4 ms·
The article is spot on. It's pretty much what happened when Maersk was hacked within an inch of bankruptcy. The flaw was identified, flagged and acknowledged b
by fambalamboni 2y ago
The article is spot on. It's pretty much what happened when Maersk was hacked within an inch of bankruptcy.
The flaw was identified, flagged and acknowledged before it happened:
"In 2016, one group of IT executives had pushed for a preemptive security redesign of Maersk’s entire global network. They called attention to Maersk’s less-than-perfect software patching, outdated operating systems, and above all insufficient network segmentation. That last vulnerability in particular, they warned, could allow malware with access to one part of the network to spread wildly beyond its initial foothold, exactly as NotPetya would the next year."
But:
"The security revamp was green-lit and budgeted. But its success was never made a so-called key performance indicator for Maersk’s most senior IT overseers, so implementing it wouldn’t contribute to their bonuses."
Basically, a near miss that wasn't incentivised for anyone to fix.
If you're interested in this type of story, it's an absolute thriller to read:
https://archive.is/Gyu2T#selection-3563.0-3563.212 https://archive.is/Gyu2T#selection-3563.0-3563.212