4 ms·
> Remediation and recovery for most threats involves OS/app reinstallation Except for all those SolarWinds admins arguing that doing a simple scan and infected
by unclekev 6y ago
> Remediation and recovery for most threats involves OS/app reinstallation
Except for all those SolarWinds admins arguing that doing a simple scan and infected binary removal is enough and then moving on and anything more is "overreacting"
I feel sorry for all these people who are stuck working with such inflexible risk assessment/ITIL processes who are now trying to justify not taking any action because "SolarWinds said everything is ok"
- ownagefool 6y agoIt's quite a mess indeed. There's obviously a contemporary movement that all your systems should be rebuildable by code, which would make getting the systems back into a trusted state (assuming you trust other layers / your code) a lot easier. Obviously this doesn't help if your data is already messed up, if firmwares are hacked, and if your code itself hasn't had te rigour to be trusted, but it's a hell of a lot better position than "scan, remove, forget".