6 ms·
While I agree with the sentiment around not paying, I don't think it's as simple as that. Calling on law enforcement to "track down the adversary" is not easy,
by ideksec 5y ago
While I agree with the sentiment around not paying, I don't think it's as simple as that. Calling on law enforcement to "track down the adversary" is not easy, and when you track it back to a random Russian cybercrime group what can you do with that information?
A lot of these payments are not fortune 500 companies with unlimited IT budget, it's small or medium businesses with a 3 person IT team. Should they have proper off-site backups? Yes. Should we just let these companies go out of business until organizations learn their lesson? I would say no.
I really like the idea of making payment more difficult and mandating organizations to report these incidents. You're correct, companies do have the incentive to cover things up. Banning payment won't stop that.
I'm interested to see how people will circumvent this if the bill passes. If you pay a third-party company who "deal with the issue" on your behalf, all under legal privilege of course, would you still need to report?
- gopher_space 5y ago> Should they have proper off-site backups? Yes. Should we just let these companies go out of business until organizations learn their lesson? I would say no. Can you expand on that? Bad management leading to criminal interaction seems like something we'd be better off without.
- ryanlol 5y agoHow about you stop dressing so slutty?
- ideksec 5y agoAn organization going out of business isn't just a case of bad management being eliminated. I wrote that line thinking of the clients I've worked with who've been hit by ransomware and didn't realize IT were not doing their job until it was too late. In some cases it's a failure on their part - not investing enough time or resources and seeing IT as "the guy who installs windows". More often than not, they were assured it was taken care of. I don't expect a manager of a car dealership to know if their Exchange server is running recent patches. If companies like SolarWinds and Kaseya can get popped and compromise their downstream customers, think of the number of small MSPs causing that same issue every day. I don't think a business should go under with people losing their jobs because IT screwed up. We would be better off without leadership who take no interest in security, and once a company is hit with a 100k ransomware bill you can bet they'll care going forward.
- throw0101a 5y ago> More often than not, they were assured it was taken care of. I don't expect a manager of a car dealership to know if their Exchange server is running recent patches. You're not wrong, but would the same dealership be as blasé about the assurances from their accountant that all their taxes are being paid? Certainly no one can be an expert in everything, but regular audits from third parties of one's business at semi-regular intervals is prudent. We call in an external IT security auditor regularly ourselves to make sure we're not missing things and still following best practices.
- nobody9999 5y ago>Certainly no one can be an expert in everything, but regular audits from third parties of one's business at semi-regular intervals is prudent. We call in an external IT security auditor regularly ourselves to make sure we're not missing things and still following best practices. You're absolutely correct, up to a point. As an InfoSec professional, I've been on both sides of such audits. Sometimes they're quite good. Sometimes they're awful. Usually, they're somewhere in between. What's more, just because an audit has been performed (even a really thorough one), there's no guarantee that the recommendations will be applied, or even if they are, that they will be applied competently. Leaving that aside and assuming that everything is done properly and thoroughly, regardless of all that hard work, it just takes one non-technical resource to click one link, and ransomware could be loosed on your network. There are, of course, mitigations and, hopefully they are all in place and just the one desktop/laptop system is compromised. All that said, many organizations don't have the time, money or expertise to properly secure their environment, let alone bring in outside auditors. Medium/large companies with such resources should absolutely do all of those things. But the vast majority of companies in the US are SMBs who likely don't have those resources. I'm not making a value judgement either way about the value of mandatory reporting, but I don't agree with your assessment. Edit: Fixed typo (word --> work).
- tomc1985 5y ago> An organization going out of business isn't just a case of bad management being eliminated. Being dispersed. Those people are still around and will go to "work" for someone else
- noduerme 5y agoI'm a one-man IT show for a few small- and mid-sized companies, and I had to manage an incident a few years ago where one of the companies was taken down for several days under a massive dDOS attack. This was accompanied by a ransom email to me. I disclosed the email to the company owner and he asked if we should pay it. I told him I wouldn't pay it if he ordered me to. I was sleeping on the floor for an hour at a time - the host handling the dedicated server basically said we had to go and threatened me that I would have to pay for their downtime, and the attack was large enough to shut down their connection to the transatlantic cable, so I had to fight around it for 48 hours while trying to quietly exfiltrate our data off the server through another one I had in Europe at the moments I could connect. I was contacted by the FBI and ultimately they found the assailants and one of the people behind it went to prison for a couple years; I got a judgment against him for my cost mitigating the attack (although it's symbolic, obviously. I'm sure I won't see a dime of it). He was just some schmuck in Florida. TL;DR - if everyone refused to pay there would be no profit in it. And if everyone had to have IT staff who were competent, or worry about being fined for malfeasance, there would be no question of paying a third party to deal with something quietly. It's right and proper that authorities get involved. Even if they do find it's some troll farm in Russia, they can sanction and block in a way that small companies cannot. It's one of those situations where you stand together or die separately.
- FDSGSG 5y ago>if everyone refused to pay there would be no profit in it Of course it's very saintly of you to refuse to pay, but often not paying is a very bad business decision. You can be sure that enough people will pay for your refusal to not make any difference.
- noduerme 5y agoIt wasn't for saintly reasons; I saw clearly that it would do no good. If we paid, there was no guarantee the attack wouldn't come back the next day. It would solve nothing - actually, it would be worse because it would put us at their mercy. If we couldn't overcome it, get back online and block the next attack, then I didn't deserve my job and the company would have been better without me. Paying wouldn't make the problem go away, it would have made it infinitely worse for me. So saintly? No way.
- JumpCrisscross 5y ago> when you track it back to a random Russian cybercrime group what can you do with that information? Having solid evidence of state-sponsored (or egregiously tolerated) criminal attacks on Americans is the first step to building will to launch (cyber) counterattacks, or at least credibly threatening them.
- pjmlp 5y agoWhen a mom and pop restaurant doesn't do the proper cleaning in the kitchen, the health inspection closes the shop, this is no different.
- horsawlarway 5y agoI really don't think it is.
- pjmlp 5y agoIt surely is, software field is in deep need of liability enforcement.
- horsawlarway 5y agoLiability for what, exactly? Because you're conflating routine cleaning with adversarial attacks. Which is beyond ridiculous. Most commercial ventures do not have the resources to compete with a nation-state in cybersecurity - full fucking stop. Let me paraphrase your argument: Person: They bombed my fucking shop! The military blew it up! You: God damn, you should take some responsibility. Why didn't you lock the doors?
- hermes8329 5y ago> when you track it back to a random Russian cybercrime group what can you do with that information? It shifts the burden from the company to the authorities