Reply to post:

First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn't get the memo

Twanky

Not off-site (though that is a good idea too), but off-line backups. In the reported case the bad guys were able to spin up a VM in CWT's systems which means (should mean) highly privileged access. If CWT had off-line backups then perhaps the same privilege was used to bring them on-line and damage/delete them?

The above is speculation of course, but if bad guys have had highly privileged access to your systems then you can never be sure they really are your systems any more.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon