IT Security5 min read

Cyber Defense Measures Against Hackers

The war between Russia and Ukraine is spilling over into cybersecurity too — here's why businesses need to stay on high alert.

Cyber Defense Measures Against Hackers

In this article

  1. What Are the Cyber Risks During Times of Crisis, and How Can They Be Countered?
  2. Turning the Checklist Into Concrete Actions
  3. Patch Management: The Boring Measure That Matters Most
  4. How Does TN Solutions' Cybersecurity Consulting Work?

Following recent (and tragic) international events, and in particular the ongoing conflict between Russia and Ukraine, Italy's ACN (National Cybersecurity Agency) and CSIRT (Computer Security Incident Response Team) issued a notice urging organizations to keep the highest level of attention on cybersecurity.

In their own words, the agencies "strongly renew the recommendation to adopt heightened cyber defense measures and maximum internal controls for the protection of digital infrastructure."

In the days before the notice, CSIRT had published a bulletin about the discovery of HermeticWiper, a new malware with potentially devastating capabilities that could also be used outside the immediate conflict zone.

"A 'wiper'-type malware — named HermeticWiper (alias KillDisk.NCV) — has reportedly been distributed. Its distinguishing feature is that it intentionally destroys the data on a device, making it unrecoverable and undermining the correct functioning of the running operating system."

Researchers have also flagged recent malicious activity on well-known instant messaging platforms, "aimed at distributing links to resources containing malicious files."

What Are the Cyber Risks During Times of Crisis, and How Can They Be Countered?

It has happened before that, during periods of war or socio-political tension, malicious software is developed specifically to exploit newly created vulnerabilities — and it wouldn't be the first time such viruses spread well beyond the countries directly involved in a conflict.

For this reason, the situation should not be underestimated. At the company level in particular, it pays to be as thorough as possible about cybersecurity, in order to avoid the risk of data loss or theft and to prevent other equally damaging incidents.

  • In-depth network analysis

  • Firewall updates

  • Constant antivirus scanning

  • Increased monitoring and logging activity

  • Frequent backups

  • Connection verification

  • Account and access control checks

  • Traffic monitoring…

…these are just some of the precautions to take to protect against possible hacker attacks and to avoid running into similar problems.

Turning the Checklist Into Concrete Actions

The recommendations above are easy to list and easy to skip in practice, so here's what each one actually means to implement:

  • In-depth network analysis means checking what's reachable from the outside: is RDP exposed directly to the internet (a very common and very risky configuration), are firewall rules broader than they need to be, is there a VPN with multi-factor authentication for remote access instead of a bare port forward.
  • Firewall updates cover both the firmware of the appliance itself and its rule set — an outdated firewall OS can carry known, published vulnerabilities that are trivial to exploit once public.
  • Frequent backups, in the context of wiper-type malware specifically, only help if at least one backup copy is offline or immutable: a wiper that has compromised a network can and often does seek out and destroy any backup it can reach over the network, which is exactly why the classic 3-2-1 rule (three copies, two different media, one offsite and disconnected) still matters more than the backup frequency itself.
  • Account and access control checks means reviewing who still has administrative rights that they no longer need, and making sure multi-factor authentication is enabled on anything exposed to the internet — email, VPN, remote access tools — since credential theft remains one of the most common ways attackers get an initial foothold, regardless of the malware eventually deployed.

None of this is specific to any one geopolitical event — it's the same baseline hygiene that reduces exposure to ransomware and destructive malware generally, which is why it's worth implementing as standing practice rather than a temporary response to a single alert.

Patch Management: The Boring Measure That Matters Most

Of everything on the checklist, patch management is the least dramatic and the most consistently underestimated. Wiper malware and ransomware alike routinely spread through vulnerabilities that already have a published fix available — the gap that gets exploited isn't a lack of a patch, it's the delay between the patch being released and it actually being applied. A defined patching cadence (critical vulnerabilities applied promptly after testing, routine updates on a fixed weekly or monthly schedule rather than "whenever there's time") closes that gap far more reliably than any single piece of security software, because it removes the vulnerability itself rather than trying to detect an attack that exploits it.

How Does TN Solutions' Cybersecurity Consulting Work?

The measures described above are only some of the IT security measures we use to protect our clients' networks and systems.

For more information on this topic, or for IT consulting, TN Solutions' technicians are always available — fill in the form below to speak with one of our IT consultants.

Related Cybersecurity Articles

If you want to learn more, here is a list of resources that might be useful to you:

Frequently asked questions

What is HermeticWiper?

It is a "wiper"-type malware with potentially devastating capabilities that intentionally destroys the data on a device, making it unrecoverable and compromising the operating system's normal functioning.

What countermeasures are recommended to stay protected during periods of geopolitical tension?

In-depth network analysis, firewall updates, constant antivirus scanning, monitoring and logging, frequent backups, connection verification, and account and access control checks.

Why did ACN and CSIRT issue a cybersecurity alert?

Following the conflict between Russia and Ukraine, to urge businesses and individuals to adopt heightened cyber defense measures and maximum internal controls, given the possibility that malware could spread beyond the countries directly involved in the conflict.

Technology partners

Want to discuss it with our team?

We analyse your infrastructure for free and propose the most suitable solution.

Discover moreRequest a quote

We use cookies

We use technical cookies required for the site to work and, only with your consent, analytics and marketing cookies. You can accept, refuse or choose category by category. If you continue browsing to another page without choosing, cookies are considered accepted. Cookie Policy