Earlier quoted context omitted.
It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.
OK I agree basic security hygiene removes ransomware as a threat. Now take limited time/budget and off you go making sure basic security hygiene is applied in a company with 500 employees or 100 employees. If you can do that let’s see how it goes with 1000 employees.
Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
51–60 of 101 posts
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#52I don't think there is a reasonable correlation, since stopping ransomware doesn't require that much of an increase in spending; it's a culture thing more than a money thing.
What do you need to do to improve culture in the correct way?
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#53Earlier quoted context omitted.
It's one of those ideas that sounds nice in theory, but doesn't survive contact with the real world. In the same way that many people would say that you shouldn't negotiate with terrorists or kidnappers; but if it's their loved one who's being held and tortured they'll very quickly change their mind. Getting to a world where no one pays ransoms and the ransomware groups give up and go away would be the ideal, and we'…
That's fine, those are acceptable casualties. Make paying any sort of ransom a criminal offense.
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#54Earlier quoted context omitted.
It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.
> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#55Earlier quoted context omitted.
> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…
AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#56Earlier quoted context omitted.
It’s not a popularly held mindset, either within the security industry or outside of it. This piece seems to be pitched at salespeople whose only job is to extract money from other companies. Basic hygiene security hygiene pretty much removes ransomware as a threat.
> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…
This is very literally what 'basic hygiene prevents these problems' addresses. Ransomeware attacks have shown time and again that they way they were able to spread was highly over-permissioned users and services because that's the easy way to get someone to stop complaining that they can't do their job.
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#57The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#58[1] https://web.archive.org/web/20240911103423/https://www.bittr...
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#59Earlier quoted context omitted.
> Basic hygiene security hygiene pretty much removes ransomware as a threat. It does not. The problem is, as long as there are people employed in a company, there will be people being too trustful and executing malware, not to mention AI agents. And even if you'd assume people and AI agents were perfect, there's all the auto updaters these days that regularly get compromised because they are such juicy targets. And n…
AFAIK the idea is to have backups so good, that restoring them is just a minor inconvenience. Then you can just discard encrypted/infected data and move on with your business. Of course that's harder to achieve in practice.
The next step is just to move to security by design operating systems like ChromeOS where the user is not allowed to run any non-approved executables.
If tricking a single employee can cause an entire company to stall out, it's a process issue. Just like how a single employee should not be able to wire out $100,000.
Re: Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
#60The idea that the spending needs to grow linearly with the growth is a damning indictment of the mindset of the vast ineffectual mess that is the cybersecurity industry.
Do you just expect one side to magically be more dollar-efficient than the other? I'm confused.