In this case, LAUSD did not pay a ransom–a critical decision and one that we strongly recommend to any organization in a similar situation. Organizations should never pay a ransom when attacked by cybercriminals. If organizations do comply with ransom demands, bad actors often replicate the attack on a larger scale to get more money. Or, they fail to hold up their end of the bargain, and they take the money and data and run. However, not updating cybersecurity protocols following an attack is a missed opportunity. Here’s how other educational institutions can avoid making the same mistake as LAUSD.
Don’t drop the ball on preventative and restorative measures
While the innovation surrounding AI and ML enables ransomware attacks to become more sophisticated, it also helps IT leaders and school administrators combat these growing threats. The key is to implement AI and ML technology sooner than later and follow through on long-term maintenance.
But where to start? According to InterVision research, most business leaders feel that ransomware is the top threat to security, but they need help determining the best approach to securing their systems. Many want to move fast to patch the immediate threat and fix more significant issues later, but the reality is: a holistic approach to cybersecurity requires both methods.
The hesitancy to implement a comprehensive cybersecurity protection plan is understandable. School administrators are stretched thin. But here’s a little secret: the best cybersecurity plans are not typically designed and deployed in-house. Many organizations outsource to trusted third-party strategic service providers that can provide consistent monitoring and adjustments based on years of industry experience. The right provider will also offer a more tailored solution, typically leveraging Ransomware Protection as a Service (RPaaS). For education institutions, this is particularly important given the consistent use of multi- cloud and hybrid environments still using on-prem data storage.
With early implementation and the right partner, administrators and IT teams can focus more on initiatives that impact the lives and education of students, faculty and staff and less on dealing with cyber breaches and ransomware attacks. It’s time for education leaders to review their options, as ransomware will only continue to rise in 2023.
Related:
In cybersecurity, balancing vigilance with access
How a cloud-based ERP helps schools innovate and be nimble
