Firewall Best Practices to Block Ransomware

Today, getting pwned is the rule, rather than the exception. Organisations that have managed to avoid breach or cyberattack are few and far between, with no industry or individual immune. According to Malaysia Computer Emergency Response Team (MyCERT), there have been more than 4,400 incidents reported in Malaysia till June 2019.

Cyberattacks, while not inevitable, are highly probable. The reason behind this is because companies can’t see what’s happening on their endpoint devices, leaving them struggling to prevent attacks or even knowing how and when they happened.

At the same time, the threat landscape is constantly evolving, and attackers are getting smarter, meaning organisations are spending longer securing their networks and their data. On average, organisations spend four days a month investigating potential security issues, and roughly 10 hours to detect significant threats. With the most common threats continuing to include ransomware, time literally means money. It’s therefore critical that organisations take a proactive approach to cybersecurity – from deploying the right tools and skills, to having support from management to invest and train staff.

When looking specifically at ransomware, a good place to start is a powerful anti-ransomware tool, while also making use of best practices in general to stay safe.

Six Firewall Best Practices to Block Ransomware

1. Ensure the right protection is in place. From high-performance next-gen firewall IPS engine to sandboxing, to encryption and backup, organisations need to put the right tools in place to take a proactive approach to cybersecurity.

2. Reduce the surface area of attacks. Review all port-forwarding rules to eliminate any non-essential open ports. Every open port represents a potential opening in the network. Where possible, use VPN to access resources on the internal network from outside rather than port-forwarding. In addition, make sure open ports are secured by applying suitable IPS protection to the rules governing that traffic.

3. Apply sandboxing to web and email traffic to ensure all suspicious active files coming in through web downloads and as email attachments, are being suitably analysed for malicious behaviour before they get onto the network. As part of this, disable macros in document attachments received via email, which will stop a huge number of infections in their tracks.

4. Minimise the risk of lateral movement within the network by segmenting LANs into smaller, isolated zones or VLANs that are secured and connected together by the firewall. Be sure to apply suitable IPS policies to rules governing the traffic traversing these LAN segments to prevent exploits, worms, and bots from spreading between LAN segments. In addition, don’t enable more login power than the user needs, this will reduce risk immediately.

5. Automatically isolate infected systems. When an organisation encounters a cyber attack, it’s important that its IT security solution is able to quickly identify compromised systems and automatically isolate them until they can be cleaned up (either automatically or through manual intervention).

6. Stay up to date. Malware that doesn’t come in via a document often relies on security bugs in popular applications, including Microsoft Office, internet browsers, Flash, and more. If an organisation stays up to date on patching, it’ll be far less vulnerable to potential exploits.

This article was contributed by Aaron Bugal, Global Solutions Engineer at Sophos

VPN Services We Recommend

NordVPN Logo min

NordVPN offers industry-leading encryption along with a massive suite of secure servers that span the globe. They are priced extremely competitively and have their service independently audited.

ExpressVPN Logo

ExpressVPN is another highly respected name on the VPN scene and also has their services audited. Their price may be a bit on the high side buy connectivity and compatibility are unsurpassed.


Surfshark is a newer player and has been focused on expanding operations. So far, services have been good and their unlimited connections make them an excellent choice for small businesses.

Frequently Asked Questions

What is Ransomware?

Ransomware is malware that attempts to lock your data and hold for a ransom payment. These threats do not only target businesses, but personal computers are also at risk.

How to prevent Ransomware?

Always use a reputable Internet security program coupled with a VPN connection. Be aware of the sites you visit online, as well as what files you download.

How to Remove Ransomware?

Many sources (including the FBI) confirm that it is not advisable to pay the Ransom. Ransomware can't always be removed but you should; isolate the affected device, try to identify the ransomware, and attempt to use a file decryptor to try and recover your files.

How is Ransomware spread?

Spam and Phishing are the most common ways Ransomware is spread. Users are enticed to click on links or download files, and along comes the Ransomware.

How does Ransomware work?

Once the Ransomware is downloaded to your device, it starts encrypting your files. When the process is complete, you're blocked from accessing your data and shown a message demanding payment in exchange for the release of your files. Typical ransom demands are around $500.

Aaron Bugal

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.