3 ms·
The true cost of any of this is very hard to quantify. There are reputational costs (though you generally want to buy the dip after a hack), national security c
by clwg 2y ago
The true cost of any of this is very hard to quantify. There are reputational costs (though you generally want to buy the dip after a hack), national security concerns, intellectual property theft, etc. So, it is a weak argument in that regard, but that's only because there's not a lot of good data to even form a solid opinion on. Sorry if my comment seemed a bit ambiguous.
Personally, I have seen during incident response many organizations drop seven figures on EDR, IDS/IPS, and a bunch of widgets while ignoring or refusing to do simple things like network segmentation and configuration/patch management, and it's because they've been sold silver bullets by their vendors, so I also hold a bit of contempt for the industry as well.
- moritzwarhier 2y agoYeah, I was also thinking about hospitals and other crucial infrastructure where ransomware attacks have even cost lives. I got your point though, that's why I edited in the paragraph about accountability. Thanks for your insights.
- K0balt 2y ago>network segmentation This gives me flashbacks. I worked in hospital IT for a few years, and the main IT office was constantly trying to fold the (unpatchable, running a mix of OS2, win95, win98, MSdos, and proprietary OSs in -2007) medical devices into the main, internet accessible network. I had to spend countless hours in meetings to keep them segregated. At times, I actually had to just pull fiber jumpers out of the switch. They’d eventually have a fit because they couldn’t see the medical devices with their threat scanning software. They could have just hooked up a laptop to the medical device network and said “yep, every single ip address on there is vulnerable” and sent a strongly worded letter to each manufacturer demanding a patch, which will never be released. Since the devices are FDA certified medical devices, you can’t just patch them without manufacturer endorsement of the software change…so any device more than a few years old is usually vulnerable. 3 months after I left they had a major ransomware event. Weird. Who could have imagined?