Efficient defense against ransomware
iQ.Suite Security for banks

Banks & Finances Sparkasse

Challenge

Sensitive and confidential data is exchanged on a daily basis, especially in the financial sector. In addition, one Sparkasse attaches particular importance to up-to-date and reliable protection of its e-mail communication. The Sparkasse has been a GBS customer since 2000 and relies on the comprehensive protection provided by iQ.Suite in the area of e-mail security. It deploys the iQ.Suite Watchdog (virus and phishing protection), iQ.Suite Wall (spam protection), iQ.Suite Trailer (legally compliant e-mail footer management) and iQ.Suite Clerk (absence management) modules under IBM Domino.

The dramatic increase in ransomware attacks on companies and financial institutions has brought the pressing issue of efficient defense against ransomware into the focus of IT management. The reason for this is that ransomware aims to encrypt data on the victim’s PC so that the user no longer has access to their data. Entire computer networks have even been compromised in this way.

Attackers exploit this situation to extort a ransom for the release of the data. The dangerous malicious code is usually sent as email attachments in phishing emails. Employees are tricked into opening the attachment on the pretence of a trustworthy sender and a legitimate request.

The Sparkasse took part in GBS’s Academy workshop “From phishing to ransomware – how to get ransomware and other threats under control” in order to obtain detailed information about protection against ransomware. Based on this, the IT management decided to implement the GBS solution iQ.Suite Convert and iQ.Suite Smart for the prevention of ransomware. “Despite regular training, we know that a watchful eye and skepticism towards unknown senders alone only help to a very limited extent in dealing with attacks from scammers. That’s why we also opted for the technological solution from GBS against dangerous macros in Office documents,” says the responsible IT Officer at the Sparkasse.

Solution

GBS offers a solution for the secure defense against ransomware with iQ.Suite Convert (conversion of attachments to PDF, for the removal of malicious code and ransomware) and iQ.Suite Smart (time-controlled e-mail dispatch). The deployment, which took just one day, uses Fingerprints to reliably detect Microsoft Office documents that contain macros. Efficient protection against ransomware is ensured by the following scenario at  the Sparkasse:

  • First, incoming emails with potentially suspicious macros in Office documents such as Word, Excel and PowerPoint are detected in combination with iQ.Suite Watchdog.
  • In the next step, these emails are stopped, quarantined and their attachments are converted to PDF format using iQ.Suite Convert.
  • The converted attachment is then delivered to the Sparkasse employees as a PDF file. This ensures that active malicious code no longer poses a threat. The employees receive a notification that, for security reasons, the original e-mail will only be delivered with a delay after a successful virus scan.
  • In the next step, iQ.Suite Watchdog and the anti-virus signatures that have been updated in the meantime are used to rescan the original email attachment. Over a period of 4 hours, the emails are repeatedly scanned for malicious code six to eight times at 30-minute intervals.
  • If the file is ultimately deemed harmless, iQ.Suite Smart is used to deliver the original Microsoft Office email attachment to the recipient. “The implementation process went completely smoothly. We are convinced that we have integrated another important building block into our security strategy with this solution,” says the IT Officer at the Sparkasse.

Benefits

By integrating iQ.Suite Convert and iQ.Suite Smart, the Sparkasse ensures the highest level of security and is comprehensively protected against new types of ransomware threats. The central PDF conversion also prevents files from being changed. In addition, iQ.Suite Convert also supports conversion to the PDF/A format approved for archiving.

Thanks to the centralized, automated control, the employees of the Sparkasse are in no way disturbed in their daily work. This eliminates the need for any training – an important aspect for productive use

With iQ.Suite, the Sparkasse has a solution in place that protects all email communication against cyber attacks. Thanks to the latest security technologies, ransomware is now also reliably detected and effectively blocked. The entire process is fully automated, ensuring smooth operation.

Contact us