6 ms·
You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to
by OminousWeapons 5y ago
You won't even be able to get private insurance if the industry has to insure against complete destruction of a given business. Are you expecting the US gov to backstop every business regardless of size against ransomware? Who is going to pay for that?
Additionally, how do you protect against the obvious opportunities for fraud and abuse (business deliberately attacks itself to collect the insurance payout, business hits their competitors to drive them out of business, etc)?
- samstave 5y ago>"insure against complete destruction of a given business." Isnt that what fire/flood insurance is for?
- OminousWeapons 5y agoFire and flood insurance protect against discrete or regional risks whereas ransomware will potentially disrupt operations globally, and actually most private insurers won't offer flood insurance to large swaths of the US because the risk has been deemed to be too high. The US gov insures against coastal flooding at GREAT expense to the tax payer.
- detaro 5y agoI wonder what the biggest company is that's totally dependent on a single location (or locations in the same flood zone) and at the same time is usefully insured against such destruction.
- samstave 5y agoPorts? Take out a port, and screw an entire region.
- Workaccount2 5y agoYou would be able to get affordable private insurance if you had a cyber security team.
- detaro 5y agoVarious providers of "cyber insurance" are right now busy getting rid of ransomware coverage because it turns out offering that isn't working for them. and yes, they do require companies to have cyber security infrastructure and audits.
- Workaccount2 5y agoThat would imply that cyber security isn't effective in mitigating these attacks then, no?
- OminousWeapons 5y agoIt suggests it is a difficult problem to stop. As I understand it, attackers now frequently perform an initial compromise and then manually escalate privileges before launching a ransomware attack for greater impact. Alternatively, the attacker will sell privileged access to a ransomware group. This isn't someone from HR opening a malicious attachment and getting the whole company owned via eternal blue.
- detaro 5y agoAt least it suggests that the current standards and auditing practices are not sufficient, and apparently formulating testable requirements is difficult.
- deleted 5y ago[deleted]