7 ms·
1. Couldn't you argue the same thing about brick and mortar stores that get robbed? "If they don't want to hire hardcore commandos to protect their property, ma
by dkokelley 5y ago
1. Couldn't you argue the same thing about brick and mortar stores that get robbed? "If they don't want to hire hardcore commandos to protect their property, maybe they deserve to get robbed/looted?"
(My point is that incompetence doesn't make it morally ok that a criminal thing happens to someone)
2. There's a risk/reward component. Nobody likes to buy insurance. Resource constrained organizations will almost always choose to invest their resources to get MORE resources, not protect against the chance that something bad will happen. A rational organization should only invest in protection when the risk is so great that it's likely to interfere with its primary business (beyond their legal/moral obligation to protect information they're trusted with).
2a. If a $2m ransomware attack hits your organization every 5 years, and it would cost you $1m/year in talent & resources to harden against this, you SHOULD let it happen because it's cheaper. Just patch the vulnerability each time it happens and try to stretch the next ransomeware attack to more than 5 years away.
3. Of course there are many irrational organizations that don't protect against ransomware for irrational reasons (e.g. due to internal politics). There's not much to say here except that at some level of management (including the CEO & board) where people are not paying attention to what's happening, and they should go hire those hardcore nerds and pay them what they need to.
- deleted 5y ago[deleted]
- DiffEq 5y agoOn Point 1....Yes; and besides that most Brick and mortar stores have insurance for catastrophic loss...so essentially they have a working backup.
- bash-j 5y agoAnd most physical items in a store can easily be replaced. If a criminal is holding your shop ransom, it's not for intellectual property.
- deleted 5y ago[deleted]
- tomc1985 5y agoTo the first point... some stores do. Hell, even fast-food restaurants in some big cities hire armed guards to keep the peace. Have you ever seen a McDonald's with armed security? I have. And in any case the threat surface is way different. If I hold up the local Best Buy at gunpoint I'm not walking out with their entire customer roll. But if I hack their POS, there's a pretty good chance that I am.
- deleted 5y ago[deleted]
- joe_the_user 5y agoResource constrained organizations will almost always choose to invest their resources to get MORE resources, not protect against the chance that something bad will happen. This is a good point but it points to something some might not like. Resource constrained warehouses might on skimp on covering the risk of fire, resource constrained restaurants might skimp on sanitation, Resource constrained power companies (PG&E) might skimp on line maintenance and let whole towns burn to the ground (Paradise, 80+ people, Berry Creek 30+ etc) and so-forth (up to every company being too "resource constrained" to pay to stop global warming). In cases of this sort, you have companies risking both their capital and the life and limb of average people. We really have companies following this resource constrained logic and horrible things have and are happening. Economists describe this dynamic in terms of "externalities" and letting it run rampant pretty literally has in world on fire (and drowned under water, etc).
- tomc1985 5y agoYou bring up a very good point, and personally I attribute this to the tyranny of shareholder primacy. At least here in the states, nothing is going to change until there is an alternative that places shareholders at a level that is at most equal to other considerations, and more preferably below more important business considerations.
- Godel_unicode 5y agoThat's not how anything works. The shareholders are the ones asking the company to do a good job with the important business decisions so that the company will do well and the stock will go up. How else would it work...?
- tomc1985 5y agoAs some other comments point out, security hardening doesn't directly raise company value. It's hard to justify in the short-term. Attitudes about it are much better now than they have ever been, but there are still a lot of folks out there that don't prioritize it.
- danmur 5y agoI think buying insurance would be a better analog to having good backups. You save some money by not buying insurance, just like when you skimp on IT infra. Warehouse fires / ransomware gangs will cost more if they happen, but if they don't you came out ahead (I guess).
- adrianN 5y agoI think having working backups is closer to locking your store and having security cameras than it is to hiring a team of soldiers.
- Woodi 5y ago> 2a. If a $2m ransomware attack hits your organization every 5 years, and it would cost you $1m/year in talent & resources to harden against this, you SHOULD let it happen because it's cheaper. Just patch the vulnerability each time it happens and try to stretch the next ransomeware attack to more than 5 years away. No, that's just brain cancer banks board directors can opt for. You simply skipped over customers data bying lost. Oh, insurance give you the money, court settlements will be payed, it's cheap ! For you. And by not having that "talent & resources" you streach your own business beyound sanity. Like that "new telecoms" breed that do not own any cables or antennas. Just marketing, H&R and finances. And lacking any competence (becouse no infra, what they could possibly do ? :> ) call center. And then they outsorce their finance. And they go down or sell themselves when zefir blows... Your thinking style promotes egg shell type of business. But it's cheap !
- dvfjsdhgfv 5y ago> they don't want to hire hardcore commandos to protect their property Brick and mortar stores don't need hardcore commandos. The recent surge in ransomware is actually a good thing as people slowly start to care about the obvious: that if they build their business on something that has a weak link, breaking this link will compromise their business, so it's their job to make sure it never happens. This means asking awkward questions to people who are in charge of your IT infrastructure, whether in house or outsourced. What happens if this computer room is set on fire? What is our strategy of dealing with ransomware attacks? How long it will take to rebuild the systems after they are compromised? These are valid questions to ask as a business owner, and if you don't know the answer to them, you are to blame when the worst happens.
- WJW 5y ago> If they don't want to hire hardcore commandos to protect their property, maybe they deserve to get robbed/looted? In places where there is sufficient law enforcement, this is not required but even then some extra-high-risk shops like banks still do. In places where there is not sufficient law enforcement, like failed states, favelas and the internet, almost all shops should hire guards (or their digital equivalent) or risk being robbed. In this particular case, the long term fix is to extend the rule of law onto the internet but until that time having good security is not optional.
- dangerface 5y agoI would consider these irrational reasons. 1. Yea if you don't lock your store you will get robbed and be held liable for the loss, your insurance won't pay out because you didn't sufficiently protect your liabilities. 2. Businesses buy insurance and secure their equipment because they are held liable for this, the cost is included in the cost of the product. 2a. If a ransomware attack hits your organisation it will destroy your reputation because customers will notice that you don't take their protection seriously, they will leave for a more expensive but reliable product that takes their business and clients seriously and actively works to protect them. I get your arguments they just don't make much sense from the perspective of a business and its liabilities.
- inglor_cz 5y ago"If a ransomware attack hits your organisation it will destroy your reputation because customers will notice that you don't take their protection seriously, they will leave for a more expensive but reliable product that takes their business and clients seriously and actively works to protect them." In many cases, you cannot really switch. https://www.reuters.com/world/uk/uks-northern-rails-self-service-ticket-machines-hit-by-ransomware-cyber-attack-2021-07-19/ https://www.reuters.com/world/uk/uks-northern-rails-self-ser... Ransomware just hit ticket machines on a UK railway. I do not think that this will make people who regularly take that railway seek for alternatives.
- inglor_cz 5y ago"If a $2m ransomware attack hits your organization every 5 years" The question is - how do you know that it is going to hit you every 5 years? This isn't a completely random event. If you build up a reputation of being a soft target, other hackers will try to dip their beaks, too. And there is a lot of them out there. Paying even one Danegeld attracts more Vikings to your shore.
- oort-cloud9 5y agoHow about designating these attacks as an act of war and treating them as terrorists and combatants with a punishment of life in prison or a capital punishment?
- diffeomorphism 5y ago> (My point is that incompetence doesn't make it morally ok that a criminal thing happens to someone) There is negligence, however. If you leave the door wide open and unsupervised and something gets stolen your insurance company will be much less understanding. That does not say anything about how theft is "morally okay", just that negligence is not okay.