Search

WhatsApp

Click To Chat

Serangan Ransomware Semakin Menggila, Ini yang Harus Dilakukan Lembaga Keuangan

Serangan Ransomware di Lembaga Keuangan

Serangan ransomware telah menjadi ancaman nyata bagi industri keuangan. Serangan ini dapat menyebabkan kerugian finansial yang signifikan dan merusak reputasi. 

Berdasarkan data Checkpoint Research 2022, sektor keuangan menjadi target utama serangan siber dengan 1.131 kali kasus setiap pekannya. Kerugian dari serangan siber di sektor keuangan menurut International Monetary Fund (IMF) pada 2020 secara global diperkirakan sebesar USD$100 miliar atau lebih dari Rp 1.433 triliun. 

Oleh karena itu, pencegahan serangan ransomware menjadi semakin penting dilakukan lembaga terkait. Seperti apa tindakan pencegahan yang dapat dilakukan oleh lembaga keuangan dan solusi tepat untuk menangkis serangan ransomware? Simak penjelasan lengkapnya di artikel ini.  

Fenomena Serangan Ransomware di Industri Keuangan

fenomena serangan ransomware di industri keuangan

Meningkatnya kegiatan perekonomian dan keuangan digital tidak hanya berdampak positif bagi industri keuangan, tetapi juga membawa ancaman keamanan siber. Berdasarkan data Badan Siber dan Sandi Negara (BSSN), serangan siber terbesar di 2020 terjadi di sektor keuangan. Adapun data Kominfo menyebutkan, selama 2021 tercatat 888.711.736 ancaman siber di Indonesia atau setara dengan 42 ancaman siber per detiknya.  

Serangan siber yang paling banyak ditemukan seperti malware, DDoS, trojan, dan ransomware. Terdapat satu kasus serangan ransomware yang sempat menghebohkan di awal 2023 yang dialami salah satu bank. Insiden ini didalangi oleh hacker yang menyerang sistem bank dengan ransomware LockBit 3.0.  

Diketahui, sekitar 1,5 TB data dari 9 database yang berisi 15 juta data nasabah dan karyawan diklaim berhasil dicuri. Data tersebut meliputi data pribadi, transaksi, dokumen finansial, hingga password semua layanan internal dan eksternal.   

Ancaman serangan ransomware ini tentunya perlu dimitigasi guna meminimalisir risiko kejahatan dan kerugian yang lebih besar. Selain itu juga diperlukan analisis mendalam untuk mengetahui sumber utamanya demi meningkatkan asek cybersecurity. 

sistem operasi yang paling sering diserang ransomware

Sumber: Gorila Guide 

Salah satunya terlihat dari hasil presentase di atas. Diketahui di 2020, 91 persen ransomware menargetkan serangan pada Windows, diikuti MacOS, Android, dan iOS. Hal ini menunjukkan tidak ada OS atau hypervisor yang aman. Bahkan, di 2022, varian ransomware Cheerscrypt” dan “Black Basta” menargetkan Virtual Machine untuk menyerang host Linux. 

Tantangan Menangani Serangan Ransomware di Industri Keuangan

tantangan menangani serangan ransomware di industri keuangan

Ada beberapa alasan yang membuat industri perbankan jadi sasaran empuk serangan siber. Pertama, masalah yang dialami oleh industri perbankan bisa berdampak besar ke industri lain. Perusahaan atau lembaga yang menyimpan uang di bank tersebut akan mengalami gangguan operasional dan tidak bisa mengakses rekening mereka. 

Kedua, hacker dengan motif untuk mendapatkan uang akan menyasar industri perbankan. Pasalnya, mereka bisa meminta tebusan dalam jumlah besar karena bank menyimpan banyak informasi sensitif nasabahnya.  

Lantas, untuk mengatasi serangan ransomware, diperlukan solusi keamanan data dan mekanisme recovery dengan analisis situasi dan ancaman secara real-time. Hal ini karena ransomware memiliki kesamaan pola, sehingga deteksi secara real-time tidak hanya untuk deteksi, tetapi juga situasi mencurigakan yang secara tidak langsung mengindikasikan aktivitas ransomware. 

 Selain itu, data harus dilindungi secara terus menerus dan sepanjang waktu. Continuous Data Protection (CDP) sangat diperlukan untuk menjaga kemanan data dengan cara menyalin atau mereplika setiap perubahan pada data. 

