Skip to content
English
  • There are no suggestions because the search field is empty.

What is SysCloud's Ransomware Protection Add-on?

SysCloud's Ransomware Protection add-on helps organizations detect and recover files that may have been encrypted during a ransomware attack.

The add-on scans backed-up cloud data for suspicious encryption activity, identifies potentially affected files and users, and provides remediation and recovery actions. Administrators can investigate detected files, restrict access to affected content, and restore clean file versions from SysCloud backups.

Ransomware detection  

Ransomware generally infects user devices, such as laptops or desktops, and encrypts the files stored on them. When cloud synchronization applications such as Google Drive, Shared Drives, OneDrive, or SharePoint are used, the encrypted file versions may be synchronized to the cloud and replace the original versions.

SysCloud continuously analyzes backed-up files for encryption patterns and other indicators of possible ransomware activity. Files that SysCloud identifies as potentially encrypted are referred to as encrypted files throughout the Ransomware Protection dashboard and documentation.

Ransomware detection helps administrators:
  • Identify files that may have been encrypted by ransomware.
  • Identify the users and cloud applications affected by the incident.
  • Review the detected files and their available backup versions.
  • Receive alerts and notifications about potential ransomware activity.
  • Investigate the scope and impact of the incident.

Detected files are displayed in the Ransomware Protection section of the SysCloud dashboard, where administrators can review the affected data and perform the required remediation actions.  

Ransomware recovery  

SysCloud allows administrators to recover clean versions of files that were modified, encrypted, or removed during a ransomware incident.

Using the backup snapshots available in SysCloud, administrators can:

  • Restore a clean file version captured before the suspected ransomware activity.
  • Recover files that may have been deleted by ransomware or by a user.
  • Restrict access to affected files while the incident is being investigated.
  • Transfer affected files to an administrator for further review.
  • Remove potentially harmful files from the source cloud application or SysCloud Archives.

            SysCloud can identify a safe snapshot for a detected file based on its analysis. Administrators can use this snapshot to restore the file to a version that existed before the suspected encryption activity.

            Supported applications

            The Ransomware Protection add-on is available for the following applications:

            Google Workspace

            • Google Drive
            • Shared Drives
            • Gmail
            • Google Classroom

            Microsoft 365

            • OneDrive
            • SharePoint
            • Outlook
            • Microsoft Teams sites

            Actions available for detected encrypted files

            The following actions are available for files identified as potentially encrypted.

            1. Transfer ownership

            Use ownership actions to transfer affected files to an administrator for investigation or return them to their original owner.

            • Transfer ownership: Transfers ownership of the selected files to an administrator for further review. Refer to this LINK for the steps.
            • Restore ownership: Restores ownership of the selected files to their original owner when one or more ownership transfers have previously been performed. Refer to this LINK for the steps.
            • Quarantine files: Removes all sharing permissions from the selected files and transfers their ownership to the SysCloud account owner. Refer to this LINK for the steps.

            2. Remove sharing

            Use sharing-removal actions to restrict access to affected files while investigating the incident.

            • Remove all sharing: Revokes all sharing permissions from the selected files. Only the file owner retains access. Refer to this LINK for the steps.
            • Remove link sharing: Revokes access granted through shared links while retaining direct sharing permissions. Refer to this LINK for the steps.
            • Remove external domain sharing: Revokes access granted to users from external domains through direct sharing or link sharing. Refer to this LINK for the steps.

            3. Restore from a safe snapshot

            Restores a clean version of the selected files using the safe snapshot identified by SysCloud. This action can also be used to recover files that may have been removed by ransomware or by a user.

            Refer to this LINK for the steps.

            4. Delete

            Deletes the selected affected files from SysCloud Archives or from the source cloud application.

            Refer to this LINK for the steps.

            5. Dismiss

            Dismisses the ransomware alert when the detected files have been reviewed and determined not to pose a threat.

            Refer to this LINK for the steps.