I’m adding this to my business card. “Ransomware Negotiator”
------------------------------------------- | | | Winston Wolf | | | | Fixer, Cleaner, Ransomware Negotiator | | | -------------------------------------------
Confessions of a Ransomware Negotiator
51–56 of 56 posts
Re: Confessions of a Ransomware Negotiator
#52Earlier quoted context omitted.
Would you let your company that earns millions for a ransomware that is asking tens of thousands of dollars?
If your company that owns millions doesn't have a backup of the mission-critical data somewhere, you have a bigger problem.
Re: Confessions of a Ransomware Negotiator
#53The idea of repeated attacks and leaked data when the ransom is paid is delusional.
Yet somehow this idea persists.
I'm not sure if the average person believes it or just the ones who speak loudest. But it's seems an example of the masses believing something both illogical and not true. A bit like torture not working, the ability to mess with peoples brains is scary.
Re: Confessions of a Ransomware Negotiator
#54Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.
Re: Confessions of a Ransomware Negotiator
#55Earlier quoted context omitted.
He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.
Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.
Re: Confessions of a Ransomware Negotiator
#56Earlier quoted context omitted.
He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.
Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.
That's a step in the right direction, but we need more.
If you're critial industry and get ransomwared there should be hefty fines for everyone involved from the top down.
Also there should be hefty fines for any data leaks that are a result of ransomware attacks.
Companies will start moving when getting ransomwared due to low security standards is a major impact on your financials and not like some "put 50k aside for data hostage situations".