Maka demikian, sudah saatnya perusahaan mulai menggunakan solusi keamanan siber berbasis platform yang mampu menghentikan ancaman teridentifikasi ransomware pada seluruh vektor serangan. HPE Zerto bisa menjadi solusi untuk mengatasi hal itu. Solusi ini menghadirkan ketahanan terhadap ransomware, Disaster Recovery, dan mobilitas cloud yang hemat biaya untuk melindungi bisnis. 

Solusi HPE Zerto, Senjata Hadapi Serangan Ransomware

HPE Zerto adalah solusi Disaster Recovery-as-a-Service (DRaaS) yang dikembangkan oleh Hewlett Packard Enterprise (HPE). Solusi ini dirancang untuk membantu perusahan menjaga kelangsungan bisnis dengan menyediakan recovery cepat dan efisien saat terdampak bencana atau kerusakan data.  

HPE Zerto menggunakan teknologi replikasi data canggih untuk membuat salinan data dan aplikasi penting perusahaan. Dengan cara ini, jika terjadi kegagalan hardware, serangan siber, atau bencana alam, perusahaan dapat dengan cepat mengaktifkan salinan data dan aplikasi yang terisolasi untuk kembali melanjutkan operasi bisnis.  

HPE Zerto merupakan salah satu solusi yang populer untuk manajemen Disaster Recovery dan replikasi data dengan dua fitur utama sebagai berikut. 

Continuous Data Protection dan Journal Based Replication

Continuous Data Protection (CDP) adalah teknologi yang memungkinkan replikasi data secara real-time dan berkelanjutan untuk melindungi data dan aplikasi. Fitur ini mencegah kehilangan data yang signifikan saat proses recovery, karena semua perubahan data langsung  direplikasi. 

Sementara itu, Journal-Based Replication adalah fitur yang memanfaatkan jurnal (journal) untuk merekam semua perubahan pada data dan aplikasi. Dengan fitur ini, HPE Zerto dapat mereplikasi data dengan presisi tinggi dan memulihkan data ke titik waktu yang spesifik. 

Real Time Ransomware Detection and Recovery

Dirancang untuk deteksi serangan ransomware secara real-time dan menyediakan mekanisme recovery cepat dan efektif. Fitur ini bekerja memantau aktivitas data secara terus-menerus dan menganalisis pola perilaku mencurigakan dengan memberikan notifikasi serta tindakan pecegahan untuk melindungi data.  

Selain itu, fitur ini juga menyediakan mekanisme recovery yang cepat dan terkendali pasca serangan ransomware. Dengan melakukan replikasi data, HPE Zerto dapat memulihkan data yang terinfeksi atau rusak ke keadaan sebelumnya. 

Dengan kedua fitur tersebut, pengguna HPE Zerto dapat memiliki perlindungan tambahan terhadap serangan ransomware. Pengguna juga dapat memiliki visibilitas lengkap dan kontrol terhadap perubahan data, hingga fleksibilitas untuk memulihkan data ke titik waktu yang diinginkan dengan presisi tinggi. 

Baca Juga: Continuous Data Protection, Solusi Ampuh Lindungi Data Finansial 

Keuntungan HPE Zerto

Melalui dua fitur di atas, HPE Zerto memungkinkan Anda mendapatkan fleksibilitas untuk menjalankan infrastruktur IT Perusahaan dengan recovery data cepat, efisien, dan andal. Berikut enam keuntungan menggunakan HPE Zerto. 

1. Kurangi Gangguan

Lindungi bisnis dari kerusakan dan gangguan dengan batasi data loss dan downtime secara cepat. 

2. Perlindungan dari Ransomware

Deteksi ancaman dan recovery data dalam hitungan menit. 

3. Modernisasi Infrastruktur

Hilangkan kompleksitas untuk tingkatkan infrastruktur bisnis dengan teknologi baru. 

4. Hybrid dan Multi-cloud

Dorong transformasi digital dengan perlindungan lintas platform untuk IaaS, PaaS, dan SaaS.

5. Migrasi Disederhanakan

Kurangi penggunaan resource dan percepat konsolidasi data dengan migrasi cross-cloud tanpa ribet. 

