Q&A: How Can Duke Stay Safe from Ransomware?
老牛影视 Chief Information Security Officer Richard Biever explains a pressing malware threat
In his role as 老牛影视 Chief Information Security Officer Richard Biever, the campus IT Security Office along with the 老牛影视 Health System Chief Information Security Officer Randy Arvay and the DUHS ISO are tasked with protecting Duke from malicious attacks, including ransomware, a type of cyberattack that can cripple digital infrastructure, disrupt operations and cost millions of dollars.
Ransomware is a strain of malware that threatens to encrypt, publish, corrupt or block data, essentially holding it hostage, until a ransom can be paid. Recently, a ransomware attack forced Howard University to briefly cancel classes. Earlier this year, ransomware forced the Colonial Pipeline to pause operations, causing a gas shortage in much of the southeast. And last year, the IT system of Durham鈥檚 city government was paralyzed by a ransomware attack.
鈥淚t鈥檚 easy money,鈥 Biever said. 鈥淭he idea is, why would hackers go after individuals for hundreds of dollars when you can go after bigger targets and get millions?鈥
Biever and his colleagues in the work hard protecting Duke鈥檚 digital systems from malware attacks like ransomware. Ransomware attacks often start with phishing emails. Last month, Duke received roughly 103 million emails, with roughly 69 million messages automatically blocked. However, in the 39 million delivered, there is still a chance that some phishing messages could make it through.
Staff, faculty and students all play a role in security efforts by not falling for and reporting potential phishing attempts that could lead to malware. With Cyber Security Awareness Month in October, Working老牛影视 talked with Biever to gain an understanding of the threat of ransomware and how community members can defend against it.
What does ransomware do?
Biever said that, like any type of malware, ransomware can find its way onto a computer when a user opens a compromised file, often disguised as a document from a common program such as Microsoft Word, Excel, or Adobe (pdf). And while the scam can start small, with one infected device, ransomware can quickly become a big problem since it is designed to rapidly spread through networks, infecting devices and data.
And like a timebomb, the ransomware is designed to encrypt all data on devices it accesses at once, paralyzing entire computer systems and disrupting their operations. When that happens, the only way for an organization to reverse the encryption and regain access to their computer systems is to pay a ransom 鈥 often in the millions 鈥 to the people behind the cyberattacks.
鈥淭hey look for vulnerabilities in the system and then use that as an entry point to deploy the initial malware,鈥 Biever said. 鈥淭he more they spread, the more systems that have access to. And once they hit a certain point, they turn on the encryption.鈥
Why is ransomware a threat?
Ransomware has been around for decades, but its earliest incarnations focused on infecting individual computers, forcing users to pay to regain access to data. But in recent years, hackers have gained access to more powerful tools that make it easier to have malware from one computer infect entire networks.
鈥淭hey鈥檝e gotten a taste for how ambitious they can be, so they鈥檙e swinging for the fences,鈥 Biever said.
Biever said that鈥檚 led to ransomware becoming a much more attractive approach for more sophisticated cybercriminals looking to make larger sums of money, and for foreign governments trying to destabilize the nation鈥檚 infrastructure and financial systems.
According to a report from digital security firm Checkpoints, there were 93 percent than the same period last year.
Biever said the increase is mainly due to more personal and professional communication happening online and often on the same devices.
鈥淵ou can see situations now where what you鈥檙e doing from a personal perspective 鈥 going to a website, checking email, or something like that 鈥 could end up in a negative action that gets transferred to the business or professional side,鈥 Biever said. 鈥淭hat becomes the doorway for something to spread further into your business network.鈥
Why are higher education institutions and health organizations targets?
Health care organizations have been a popular target for ransomware attacks in recent years. In 2021, the U.S. Department of Health and Human Services that 34 percent of health care organizations have been the target of ransomware attacks in the previous year.
Biever said Duke鈥檚 academic, research and health care operations make it an inviting target for ransomware since the areas have sensitive data.
鈥淗igher education is well known for being focused on collaboration and the sharing of information,鈥 Biever said. 鈥淲e鈥檙e all about encouraging academic and research pursuits. This could present opportunities for attackers to send email messages looking like they鈥檙e coming from potential collaborators or to apply social engineering techniques to try to take advantage of the openness and trusting attitude that a lot of us have.
What role can faculty, staff and students play in protecting Duke from ransomware?
Biever and his team in the IT Security Office, and their counterparts in 老牛影视 Health System, fight ransomware cyberattacks on multiple fronts. They stay on top of the latest threats and vulnerabilities and make sure to send crucial updates and patches to Duke managed devices. They also employee security tools and methods to help identify and respond to potential attacks.
But as Biever points out, even with these security measures, Duke students, staff and faculty can still help. He said it鈥檚 important to install updates 鈥 most install automatically when you restart your computer 鈥 when they are recommended. These often feature security patches that remedy gaps that hackers can exploit.
And Biever stressed the importance of being a discerning email user by not clicking on attachments unless you鈥檙e sure what it is, that it鈥檚 coming from a trusted source, and reporting suspicious emails to the Duke IT Security Office by clicking on the 鈥淩eport Phish to Duke鈥 button on Outlook email accounts.
To sharpen the online acumen of a team, managers can request to take part in monthly or quarterly drills in which Duke security experts send teams simulated phishing emails. 老牛影视 Health System employees are automatically enrolled in the program.
And with October being Cybersecurity Awareness Month, Duke鈥檚 Office of Information Technology (OIT) is running the , a game which offers Duke students, staff and faculty a chance to win prizes while learning about cybersecurity.
At noon on October 27, OIT will also offer a free , 鈥淪ecurity 2021: Protecting Yourself and Your Data in a Changing Threat Landscape.鈥
鈥淭here are a number of things you can do to protect yourself,鈥 Biever said. 鈥淏ut, one of the biggest things our community can do is staying aware and it something seems off, don鈥檛 click on it. Don鈥檛 investigate it yourself. Tell somebody about it.鈥
For a deep dive into the threat posed by ransomware, check out this webinar from a recent edition of the Virtual Security Academy from Duke鈥檚 IT Security Office.
Send story ideas, shout-outs and photographs through or write working@duke.edu.