Sony Pixel Power calrec Sony

WannaCry Ransomware

22/05/2017

-- WannaCry Ransomware: Could it happen to your Media Production Company?

If you have any centralised data storage or computer resource, like network attached storage (NAS), you should be very concerned indeed about CyberCrime.

You can't have failed to miss the WannaCry Ransomware cyber-attack that has hit 150 countries, 1000's of computers and brought several hospitals in the UK to a halt (cancelled operations being amongst the issues). The temptation reading about the attack is simply to think, I keep my computers up to date so it couldn't happen to me. Or, my critical data is on a NAS device so I don't overly care if a PC gets compromised . Think again.

Cybercrime is on the rise and sooner or later we will all come under attack. Some attacks are generic, like WannaCry, but other attacks are highly targeted. And, whether we are in large companies like Sony Pictures with their well-publicised issues (https://en.wikipedia.org/wiki/Sony_Pictures_hack) or a small company like my own that had emails going from the CEO to the CFO asking for bank transfers to be carried out (they were of course fraudulent) we are all potential targets.

And here is a big issue: Media Production companies are particularly vulnerable because many of them keep all, or a significant portion, of their information assets in very few places. This is especially true where access is via unsecure protocols and procedures.

Take this scenario. Your storage provider was running a great deal for you if you just buy one huge NAS device. Not minding the future, you decided to consolidate the bulk of your information onto that single solution. A hacker compromises a PC with access to the NAS / SAN and that PC happens to have access to a large number of files. It could be a disgruntled employee, or a kid in a bedroom 2,000 miles away, but now the hacker runs an encrypt or destroy app. It doesn't need to take long. A targeted application doesn't need to encrypt every byte - just enough to make the files it touches unreadable. And to therefore lock them. Just for added measure it encrypts the well-known metadata controller of your storage device. And, now it destroys itself. Getting an unencrypt key is nigh-impossible. Hey presto. Your millions of dollars of assets are now under ransom, but for just one of those millions you might get an unlock key. If you are lucky .

I'm sure there are worse scenarios, but if you believe that this type of attack won't happen in the future then you are wrong. Look at Sony. It won't be a one-off. It's already happening now to other media production companies.

But strategies to defeat this type of hack are possible. Firstly, disaster recovery systems, replication, and back-up are key to being able to getting data back if this occurs. But a deep and clever hack attack may target those systems as well. Care must be taken not to backup or replicate the hacked data. Another challenge is that as a large media producer handling potentially Petabytes of data, backing up everything is sometimes , well let's say asynchronous . That is to say a subset of the data might not yet be backed up.

Another strategy is to keep your data behind a firewall. A very strong firewall. And then to only let out copies of data that are for (e.g.,) media editing, checking back in edited versions. This is the strategy promoted by object storage when it sits behind an object storage API.

Speaking to Francisco Ontoso, CTO of Object Matrix who provide MatrixStore an object storage solution for the media industries, he stated:

MatrixStore has been proven in a major real-world hack against a production company to have not only kept data safe during that attack but also to have tracked/audited that the data was safe. There simply wasn't a filesystem interface for the hackers to walk through and the security on the API meant the hackers would have had to have had access to a special set of keys. We call this Digital Content Governance. No system is full-proof but can digital content governance provides extra layers of security.

In your Digital Content Governance strategy the following considerations should be included:

Disaster recovery and business continuity via replication

Full protected audit of actions on the cluster (including reads, writes, updates and administration actions)

Lock-down media library access to API only, therefore restricting access from common protocols (e.g., filesystems) and protecting access to only those with security credentials

If Samba (SMB) is to be used mounting it externally avoids some of the security holes. Furthermore, the Samba instance can be given access to only a subset of the assets (e.g., not the full media-archive)

These and many other features are detailed in MatrixStore security datasheet.

The OM View: How to keep your data safe

Gone are the days when data sat disconnected to the rest of the organisation on tapes on shelves. They weren't that good anyway. Fires have burned down many an archive.