6. Tingkatkan Operasional

Otomatisasi, orchestration, dan kemudahaan penggunaan untuk permudah operasional IT. 

Implementasikan Solusi HPE Zerto Bersama Helios

Saatnya gunakan solusi HPE Zerto untuk mendeteksi, merespons, dan mengurangi insiden serangan ransomware di lembaga keuangan secara efektif. Helios Informatika Nusantara (HIN) sebagai partner resmi HPE Zerto akan membantu Anda mengimplementasikan HPE Zerto untuk memastikan bisnis Anda terhindari dari trial and error saat sebelum, hingga sesudah proses deployment. Jika Anda tertarik menggunakan solusi HPE Zerto, klik di sini.

Penulis: Wilsa Azmalia Putri 

Content Writer CTI Group 

 

Share this article

Table of Contents

Start a Conversation
Start a Conversation

TERMS & CONDITIONS

Welcome to Helios Informatika Nusantara!

These terms and conditions outline the rules and regulations for the use of Helios Informatika Nusantara’s Website, located at https://www.helios.id/.

By accessing this website we assume you accept these terms and conditions. Do not continue to use Helios Informatika Nusantara if you do not agree to take all of the terms and conditions stated on this page.

The following terminology applies to these Terms and Conditions, Privacy Statement and Disclaimer Notice and all Agreements: “Client”, “You” and “Your” refers to you, the person log on this website and compliant to the Company’s terms and conditions. “The Company”, “Ourselves”, “We”, “Our” and “Us”, refers to our Company. “Party”, “Parties”, or “Us”, refers to both the Client and ourselves. All terms refer to the offer, acceptance and consideration of payment necessary to undertake the process of our assistance to the Client in the most appropriate manner for the express purpose of meeting the Client’s needs in respect of provision of the Company’s stated services, in accordance with and subject to, prevailing law of id. Any use of the above terminology or other words in the singular, plural, capitalization and/or he/she or they, are taken as interchangeable and therefore as referring to same.

 

Cookies

We employ the use of cookies. By accessing Helios Informatika Nusantara, you agreed to use cookies in agreement with the Helios Informatika Nusantara’s Privacy Policy.

Most interactive websites use cookies to let us retrieve the user’s details for each visit. Cookies are used by our website to enable the functionality of certain areas to make it easier for people visiting our website. Some of our affiliate/advertising partners may also use cookies.

 

License

Unless otherwise stated, Helios Informatika Nusantara and/or its licensors own the intellectual property rights for all material on Helios Informatika Nusantara. All intellectual property rights are reserved. You may access this from Helios Informatika Nusantara for your own personal use subjected to restrictions set in these terms and conditions.

You must not:

  • Republish material from Helios Informatika Nusantara
  • Sell, rent or sub-license material from Helios Informatika Nusantara
  • Reproduce, duplicate or copy material from Helios Informatika Nusantara
  • Redistribute content from Helios Informatika Nusantara

This Agreement shall begin on the date hereof. Our Terms and Conditions were created with the help of the Terms and Conditions Generator.

Parts of this website offer an opportunity for users to post and exchange opinions and information in certain areas of the website. Helios Informatika Nusantara does not filter, edit, publish or review Comments prior to their presence on the website. Comments do not reflect the views and opinions of Helios Informatika Nusantara,its agents and/or affiliates. Comments reflect the views and opinions of the person who post their views and opinions. To the extent permitted by applicable laws, Helios Informatika Nusantara shall not be liable for the Comments or for any liability, damages or expenses caused and/or suffered as a result of any use of and/or posting of and/or appearance of the Comments on this website.

Helios Informatika Nusantara reserves the right to monitor all Comments and to remove any Comments which can be considered inappropriate, offensive or causes breach of these Terms and Conditions.

You warrant and represent that:

  • You are entitled to post the Comments on our website and have all necessary licenses and consents to do so;
  • The Comments do not invade any intellectual property right, including without limitation copyright, patent or trademark of any third party;
  • The Comments do not contain any defamatory, libelous, offensive, indecent or otherwise unlawful material which is an invasion of privacy
  • The Comments will not be used to solicit or promote business or custom or present commercial activities or unlawful activity.

You hereby grant Helios Informatika Nusantara a non-exclusive license to use, reproduce, edit and authorize others to use, reproduce and edit any of your Comments in any and all forms, formats or media.

