Question 1 Report
Read the information below about a dental practice. The practice receives an email stating that its appointment server has been encrypted by ransomware. The message demands cryptocurrency and warns that copied patient information will be published. The practice has three days before a busy holiday period. Its computers contain medical notes, x-ray images and contact data. Managers need an incident response that protects patients and allows safe recovery.
(a) Give three immediate actions the practice should take after identifying ransomware. [3]
(b) Describe three ways ransomware may have entered the practice network. [3]
(c) Explain four measures that would reduce the likelihood or effect of a future ransomware attack. [4]
(d) Discuss whether the practice should pay the ransom. Give three relevant points. [3]
(a) Immediately disconnect affected computers from the network and internet to limit spread. Report the incident to IT or security management, preserve evidence and logs, identify affected systems, and begin the incident-response procedure. [3]
(b) Ransomware may enter through a malicious email attachment, a phishing link that downloads malware, or an unpatched operating system or software vulnerability. Other routes include a compromised remote-access password or infected USB device. [3]
(c) Keep offline or immutable tested backups so recovery is possible without relying on criminals. Apply security patches, train staff to recognise phishing, and use anti-malware or endpoint protection. Least-privilege permissions, multi-factor authentication and network segmentation further reduce spread and access. [4]
(d) Paying does not guarantee a decryption key or that copied patient information will be deleted. Payment may encourage further criminal attacks. Recovery from tested backups may be safer, while legal, regulatory and reputational consequences must be considered. The practice should seek specialist police and cyber-security advice. [3]
Everything you need to excel in your exams