Notice of Data Breach : Learn about a data breach Ocuco recently experienced

Has Ocuco Transformed Your Business? Refer us and get rewarded!

Combatting Ransomware with Training: The Best Defence is Education

Combatting Ransomware with Training: The Best Defence is Education

Ransomware is to data as Glaucoma is to Optometry. One steals away data as the other steals away sight. Ransomware, a type of malware that threatens to perpetually block access to a victim’s data unless a ransom is paid, affects everything from small businesses right up to the largest of organisations and government institutions.

Some reports suggest that ransomware attacks are becoming more prevalent. In 2020, a CheckPoint study saw a 50% increase in the daily average of ransomware attacks in Q3, compared to the first half of the year (1). One survey found that half of all respondents detected a ransomware attack in 2019, resulting in business disruption and possible data loss in nearly 75% of cases (2). In fact the consensus in the security industry with regards to being compromised by malware is becoming a ‘when, not if’.

Risk factors can be managed by appropriate security, backup and software patching provisions. These are crucial not only for prevention but also the recovery process post-infection.

That said, is there more that can be done to protect ourselves beyond these technical safeguards?

According to the Centre for Internet Security (CIS), a non-profit industry leader in designing best-practice standards for securing IT  and data systems, the most common vector for ransomware infections is “user-initiated actions” (3). Indeed, this is broadly true of malware historically. In responding to this, training is key.

What are “user-initiated actions”?

CIS defines these as “actions such as clicking on a malicious link in a spam email or visiting a malicious or compromised website”. In short, “user-initiated actions” are actions that involve ’the human element’, the activities of the person using the device. Therefore, it stands to reason that if we can mitigate ’the human element’, we can go a long way to improving our defences.

“Ransomware, a type of malware that threatens to perpetually block access to a person’s data unless a ransom is paid, affects everything from small businesses right up to the largest of organisations and government institutions.”

Given it is neither practical nor legal to eliminate humans, we are left with the route of mitigation through training.

A 2020 industry study produced by CyberEdge (4) found that one of the largest obstacles to security is “low security awareness among employees”.

Here are a few high-level training steps to help minimise the risk of a Ransomware attack:

  • Invest in practical and ongoing security awareness programmed that can help staff understand and minimise risk.
  • Invest in an incident management and response program, identified by CIS, as a key step in dealing with Ransomware and other scenarios.
  • Practice what the incident management and response program preaches. Many businesses have these programs have never practically rehearsed them, conducting paper exercises only. This lack of rehearsal was observed as an aggravating factor in the ransomware breach that affected the NHS in May 2017 (5).

“A 2020 industry study produced by CyberEdge found that tied first place as the largest obstacle to security is ‘low security awareness among employees’.”

No sports team takes to the pitch with a paper plan only, nor does any team take to the pitch without their players having been trained or having trained together. Training and rehearsals should be active and scenario-based, as opposed to passive information dumps via email and presentations.

Play out scenarios, run practical tests, gamify the training (many companies provide services to do exactly this). We teach our patients good optical hygiene through practical demonstration, not just through marketing materials, we should do the same for our cyber hygiene.

References:

1. https://blog.checkpoint.com/2020/10/06/study-global-rise-in-ransomware-attacks/
2. https://www.sophos.com/en-us/medialibrary/Gated-Assets/white-papers/sophos-the-state-of-ransomware-2020-wp.pdf
3. https://www.cisecurity.org/blog/ransomware-facts-threats-and-countermeasures/
4. https://cyber-edge.com/cdr/#infographic
5. https://www.nao.org.uk/wp-content/uploads/2017/10/Investigation-WannaCry-cyber-attack-and-the-NHS-Summary.pdf

Ocuco offers innovative eyecare software, designed for independents, chains, and labs. Whether you need optical retail shop software for your independent optical retail shop, optical chain software to manage a chain business or optical lab management software for your lab, we have the ideal solution for your optical needs.
Are you looking for optical practice management software?  Acuitas offers product management, electronic health record systems, appointments and multiple configurations to meet the specific needs of your optical business. Contact us today for free expert advice.

Table of Contents

Learn More About Our Products

Darragh Leahy is Head of Cloud and Infrastructure Services for Ocuco Ltd.

He is a cyber security specialist, holding two master’s degrees: one in Cyber Security and another in Digital Innovation. At Ocuco, he oversees the design and implementation of networks, security solutions and data centre environments. Darragh is also an expert in Healthcare and General Data Protection Regulations, such as GDPR, HIPAA and Canada’s PIPEDA.

Related Posts :

Optical lab management software has always been essential for manufacturing workflows: coordinating production, exchanging data…

Running an optical practice involves more than just clinical excellence. These days, if you want…

Your Ultimate Guide to Vision Expo West in Las Vegas, Preparation, Must-Sees, Insider Tips, Plus…

FAQ

What is the best EMR for optometrists?

A system that combines examination templates, imaging integration, and easy referral letters. Acuitas 3 ticks all those boxes while adding retail tools that many EMR‑only systems miss.

Yes, Acuitas 3 is a configurable optical software solution. Whether you’re looking to approve incoming online booking requests, create custom appointment types within the diary or custom eye exam workflows, Acuitas 3 offers the functionality your optical practice requires to achieve your goals.
As a modular omnichannel application, Acuitas 3 allows you to expand on existing eyecare software functionality as your optical business grows, e.g. adding the advanced CRM module for enhanced patient communication capabilities. Software is not one size fits all, Acuitas 3 evolves with your business.

Yes, data from your current system will be extracted in conjunction with your existing software provider and transferred to Acuitas 3. Those using Ocuco provided solutions: Acuitas 2, Focus, Focus 2, See20/20 your data will be migrated from your current system to Acuitas 3.
Yes, Acuitas 3 offers the largest portfolio of equipment links to imaging, diagnostic and dispensing devices within the optical industry. Our dedicated equipment links team continuously integrate the latest ophthalmic equipment to Ocuco’s optical practice management software.

Ocuco’s experienced technical support team are on-hand to provide assistance via phone and online, 6 days a week from our Dublin HQ, the UK and Vancouver. 
Our adept team combines eyecare technology expertise with optical domain knowledge to ensure your practice is supported from day one. 
Ocuco’s Academy eLearning solution offers interactive real-life simulations and training resources for staff as well as performance visibility to track progress and identify knowledge gaps. 

No data was found

Want to Learn More About any of our Products? Fill in the Form Below to Request a Demo.