>
if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited.The problem is that it matters less than we'd like to think how "serious they are about security".
I'm seeing a lot of discussion about the responsibility of the victims to secure their networks, and it's mostly valid.
But it's strange that we're talking about how to punish the victims versus the criminal conspirators. We virtually let the malicious, overtly criminal party off the hook. It's almost like we're saying we expect criminals to be criminals and these guys are so hard to catch that the onus is entirely on the targets to repel their incessant attacks, else they're negligently malicious themselves. Sure, most of these victims can do better in just about every case. But, people here know better than most how difficult it is to 100% secure every layer of the stack from software to firmware to hardware, with multiple vendors and vectors, OSS, zero days, etc. And the bad guys only have to be right once across this broad attack surface. It's impossible to defend completely. There will always be breaches.
So, there's another element of this that has to be addressed, and that's getting serious about punishing these people. As it is, there's zero disincentive for them to just keep trying until they get through, but the upside is massive.
Most if not all of this activity originates from nations that are adversarial towards the US. So, we need to start treating these instances as official sovereign actions, especially when they originate from nations wherein the government and their intelligence services exert control over (and outright sponsor) such criminal schemes, and wield these attacks as a projection of national power.
These regimes also tend to feature oppressive criminal justice systems and harsh reprisals for even political dissidents. So, the message is, "we're not going to argue whether you're sanctioning these acts, but we're also not buying that you can't stop them, so we'll treat each incident as an official act of the state. We're holding you responsible for your criminals when they attack us and we will respond accordingly".
Detailed discussion around exactly how the most recent exploit might be mitigated is interesting and useful. But the balance in these discussions between mitigation and reprisals for the perpetrators needs to be shifted much more towards the latter. Otherwise, we can expect these discussions ad infinitum.