>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments. >The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said. pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st…
Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
11–20 of 200 posts
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#12First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#13Earlier quoted context omitted.
An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.
There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#14I strongly suspect this too will end up mostly a jurisdiction/accounting nuance rather than a substantial change.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#15First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#16So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?
> What would stop them from paying the ransom They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head). Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, a…
There may have been a time when a company would act on principle, but I think it's very rare today. You hardly even expect people to do that. It's the world we have made.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#17So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?
Obviously none of these make it impossible, but the goal needs to be to tip the value proposition the other way.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#18Earlier quoted context omitted.
There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.
Sorry, by air-gapped I was envisioning things like tapes or disconnected disk drives.
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#19So there's that woman I follow who used to work in hostage and ransom negotiation business, and she's adamant there's no such thing as "no negotiations with terrorists" no matter public rhetoric or legislation. When push comes to shove, side channels and loopholes are inevitably found and third party contractors like her are getting hired. I strongly suspect this too will end up mostly a jurisdiction/accounting nuanc…
Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says
#20First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").
I would guess that the affected entities here are not companies, but public entities. Federal departments, the state governments, and municipal governments all run their own IT systems and have been affected by ransomware; if there is a top-down policy of "don't pay the ransom" it presumably affects policy for all of those.
Many types of attack don't actually know where they're breaking into at the time they break in. And once you're in, you might as well try running a ransom attack.