New Ricoh Solution Detects, Contains Ransomware Attacks

Ricoh USA today announced RansomCare, its new Ransomware Containment Solution that’s said to help to stop ransomware attacks, which it says is one of the top security threats to businesses in the U.S. and around the world.

According to Ricoh, RansomCare’s multi-layered security detects, identifies, contains, and isolates ransomware outbreaks at the source, limiting their impact on data integrity, system downtime, company-wide productivity and overall operations.

Capable of infecting up to 10,000 files per minute per infected device, ransomware is a form of malicious software, or malware, that encrypts files and documents, and holds computers and data files hostage, drastically affecting downtime, contributing to data loss, locking down entire networks, and bringing business to a halt.

With RansomCare, however, Artificial Intelligence (AI) and Machine Learning use heuristic analysis and file metadata to identify the tell-tale sign of ransomware — illegitimate file encryption. Upon discovery, the system generates an alert via email or app, and shuts down the endpoint to limit the outbreak. Reporting of infected files reduces downtime and time to recovery.

RansomCare:

  • Detects unauthorized changes in file activity.
  • Responds by immediately isolating the source.
  • Provides detailed reporting.

RansomCare is an agent-less, cloud-based solution, that Ricoh says can be deployed in days with minimal demand on IT resources. No agent also means customers don’t have to worry about network or device performance issues. Monitoring configures automatically, leaving customers only having to define alert settings. Benefits include:

  • No file server, storage platform, cloud, or endpoint installation required.
  • No write access to storage platforms.
  • No network overhead.
  • Integration with Microsoft SharePoint and Office 365, as well as many cloud services.
  • Operating system–agnostic for monitoring devices and network environments.
  • Integration with Cisco ISE, Windows Defender ATP, and other security solutions.

RansomCare’s advanced tools for data protection, including:

  • Active file monitoring to detect known and unknown ransomware variants and immediately alert security administrators of threats;
  • Quick response to infected devices to halt illegitimate encryption, preventing mass spreading to files and reducing risk of expensive recovery efforts;
  • Informed recovery of impacted files, simplifying backup restoration and logging attack details for additional insight;
  • Detailed reporting, including exact time of attack, compromised users and devices, affected files and owners, and easily exported incident reporting.

Ricoh’s RansomCare, powered by Bullwall, monitors networks in near real time using multiple detection tactics to instantly detect the tell-tale signs that ransomware is at work. RansomCare responds by isolating and quarantining the compromised user and quickly identifying encrypted files to restore them from backup while automating any necessary incident reporting.

Visit Ricoh here for more information.