Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

171–180 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#171
post #107

"After an organization experienced a ransomware attack, the top 5 solutions implemented included security awareness training (48%), security operations (SOC) (48%), endpoint protection (44%), data backup and recovery (43%), and email scanning (41%)." Only 43% of organizations invested in data backup and recovery after a randsomware attack? I would expect that number to be closer to 100%!

And how many of that 43% actually put in place a method to test their backups regularly? I'd bet its less than 5%

Re: 80% of orgs that paid the ransom were hit again

#173
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Where is the hacker's Honor... Cmon man

Re: 80% of orgs that paid the ransom were hit again

#174
post #50

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

I think wikipedia got the details wrong there. Crassus didn't offer to buy the burning buildings, he offered to put fires out. At least, that's how I understood it years ago and that's what Wiki's own source shows-- http://www.trivia-library.com/b/richest-people-in-history-ma... . edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.

That's interesting - I definitely have heard it taught the way Wikipedia has it. But I suppose some website here or there doesn't really count as much of a source when we're talking of events so far in the past. Maybe someone can provide a primary source or two?

Re: 80% of orgs that paid the ransom were hit again

#175
What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second.

Now just wait to see what will happen to your insurance rate after you pay the third ransom.

They certainly will begin to understand the need for backups.

Re: 80% of orgs that paid the ransom were hit again

#176
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

I understand how this sort of off-topic snag can feel provocative, but please don't copy it into the thread where it can turn into an entire flamewar. There's nothing new in any of this at this point, and therefore nothing interesting. When there's nothing interesting, discussions turn nasty. Solution: focus on the interesting specific information and diffs in a post, and ignore the provocative bits.

https://news.ycombinator.com/newsguidelines.html

Re: 80% of orgs that paid the ransom were hit again

#177
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Where is the hacker's Honor... Cmon man

It went away when telling someone their system was broken stopped being treated a favor and started being treated as a crime.

All the good guys shut up, and so you're left with the criminals who then exploit the flaws instead.

Re: 80% of orgs that paid the ransom were hit again

#179
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Different groups have different policies. I believe some do actually add you to a whitelist if you pay and grant you at least a year or two before your immunity expires. (Maybe some do permanent whitelists? Not sure.)

Something something Norton Anti-Virus something.

Re: 80% of orgs that paid the ransom were hit again

#180
post #131
post #50

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

Free market in action.

Doesn’t mean the free market doesn’t work. Asking people to pay before putting out the fire could be seen as a pay per use model. While a government run service funded by tax dollars could be seen as a subscription service that price discriminates on income tax rates.

In both cases it’s the market at play.

Post reply on HN