4 ms·
Ask HN: How easy is it to get infected with ransomware?
So it seems every other week, orgs are getting compromised with ransomware (and now recently even Linux-based ransomware). My question is: How easy is it to get infected with ransomware?
I like to consider my setup bolstered against ransomware and malware. I leverage all the usual security/mitigation strategies like compartmentalization, isolation, segmentation of the network, different virtual machines for different things, different USB thumb-drives for different things, obscure (encrypted) filesystems that can't be accessed by (Windows-based) ransomware, reducing the attack surface, and using 'principle of least privilege' using Linux, not opening malicious email attachments, etc. In short, I am not immune, but I like to think I have a good degree of damage control in place.
But do orgs do this too? I would like to think so, but how are so many orgs getting hit now? What kind of vectors are these ransomware gangs using?