Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

81–90 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#81

Earlier quoted context omitted.

Not surprising. Having insurance just means you're a more attractive target now.

And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…

> This makes you wonder who ends up paying for all of this (with time, energy, money, mental health).

With money? The cost gets passed on to the customers. In a few decades, the invisible hand of the market might push those customers to firms taking this issue seriously... But I think that to be quite unlikely.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#82

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

I wonder if it would make sense that the insurance policy offers a bounty on the hackers after the ransom has been paid. It makes your clients less attractive to attack and might in the long term lower your underwriting costs.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#83
post #33

Earlier quoted context omitted.

This is why you need government intervention. Just make it illegal to pay such ransoms. Now the easy option has disappeared. You likely go out of business, and the company which takes your place implements good security policies from the get go. Funding for hacker groups and newer attacks dries up. Sucks for you in particular, but the public overall is better for it.

> This is why you need government intervention. Just make it illegal to pay such ransoms. this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping. I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be l…

Businesses that don't look after their business are not victims, their unknowing customers are.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#84

Earlier quoted context omitted.

> This is why you need government intervention. Just make it illegal to pay such ransoms. this penalizes the victim. Legally this might be impossible for the same reasons the law is unable to stop you from paying a ransom in kidnapping. I'm not convinced this would affect the problem even if outlawed. Companies would simply go the path of least resistance the same way they do with avoiding tax. There will always be l…

a cybersecurity company to which you pay an annual retainer will just pay the attackers instead. Communication will be done by lawyers and subject to strong confidentiality protection, no one will ever know. Basically, exactly how it happens with kidnappings today.

Attorney-client privilege does not extend to lawyers doing illegal things on your behalf. For example, you can't ask your lawyer to hire a hitman to off a guy, and any evidence related to such activity will not be protected by attorney-client privilege.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#85
post #6
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Do you have any proof of that (or even cases where that has happened before), or are you just making it up?

Proof already was provided, but even without it's just common sense. If ransomware was implemented correctly (like using asymmetric cryptography for encryption). There's hardly anything you can do if you don't have backups.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#86
post #6
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Do you have any proof of that (or even cases where that has happened before), or are you just making it up?

What else could these companies realistically do? All I can think of is restore from backups or break the encryption. First sounds like a job for IT and second impossible unless it’s been done completely incompetently

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#87
I don't see this being true as hackers targetting.

Cyber insurance is not generally public information.

Moreover, there are different flavors of cyber insurance. Some of which cover ransom pay and some do not.

Having knowledge at such a thing means only 1 thing: Someone in the hacker group has access to insider information. Only select people have access to such policies.

Call me a skeptic but i would assume 1 of 100 such hacks don't actually know the cyber coverage that the target has. The ratio of 1:100 may be larger if you expanded the question to Hackers knowing which companies have Cyber coverage... but not which flavor. I still think this is a limited number anyway.

AXA here is just taking the easy route out. A lot of unsuspecting customers (startups) will buy this and get surprised 10 years from now, because their CEO did not bother to read the fine print of a 30 page document.

Lots of lawsuits in the horizon.

Insurance is literally protecting yourself from long tail events. This is such a thing.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#88

Earlier quoted context omitted.

Not surprising. Having insurance just means you're a more attractive target now.

How would one go about finding out if a company has cyber insurance?

Phish the insurance company for a list of customers?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#89

> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay. Wow.

Not surprising. Having insurance just means you're a more attractive target now.

And insurers themselves are good targets, as they give you a validation list of covered businesses to go after, as they're likely to pay out...

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#90
post #88

Earlier quoted context omitted.

How would one go about finding out if a company has cyber insurance?

Phish the insurance company for a list of customers?

https://www.scmagazine.com/home/security-news/ransomware/pol...

By targeting the insurers themselves (their cyber isn't magically better....), and getting a customer list.

Post reply on HN