Sophos Beefs Up Ransomware Capabilities

Sophos announced the availability of CryptoGuard with its Sophos Server Protection products, available via channel partners. With this optimization, Sophos Server Protection now has signatureless detection capabilities to combat ransomware – similar to Sophos Intercept X for endpoints.

Further, Sophos is also expanding its Synchronized Security initiative by adding Sophos Security Heartbeat capabilities to Sophos Central Server Protection Advanced in Sophos Central. As a result, Sophos helps enterprises accelerate their threat discovery, investigation and response times exponentially, the company said.

Home to confidential corporate and employee information, social security numbers and private customer documents, servers are considered the jackpot for cybercriminals. And, the explosion of remote workers and BYOD, has only left them even more vulnerable to ransomware attacks.

While most enterprises typically have some kind of backup strategy in place, recovery from a backup isn’t always easy, and many are still forced to pay hackers to get their data back.

By adding CryptoGuard to server security, Sophos is closing a gap by preventing ransomware attacks that could come in through rogue, guest or remote access users or other weaknesses in a company’s network. For example, if a company allows bring-your-own-laptops on the network, remote access for employees or is victimized by an insider cyber threat, servers become highly susceptible to ransomware. Additionally, network shares on servers are high-value targets as they contain proprietary financials, personally identifiable information and other key data, and should be protected as such.

“Servers are considered the jackpot for cybercriminals, since they can store confidential corporate and employee information, medical records with social security numbers or private customer documents. It would be devastating for organizations to lose this kind of sensitive data to ransomware,” said Dan Schiappa, senior vice president and general manager of Sophos’ Enduser and Network Security Groups. “Most organizations back-up their data, but recovery from a backup is not always easy. Businesses, schools or hospitals do not want the liability, hassle and operational disruption required to restore from a backup. Anti-ransomware technology is a critical layer for the protection and ongoing accessibility of the information that resides on servers. Sophos has optimized its Server Protection products with CryptoGuard, adding another layer of next-gen protection to block this pervasive and highly-damaging cyber threat.”

Meanwhile, by adding Security Heartbeat to servers, an IT administrator can now leverage Sophos XG Firewall to automatically isolate infected servers and endpoints to identify and respond to the source of compromises faster. Sophos Central Server Protection also includes malicious traffic detection, which monitors for traffic to command and control servers and application whitelisting with one-click server lockdown, which secures servers in a safe state and prevents unauthorized applications from running.

Sophos Server Protection products with CryptoGuard capabilities now includes Central Server Protection Advanced on the cloud-based Sophos Central platform and Sophos Server Protection Enterprise, which is managed with a traditional on-premise console.

Dan Russell, chief information officer, Pine Cove Consulting, a Sophos channel partner based in Bozeman, Montana, noted: “Protection for servers is especially critical for our customers who allow remote desktop connections or have weak desktop credentials, which is a known vulnerability for ransomware attacks. Even our customers who have put every safeguard in place could still have an exposed server, due to that one rogue laptop someone connects into the network. Just one click on a tainted email could encrypt every file with ransomware. We’ve seen this happen with a customer, so from a technical standpoint, it’s exciting to have anti-ransomware capabilities at the server level. Sophos also designed its server protection to be ‘lightweight.’ Many of our customers are educational institutions with older computers, so having an anti-ransomware capability that doesn’t impact server performance – no matter how old or new – is a must. The evolution of ransomware is a reality our customers need to deal with right now. We are focused on selling Sophos Central Server Protection Advanced and Sophos Intercept X to guard against ransomware threats.”