"After an organization experienced a ransomware attack, the top 5 solutions implemented included security awareness training (48%), security operations (SOC) (48%), endpoint protection (44%), data backup and recovery (43%), and email scanning (41%)." Only 43% of organizations invested in data backup and recovery after a randsomware attack? I would expect that number to be closer to 100%!
80% of orgs that paid the ransom were hit again
171–180 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#172Re: 80% of orgs that paid the ransom were hit again
#173The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Re: 80% of orgs that paid the ransom were hit again
#174Earlier quoted context omitted.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
I think wikipedia got the details wrong there. Crassus didn't offer to buy the burning buildings, he offered to put fires out. At least, that's how I understood it years ago and that's what Wiki's own source shows-- http://www.trivia-library.com/b/richest-people-in-history-ma... . edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.
Re: 80% of orgs that paid the ransom were hit again
#175Now just wait to see what will happen to your insurance rate after you pay the third ransom.
They certainly will begin to understand the need for backups.
Re: 80% of orgs that paid the ransom were hit again
#176Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
I'm sorry but I have to ask: why assume the attacker is female?
Re: 80% of orgs that paid the ransom were hit again
#177Earlier quoted context omitted.
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Where is the hacker's Honor... Cmon man
All the good guys shut up, and so you're left with the criminals who then exploit the flaws instead.
Re: 80% of orgs that paid the ransom were hit again
#178Re: 80% of orgs that paid the ransom were hit again
#179Earlier quoted context omitted.
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Different groups have different policies. I believe some do actually add you to a whitelist if you pay and grant you at least a year or two before your immunity expires. (Maybe some do permanent whitelists? Not sure.)
Re: 80% of orgs that paid the ransom were hit again
#180Earlier quoted context omitted.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
Free market in action.
In both cases it’s the market at play.