However, things are getting tougher. Too much cyber-crime has paid and the recent cyber attack will only make criminals and malicious individuals more targeted in the way they attack. You have a lot of wealth in your data. That data is vulnerable.

Avoid having access to large swathes of data from a single PC / login. It is a major security hole.

Think about your backup, disaster recovery and replication strategies with the hackers in mind. The hackers will compromise a PC at some-point. What could a determined hacker do from there?

Think about keeping data safe in purpose built storage. Exposing everything via a filesystem is extremely dangerous. Consider on-premises object storage for this. Get into the mind of the hacker when forming your digital content governance strategy.

Normally at this point it is common to sa
LINK: http://object-matrix.com/wannacry-ransomware/...
See more stories from matrixstore

Most recent headlines

04/09/2025

Monumental Sports & Entertainment and Dalet Win Prestigious 2025 NAB Show Project of the Year Award

Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...

11/05/2025

Berklee Honors Andr 3000 and Sara Bareilles at 2025 Commencement

Berklee Honors Andr 3000 and Sara Bareilles at 2025 Commencement This years honorary doctorate recipients were recognized for their profound influence as art...

10/05/2025

The National Film and Video Foundation Members of the Appeal Review Committee Call is Open

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

10/05/2025

Samsung Ads Debuts the Samsung Television Network

NEW YORK During the IAB NewFronts 2025, Samsung Ads announced the debut of STN, the Samsung Television Network, a FAST channel with live content that will be av...

10/05/2025

TMobile Demo Sets a 5G Uplink Record

SEATTLE T-Mobile has announced that it set a new uplink speed record of 550 Mbps in sub-6 GHz spectrum using cutting-edge 5G Advanced tech....

10/05/2025

22 Republican U.S. Senators Urge FCC to Modernize Ownership Rules

WASHINGTON Twenty-two U.S. Senators have sent a letter to Federal Communications Commission chair Brendan Carr urging him to modernize ownership caps that are...

10/05/2025

Meet Graduates from Berklees Class of 2025

Meet Graduates from Berklees Class of 2025 Members of this years graduating class reflect on their proudest moments at Berklee and look ahead to whats next. ...

09/05/2025

Journalism Under Gender Apartheid: An Interview with Malala Yousafzai and Zahra Joya

At the Frontline Club in London, a venue long associated with media freedom and ...

09/05/2025

Spotify Data Reveals Eurovision 2025 Fan Favorites, With Sweden's KAJ Leading the Pack

As excitement builds for the annual Eurovision Song Contest, Spotify data offers...

09/05/2025

The National Film and Video Foundation Marketing and Distribution Advisory Panel Call.

The National Film and Video Foundation (NFVF), an agency of the Department of Sp...

09/05/2025

The Future of Consumer Engagement

In our latest blog, Laura Rognoni dives into the shifting currents of change in the digital entertainment landscape, revealing the trends that will keep viewers...

09/05/2025

Netflix to Rollout New More Flexible UI Starting May 19

LOS GATOS, Calif. Netflix has announced that starting May 19 it will begin rolling out a major upgrade to its user interface and the TV experience it offers str...

09/05/2025

Iger: Pay TV Subs to Get Upcoming ESPN DTC App

The Walt Disney Co. CEO Bob Iger told analysts the direct-to-consumer ESPN app often referred to as ESPN Flagship will be available to the linear channel'...

09/05/2025

Berklee Online Signs Transfer Articulation with Conservatorio Nacional de Msica

Berklee Online Signs Transfer Articulation with Conservatorio Nacional de M sica The new agreement allows CNM students in the Dominican Republic to transfer i...

09/05/2025

Wooden Camera Launches Accessories for the Blackmagic URS...

Wooden Camera, a leading innovator in camera accessories, is proud to announce the launch of a new line of products for the Blackmagic URSA Cine Cameras. These ...

09/05/2025

LYNX Technik Expands Series 5000 Platform with New 12G-SD...