 

Hyperlinking to our Content

The following organizations may link to our Website without prior written approval:

  • Government agencies;
  • Search engines;
  • News organizations;
  • Online directory distributors may link to our Website in the same manner as they hyperlink to the Websites of other listed businesses; and
  • System wide Accredited Businesses except soliciting non-profit organizations, charity shopping malls, and charity fundraising groups which may not hyperlink to our Web site.

These organizations may link to our home page, to publications or to other Website information so long as the link: (a) is not in any way deceptive; (b) does not falsely imply sponsorship, endorsement or approval of the linking party and its products and/or services; and (c) fits within the context of the linking party’s site.

We may consider and approve other link requests from the following types of organizations:

  • commonly-known consumer and/or business information sources;
  • dot.com community sites;
  • associations or other groups representing charities;
  • online directory distributors;
  • internet portals;
  • accounting, law and consulting firms; and
  • educational institutions and trade associations.

We will approve link requests from these organizations if we decide that: (a) the link would not make us look unfavorably to ourselves or to our accredited businesses; (b) the organization does not have any negative records with us; (c) the benefit to us from the visibility of the hyperlink compensates the absence of Helios Informatika Nusantara; and (d) the link is in the context of general resource information.

These organizations may link to our home page so long as the link: (a) is not in any way deceptive; (b) does not falsely imply sponsorship, endorsement or approval of the linking party and its products or services; and (c) fits within the context of the linking party’s site.

If you are one of the organizations listed in paragraph 2 above and are interested in linking to our website, you must inform us by sending an e-mail to Helios Informatika Nusantara. Please include your name, your organization name, contact information as well as the URL of your site, a list of any URLs from which you intend to link to our Website, and a list of the URLs on our site to which you would like to link. Wait 2-3 weeks for a response.

Approved organizations may hyperlink to our Website as follows:

  • By use of our corporate name; or
  • By use of the uniform resource locator being linked to; or
  • By use of any other description of our Website being linked to that makes sense within the context and format of content on the linking party’s site.

No use of Helios Informatika Nusantara’s logo or other artwork will be allowed for linking absent a trademark license agreement.

 

iFrames

Without prior approval and written permission, you may not create frames around our Webpages that alter in any way the visual presentation or appearance of our Website.

 

Content Liability

We shall not be hold responsible for any content that appears on your Website. You agree to protect and defend us against all claims that is rising on your Website. No link(s) should appear on any Website that may be interpreted as libelous, obscene or criminal, or which infringes, otherwise violates, or advocates the infringement or other violation of, any third party rights.

 

Reservation of Rights

We reserve the right to request that you remove all links or any particular link to our Website. You approve to immediately remove all links to our Website upon request. We also reserve the right to amen these terms and conditions and it’s linking policy at any time. By continuously linking to our Website, you agree to be bound to and follow these linking terms and conditions.

 

Removal of links from our website

If you find any link on our Website that is offensive for any reason, you are free to contact and inform us any moment. We will consider requests to remove links but we are not obligated to or so or to respond to you directly.

We do not ensure that the information on this website is correct, we do not warrant its completeness or accuracy; nor do we promise to ensure that the website remains available or that the material on the website is kept up to date.

 

Disclaimer

To the maximum extent permitted by applicable law, we exclude all representations, warranties and conditions relating to our website and the use of this website. Nothing in this disclaimer will:

  • limit or exclude our or your liability for death or personal injury;
  • limit or exclude our or your liability for fraud or fraudulent misrepresentation;
  • limit any of our or your liabilities in any way that is not permitted under applicable law; or
  • exclude any of our or your liabilities that may not be excluded under applicable law.

The limitations and prohibitions of liability set in this Section and elsewhere in this disclaimer: (a) are subject to the preceding paragraph; and (b) govern all liabilities arising under the disclaimer, including liabilities arising in contract, in tort and for breach of statutory duty.

As long as the website and the information and services on the website are provided free of charge, we will not be liable for any loss or damage of any nature.

PRIVACY POLICY

At PT Helios Informatika Nusantara, ensuring the privacy and security of your information is of utmost importance to us. As you navigate through our website, https://www.helios.id/, collectively referred to as this “Website”, we strive to create a safe and trustworthy environment for all users. This Privacy Policy establishes the terms governing your use of our website between you (“you” or “your”) and [Helios Informatika Nusantara]. By accessing our website, you acknowledge that you have reviewed, understood, and consent to be bound by this Privacy Policy.

