Understanding the Kaseya Ransomware Supply Chain Attack
A major attack this month targeted IT management software used to support businesses like yours.
This month's attack on Kaseya, a widely used IT management platform, is a stark reminder of "supply chain" risk — attackers compromised software used by IT providers to manage their clients' systems, spreading ransomware downstream to potentially thousands of businesses through a tool that was supposed to help protect them.
For a small business, the direct lesson is less about this specific software and more about a broader principle: ask your IT provider how they secure the tools they use to manage your systems, including whether those tools require MFA and are kept patched as a priority.
If you were ever notified by your provider about exposure related to this incident, follow their remediation guidance directly — password resets, patching, or monitoring — rather than assuming no news is good news.
Related Articles
May 10, 2014
What to Do About the Heartbleed Bug
A plain-English explanation of the Heartbleed OpenSSL vulnerability and the steps small businesses should take.
March 12, 2015
Protecting Your Business From CryptoLocker-Style Ransomware
Ransomware that encrypts your files and demands payment is on the rise. Here's how to reduce your risk.
December 6, 2016
What Is Ransomware and How Locky Spread So Fast
A look at how one of this year's most widespread ransomware campaigns tricked so many businesses.
Prefer to have this handled for you?
Our team can take care of this and everything else on your IT plate — no obligation to find out how.