Earlier quoted context omitted.
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough to have any chance of stopping a targeted state actor. The fact they caved so quickly tells me they are years away from a reasonable security posture.
Still, this might lead to their first solid security hire that can bring about change in the form of zero-trust principles, security in depth, etc.
> to have any chance of stopping a targeted state actor.
Given unlimited resources, interest and budget, no participant in the modern digital landscape has a significant chance of stopping motivated threat actors.
> The fact they caved so quickly tells me they are years away from a reasonable security posture.
Yes, obviously, but driving change is about incrementally tending to a desired state. Your fatalism is, quite frankly, unnecessary, not that you're not entitled to your opinion, just that disagreeing with GP or stating they are naive because this won't bring about perfect, all-encompassing change is not useful.