Information We Collect

When utilizing or engaging with our Website, we may gather or receive various types of information, collectively referred to as “Information”, including but not limited to:
  1. “Personal Information,” such as your name, email, contact details, or any other personal content provided to us via forms on our website or other means of communication (e.g., email, phone, mail, etc.).
  2. “Technical Information,” such as browser type, operating system, device type, IP address, and similar technical data typically obtained automatically from browsers or devices when interacting with our Website. This may also encompass the referring URL that directed you to our website.
  3. “Usage Information,” such as the pages visited on our website, click activity, searches conducted, and other related data on how you have utilized our website. This category may also encompass details regarding your interaction with emails, including whether you opened, clicked on links, or received them.
We acknowledge that certain Technical Information or Usage Information may be considered personal data, either independently or when combined with other data, under various laws and jurisdictions. We are committed in handling such data in accordance with applicable laws and regulations.

The Methods We Use to Collect and Receive Information

Depending on the type of Information, we collect or receive it through various channelsincluding but not limited to the following conditions:
  1. When you voluntarily share Information with us. For instance, when you subscribe to our newsletter or fill out our online form to request contact.
  2. By using cookies and similar technologies. These technologies help us analyze how our Website is utilized and tailor content that is pertinent to you. They also assist in delivering more relevant advertisements on our own or third-party sites.
  3. Information obtained from third-party sources. This encompasses Information acquired through various business support tools and services we utilize, such as Website, analytics services, etc., as well as public sources like social media sites. We may merge the Information from these sources with other data we possess to maintain updated records and provide you with pertinent content.

The Purposes

We utilize Information for the following purposes:
  1. Processing your inquiries and responding to your requests, such as when you reach out to learn more about our products or services.
  2. Sending you information related to our services and products that we believe may be of interest to you, such as an invitation to our upcoming events, follow-up by WhatsApp blast and/or call, newsletters, or updates on products and services. These communications are sent to you either based on your explicit consent or when we have a legitimate interest in marketing our products and services. You always have the option to optout of receiving invitation, newsletters, and/or updates on products and services.
  3. Understanding how you interact with our Website and tailoring it to align with your interests, past actions, and preferences. We do this to enhance our Website, diagnose any issues, and improve your experience while navigating through them.
  4. Preventing fraud or harm to us or any third party, and ensuring the security of our network and services, which is in our legitimate interest.
  5. Complying with our legal obligations and exercising and enforcing our legal rights as necessary for PT Helios Informatika Nusantara.
  6. Utilizing certain third-party marketing and advertising networks to assist in marketing our products on our website and third-party Website.

Who We Share Information With

To facilitate our business operations and the functioning of our Website, we may disclose Information to various third parties, including:
  1. Our global branches and subsidiary companies.
  2. Third-party service providers aiding in the operation of our Website, such as hosting companies, recruitment platforms and agencies, payment processors, business management,and email distribution service providers, and similar service providers. These entities are authorized to use your personal information solely to provide these services to us.
  3. When compelled by law, such as to comply with court orders, search warrants, regulatory orders, subpoenas, and other lawful requests from public authorities, including those for national security or law enforcement purposes.
  4. Legal authorities, consultants, advisors, or service providers required to investigate, respond to, or prevent fraud, or to ensure the security of our network and services and safeguard the well-being of PT Helios Informatika Nusantara or the public.
  5. In the event of a merger and/or acquisition involving PT Helios Informatika Nusantara, Information may be transferred to the merging or acquiring entity, as well as to any advisors representing parties involved in discussions related to such merger or acquisition.
  6. Principal, resellers, partners, sponsors, or service providers acting on our behalf in conjunction with the offering of PT Helios Informatika Nusantara]’s products or services.
  7. Third-party marketing and advertising networks assisting in the promotion of our products on our Website and on third-party websites, such as Google for remarketing ads across the Internet.
  8. PT Helios Informatika Nusantara may also disclose general aggregate and anonymized information (e.g., statistical data) pertaining to the use of its Website.

