resilience against novel attacks, by autonomously learning their ‘digital DNA’. Darktrace’s Self-Learning AI defends people, data and infrastructure from whatever is around the corner.

 

To stay up to date on Best Practices in Freight Management, follow me on Twitter @DanGoodwill and join the Freight Management Best Practices group on LinkedIn.

0

Comments

  • No comments made yet. Be the first to submit a comment

Leave your comment

Guest Monday, 29 April 2024

Most Recent Posts

Search


Tag Cloud

Horizontal Supply Chain Collaboration customer engagement Amazon cyber security buying trucking companies marketing last mile delivery Digital Freight Networks small business JB Hunt Sales Training home delivery Freight Management Management Transportation service recession Ferromex intermodal Canadian economy Toronto Maple Leafs CSX Outsourcing Sales asset management Training New Hires Driver Shortage Grocery Success Tracy Matura US Economy computer security BlueGrace Logistics Dedicated Trucking network optimization US Manufacturing MPG rail safety Blogging carrier conference economy dynamic pricing Keystone Pipeline 2013 Economic Forecast Career Advice computer dark stores broker bonds business security Education BNSF Wal-Mart Montreal Canadiens autos Spanx Toronto Global Transportation Hub transportation news 3PL Twitter Derek Singleton ProMiles Distribution Freight Capacity Yield Improvement freight cost savings 2015 Economic Forecast fuel surcharge General Motors Sales freight rate increases Retail NCC tanker cars Job satisfaction transportation audit peak season Harper Davos speech Business Strategy energy efficiency Bobby Harris LinkedIn Conway Broker financial management TransForce Otto cars Digitization Dedicated Contract Carriage Freight Carriers Association of Canada capacity shortage Crisis management driver pay YRCW Transcom Fleet Leasing Transplace driver shortages Canadian truckers Climate Change EBOR Leadership Sales Management routing guide shipping Regina USA Truck future of freight industry Business Transformation Strategy Loblaw natural disasters FMS online shopping LTL business start-up freight transportation Geopolitics Canada U.S. trade NAFTA Global experience freight costs Electric Vehicles UP cheap oil US Housing Market economic outlook Dan Goodwill Search engine optimization employee termination Reshoring Trump computer protection CN Rail NMFC Packaging CSA scores Freight Recession Canada shipper-carrier contracts US Auto Sales Trucker Protest Habs driver Rate per Mile freight agreements New York Times professional drivers freight marketplace Muhammad Ali President Obama Celadon Werner Software Advice home delibery 3PLTL University of Tennessee Online grocery shopping MBA Canadian Transportation & Logistics freight bid Masters in Logistics Comey Entrepreneur Donald Trump Right Shoring e-commerce Facebook CP Rail freight RFP Canada-U.S. trade agreement YRC Doug Nix Blockchain Business Development Failure freight transportation conference CN China NS robotics ShipMax 2012 Transportation Business Strategies. Jugaad derailments Social Media in Transportation Canada's global strategy Transportation economic forecasts for 2012 Microsoft Colilers International Leafs Canadian freight market Rail CSA ELD bulk shipping shipper-carrier collaboration Success failure entrepreneur Carriers risk management Freight Load broker freight forwarders digital freight matching Sales Strategy trucking company acquisitions Freight Matching Freight Shuttle System 2014 economic forecast consumer centric broker security APL Associates Surety bond drones truck drivers Load Boards Cleveland Cavaliers Railway Association of Canada Schneider Logistics hiring process technology Crude Oil by Rail Rotman School of Business CRM Anti-Vax truck driver Government small parcel 360ideaspace capacity shortages trade $75000 bond coaching selling trucking companies Transportation Buying Trends Survey supply chain management LCV's pipelines Value Proposition laptop Map-21 mentoring Retail transportation Trucking FCA Business skills shipping wine automation Warehousing Shipper freight payment freight audit Freight Rates Doug Davis Fire Phone truck capacity RFP FCPC solutions provider Adrian Gonzalez Hockey Finance and Transportation Infrastructure Justice freight payment transportation newspaper Emergent Strategy Hudsons Bay Company Truckload autonomous vehicles Consulting Stephen Harper Trade Vision Freight contracts Impeachment Accessorial Charges freight audit freight broker Covid-19 TMS USMCA shipper-carrier roundtable Inbound Transportation Uber Freight FuelQuest Politics Life Lessons dimensional pricing David Tuttle Scott Monty Whole Foods Transloading IANA KCS Tariffs CITA Shipper Pulse Survey Driving for Profit the future of transportation 2014 freight volumes Canadian Protests Training 2014 freight forecast FMCSA freight transportation in 2011 TMP Worldwide Omni Channel Coronavirus Swift Deferred Packaging driverless Social Media Transport Capital Partners (TCP) US Election

Blog Archives

April
March
February
December
October
September
August
June
May
April
March
January