Ransomware is malicious software that will encrypt computer systems. Often delivered via a phishing email the threat actor will demand payment to decrypt this data. Often, even if money is paid, the decryption process may fail. As IT and OT systems are often linked there can be a direct impact on a production facility following a ransomware incident resulting in loss of production and system downtime.
Patching, good backups and a segmented network are good measures to help prevent ransomware, as well as good user education, email filtering and management. OT assets must be documented and fully understood as well as how they connect to IT systems. Use of properly configured firewalls can be helpful. Ultimately the answer to a successful ransomware incident is to restore systems from backup. This must include OT systems and the backup must be secured from inadvertently being encrypted by the same ransomware. Finally a good, well-rehearsed incident response and recovery plan will ensure that should you be a victim of ransomware you have the people, process and technologies in place to deal with it.