LYNX Technik, provider of modular signal processing solutions is expanding its popular Series 5000 platform with three new 12G-SDI cards. The new cards provide ...

09/05/2025

Pebble migrates ON TV to new technology platform

Pebble, the leading automation, content management and integrated channel specialist, has completed a project to migrate ON TV, the major independent broadcaste...

09/05/2025

NUGEN Audio Unveils DialogCheck Speech Intelligibility So...

NUGEN Audio launches its new speech intelligibility plug-in, DialogCheck. A mono, stereo and multichannel dialog clarity meter, the software provides an objecti...

09/05/2025

Disguise to Showcase Turnkey Solutions at Middle Easts To...

Disguise the technology platform and solutions provider that powered MDL Beast Soundstorm 2024, Dubai Expo's Al Wasl Dome and visual displays at the Burj ...

09/05/2025

CVP Brings Cutting-Edge Broadcast Live Production and Stu...

CVP has announced it will demonstrate its cutting-edge broadcast, live production and studio solutions at MPTS 2025. Taking place at Olympia London from 14th - ...

09/05/2025

Mediagenix and White Peaks Solutions Team Up to Power Sha...

Mediagenix, a global leader in smart content solutions to profitably connect the right content to the right audience, and White Peaks Solutions, the prominent e...

09/05/2025

SportsEngine Play Extends Award-Winning Collaboration Wit...

SportsEngine Play, the first-of-its-kind streaming service for youth sports, has agreed to a multi-year extension with AI-automated sports content leader, Pixel...

09/05/2025

TOD by beIN goes live with Friend MTS to tackle piracy in...

Friend MTS, a leading global provider of content protection services, today announced that TOD, the premier sports and entertainment OTT subscription service fo...

09/05/2025

ZEISS Demos One-Click Virtual Lens Tech for VFX and Compo...

ZEISS announces that it is in development on a new virtual lens technology that will allow visual effects and compositing artists to apply an authentic lens loo...

09/05/2025

Cerberus Tech at MPTS Unifying Cloud and On-Premises Cont...

At the 2025 Media Production & Technology Show (MPTS), Cerberus Tech will showcase the latest major enhancement to its Livelink IP video delivery platform the...

09/05/2025

Warren Thomas Named Vice President and General Counsel of Capitol Broadcasting Company

Capitol Broadcasting Company welcomed Warren Thomas as the new Vice President an...

09/05/2025

Harvard Taps Studio Technologies for Sports Telecasts

CAMBRIDGE, Mass. Studio Technologies said the Harvard University athletics department has integrated Dante-enabled equipment from the vendor into its broadcast ...

09/05/2025

ITN, Magnite Launch Programmatic Solution for Local Linear TV

NEW YORK ITN, a provider of a local linear supply side platform, and Magnite, a independent sell-side advertising company, have announced that they working toge...

09/05/2025

Nugen Audio Unveils DialogCheck Speech Intelligibility Software

LEEDS, U.K. Nugen Audio has launched a new speech intelligibility plug-in, DialogCheck and offered up quotes from technologists working at places like Netflix p...

09/05/2025

AJA I/O Gear: The Heart of Broadcast Solutions' VEGO Mobile Editing Solution

AJA I/O Gear: The Heart of Broadcast Solutions' VEGO Mobile Editing Solution Brie Clayton May 8, 2025 0 Comments When working remotely on broadcas...

09/05/2025

What do they teach in an Advanced Adobe After Effects Course?

What do they teach in an Advanced Adobe After Effects Course? Roland Kahlenberg May 8, 2025 0 Comments There aren't many advanced After Effects co...

09/05/2025

Larry Jordan Sits with Trevor Morgan of OpenDrives at NAB 2025

Larry Jordan Sits with Trevor Morgan of OpenDrives at NAB 2025 Brie Clayton May 8, 2025 0 Comments Trevor Morgan, COO of OpenDrives, shares how the co...