Cross Border Data Transfers

  1. We may need to transfer Information to countries where we and/or our service providers operate. These countries may have different data protection laws compared to the country where the data originated, potentially offering different levels of protection. By using our Website, you consent to such transfers. In cases where applicable to the services provided, we will establish agreements with our service providers to ensure a level of privacy consistent with the terms of this policy.
  2. Regarding the collection, use, and retention of personal information transferred from Indonesia, please note that PT Helios Informatika Nusantara remains compliant with all relevant laws concerning such transfers.

Protecting Your Information

We aim to uphold top-tier security standards throughout our business operations. We have adopted suitable technical and organizational safeguards aligned with industry best practices. These safeguards are devised to prevent unauthorized access or unlawful handling of Personal Information and to mitigate the risk of accidental loss, destruction, or damage of such information. As part of these efforts, we have instituted several policies and procedures to guide us, covering aspects such as asset management, access control, physical security, personnel security, product security, cloud and network infrastructure security, third-party security, vulnerability management, security monitoring, and incident response.

Information Storage and Retention

We may store Information on both our own servers and those managed by third-party data hosting providers. As explained in Section 5 above (Cross Border Transfers), these servers may be situated globally. We will retain your Personal Information only for as long as necessary to fulfill the collection’s intended purpose. Additionally, we may retain your Personal Information for the duration required to pursue our legitimate business interests, address any legal claims, and ensure compliance with legal obligations. In instances where we utilize your information for direct marketing, we will retain your data until you choose to opt-out of receiving marketing materials; however, certain information may need to be retained to maintain a record of your request.

Modifications to This Policy

PT Helios Informatika Nusantara reserves the right to amend this Privacy Policy at any time. In the event of a significant change, we will provide notice on this page and/or adjacent to the link leading to this page. These updates will become effective immediately for new Information collected or provided from the date of the update, and within thirty (30) days for any Information collected or provided to PT Helios Informatika Nusantara prior to the update. If you do not agree to the terms of the revised policy, please contact our Legal Department using the contact details provided in Section 11 below. We encourage you to periodically review this page for any updates.

Your Choices

We offer you various options regarding the use of Information in relation to: (i) our marketing activities; and (ii) our utilization of cookies and similar technologies for interest-based advertising and website usage analysis
  1. You can choose to discontinue receiving our newsletter or marketing emails by following the unsubscribe instructions included in these emails, adjusting email preferences in your account settings page, or contacting us through https://www.helios.id/You can manage your preferences concerning our use of cookies and similar technologies, which are used to provide targeted interest-based advertisements and analyze your website usage, by referring to our Cookie Policy for guidance.
  2. Moreover, the laws in some jurisdictions may grant you various rights concerning our processing of certain Information. These rights may include:
    • The right to withdraw previously provided consent;
    • The right to access specific information about you that we process;
    • The right to rectify or update any Personal Information;
    • The right to request the erasure of certain Information;
    • The right to temporarily suspend our processing of certain Information;
    • The right to receive Information in a common machine-readable format;
    • The right to object to our processing of Information for direct marketing purposes or when we rely on legitimate interests as the lawful basis for processing your information; and
    • The right to file a complaint with the relevant data protection authority.
We will address your requests promptly. Please note that these rights may be subject to limitations under applicable law. For further information on these rights or to exercise them, please contact [Helios Informatika Nusantara] at: [email protected]

Social Media and Third-Party Services

Our Website may include a blog with a ‘comments’ section and several social media features, such as a ‘share’ button or links to third-party websites and services like Facebook, X, YouTube, LinkedIn, and Instagram. When utilizing these features, certain information may be gathered by these third parties, such as your IP address or the specific page you are visiting on our website. Additionally, these third parties may set cookies to ensure the proper functioning of the features. Any data collected by these third parties is subject to their respective privacy policies. We encourage you to thoroughly review the privacy policies of these third parties.

Contacting Us

If you have any questions or concerns regarding this Website Privacy Policy, the information we collect, PT Helios Informatika Nusantara’s practices, or your interactions with the Website, please feel free to contact us. You can reach us via email at [email protected] or by physical mail addressed to: PT Helios Informatika Nusantara  Centennial Tower, 12th Floor Jl. Jend. Gatot Subroto Kav. 24-25 Jakarta 12930, Indonesia phone: +62 21 8062 22