3 ms·
That's the official stance, but if it really mattered they'd pay. And there's of course paths to pay without losing face, like hiring a negociator or a recover
by makeitdouble 1y ago
That's the official stance, but if it really mattered they'd pay.
And there's of course paths to pay without losing face, like hiring a negociator or a recovery firm that acts like a bridge for the money[0]. We came to accept that companies don't act ethically and will only maximize profit, yet the narrative is still stuck on that weird assumption they care about the future of society regarding ransomware.
[0] https://zendata.security/2025/07/08/ransomware-negotiator-scandal-rocks-recovery-industry/ https://zendata.security/2025/07/08/ransomware-negotiator-sc...
- spwa4 1y agoShouldn't the company be punished for the security failure in the first place? It might even be helpful: you could prevent the incentive to pay for security breaches regardless of the negotiation outcome.
- jacquesm 1y ago> Shouldn't the company be punished for the security failure in the first place? Yes. The GDPR has provisions for this. But enforcement is still relatively light.