09/05/2025

Berklee Popular Music Institute Announces UK Festival Debut and Tour Dates

Berklee Popular Music Institute Announces UK Festival Debut and Tour Dates For the first time, BPMI will bring Berklee-affiliated artists and students to the ...

09/05/2025

MLB Sunday Leadoff' 2025: MLB Local Media Pulls the Production, Operational Strings in Second Season on Roku

MLB Sunday Leadoff' 2025: MLB Local Media Pulls the Production, Operational ...

09/05/2025

LTN, Pro Volleyball Federation To Wrap Second Season With Championship Weekend

LTN, Pro Volleyball Federation To Wrap Second Season With Championship Weekend PVF's broadcast coverage has risen 350% from its debut season By Mark J Burn...

09/05/2025

Evertz's Ray Kasprzyk on Meeting the Unique Technological Needs of Massive Live Esports Productions

Evertz's Ray Kasprzyk on Meeting the Unique Technological Needs of Massive L...

09/05/2025

With Real Madrid-FC Barcelona, ESPN Preps for Most Ambitious LaLiga Match Coverage Yet

With Real Madrid-FC Barcelona, ESPN Preps for Most Ambitious LaLiga Match Covera...

09/05/2025

Sky Original documentary The Girl Who Caught a Killer to air on Sky and streaming service NOW on 25 May

Friday 9 May 2025 Download images HERE Episodes are available on Sky Media Vil...

09/05/2025

SO JI-SUB Returns With Cold and Intense Noir Action Series Mercy For None', Premiering June 6

Back to All News SO JI-SUB Returns With Cold and Intense Noir Action Series Me...

09/05/2025

Netflix Announces Our First-Ever Nordic Medical Drama Starring Sara Khorami in the Lead Role

Back to All News Netflix Announces Our First-Ever Nordic Medical Drama Starring...

09/05/2025

Marquis launches Postflux for Pro Tools' audio production management software

New beta programme for Avid Pro Tools users provides versioned backup/archive M...

09/05/2025

RT Statement: Eurovision Song Contest 2025

Further to the comments from RT Director-General, Kevin Bakhurst on Wednesday 7th May included below in which he asked the EBU for a discusion on Israel...

09/05/2025

Tom Brady, Nadine Coyle, Joe Duffy and EMMY among guests on this week's Late Late Show season finale

Here is your host, Patrick Kielty! In the season finale of The Late Late Show, ...

09/05/2025

My Eurovision Party 2025 - join in on the fun with RT Kids and Marty Whelan avatar!

My Eurovision Party 2025 - join in on the fun with RT Kids! Eurovision launche...

08/05/2025

What to Watch: 6 Sundance Institute-Supported Films by Filipino Directors

A sinister fairy infiltrates a desperate family in Kenneth Dagatan's In My Mother's Skin, which premiered at the 2023 Sundance Film Festival. Photo co...

08/05/2025

Expected weak market dynamics weigh on business development in the first three months 2025

As expected, continued weak demand from key sales markets and declining economic...

08/05/2025

BBC announces Agatha Christie's Endless Night, adapted by Sarah Phelps

A new three-part series is coming to BBC iPlayer and BBC One (Image: The Christie Archive Trust) The BBC has announced Agatha Christie's Endless Night, a...

08/05/2025

Managing the Mission: Teaching Technique to C3ISR Operators

For skyward-bound operators, training focuses on the unique aspects of flying ISR missions, including the management of onboard surveillance equipment and the e...

08/05/2025

Cable Industry Backs Broadcasters' Move to Software-Based EAS

The cable industry has told the Federal Communications Commission it supports the National Association of Broadcasters' proposal to allow broadcasters to us...

08/05/2025

CTA Tells FCC: Dont Mandate ATSC 3.0 Tuners

WASHINGTON The Consumer Technology Association has continued its opposition to mandates requiring that NextGen TV/ATSC 3.0 tuners be included in new TV sets, sa...