3 ms·
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small bus
by yzmtf2008 6y ago
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.
- quickthrower2 6y agoI think this is where insurance can come into play. Like get a smoke alarm and sprinklers, but also get fire insurance.
- yzmtf2008 6y agoAn insurance would be a much better idea than what OP suggested.
- tantalor 6y agoCyber insurance is already a thing. Even though not paying the ransom is recommended, some companies are instead paying the ransom as part of their insurance coverage. For example, earlier this year Lake City, Florida was a victim of a ransomware attack. After receiving approval from their insurer. Lake City paid $460,000 in order to restore their systems. Since they had cyber insurance, the city only had to pay a $10,000 deductible. https://content.naic.org/cipr_topics/topic_ransomware.htm https://content.naic.org/cipr_topics/topic_ransomware.htm
- akersten 6y ago> let any company that doesn't have the budget to have a proper cybersecurity team just die? Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations, I really don't have a problem with them going under. It's less burdensome than being compliant with the local tax code, which all businesses have to do already.
- yzmtf2008 6y ago>"the most basic offline redundancy" How many people you meet everyday that are not in IT even knows what offline redundancy means? I think what your suggestion amounts to, is effectively a mandate on SMBs having either an in house security team, or a contract with a consultancy on cyber security. That's a huge burden. It's not really easier than local tax code. These things change much more frequently and it's not like you can just walk into a local H&R Block to take care of your cybersecurity needs. Ransomeware, as it is now, didn't even exist (or is that popular) 10 years ago.
- TedDoesntTalk 6y ago> the simplest of backup solutions would have prevented this. Incorrect. The black hats almost always encrypt backups, too. You could say "what about offline, glacial backups?" But then you're no longer talking about "the simplest of backup solutions"
- deleted 6y ago[deleted]
- mlyle 6y ago> the simplest of backup solutions would have prevented this A big part of the threat is the disclosure of sensitive data that they exfiltrated. Backups don't help this. Not to mention that the pros delay encryption until they've managed to screw up backups, too.
- dx034 6y agoI don't think that budget is the problem. You can be very safe without a big budget. It's a lack of priority and management valuing quick development over security.