Earlier quoted context omitted.
It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?
Layoff. They were costing the company money for irrelevant problems.
The push to ban ransom payments is gaining momentum
131–140 of 173 posts
Re: The push to ban ransom payments is gaining momentum
#132Earlier quoted context omitted.
It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?
The answer from Toyota, where this kind of thing (anyone can stop the assembly line if they think there's a problem) originally came from: if the employee reasonably believed there was a problem, they suffer no consequences (and perhaps even get a merit) for pulling the red cord. Because you lose much more money next time there's a real problem, if no-one dares to stop the machine.
If an employee opens a phishing attachment or something, they should be able to report it without fear of losing their job so the incident can be contained.
Instead - they are incentivised to say nothing and hope for the best for fear of getting fired.
Re: The push to ban ransom payments is gaining momentum
#133Earlier quoted context omitted.
The idea would be to reduce the likelihood of a payout.
And just to spell it out: Fewer payout means fewer resources to spend on further operations. So I would absolutely think that the criminals care if there is an actual ban.
The actual cost of launching an attack like this is basically nothing - initial access, etc, is largely automated and performed at scale.
The “costly” part is the hands on keyboard part, but even that can be largely automated, and even manually doesn’t take long.
Re: The push to ban ransom payments is gaining momentum
#134For my MSc in Cyber Risk strategy & governance my final dissertation was built on the parallelism of Italy's ban on payment of ransoms for kindnappings and the current ransomware trend. It's difficult to take solid conclusions, the measure could be effective in disrupting some financially motivated attackers but, given the current landscape, I guess the threat actors could shift more towards extorting end users where…
The ransom would be a few hundred dollars.
Things got rather interesting after WannaCry and NotPetya - some underground markets/sites banned discussion of ransomware for a while, a lot of groups went quiet.
Then it came back with almost exclusively targeting of enterprise/companies for big payoffs instead of a shitload of small payoffs.
Re: The push to ban ransom payments is gaining momentum
#135Re: The push to ban ransom payments is gaining momentum
#136The blackmail part is already illegal, so the criminals wont care one way or another. It's the victims that would now have two problems: damned if they pay, damned if they dont. It's not like the criminals will be at any increased risk or effort either. They're criminal operations already doing other criminal stuff, most of the work is automated (via viruses, bots, etc), and they already couldn't take the payments op…
The idea would be to reduce the likelihood of a payout.
Do you think we should do similar for theft? Should it be illegal for a store assistant to hand over money to armed robbers, because theoretically if less people handed over money there might be less armed robberies?
And I disagree with what you're saying anyway. I doubt this would stop ransomeware. I think if anything this would just push ransomware to become even more cruel so that they increase the likelihood of their victims choosing to break the law over not giving the ransomware owners what they want.
Re: The push to ban ransom payments is gaining momentum
#137Earlier quoted context omitted.
They already must report breaches to the FTC and they must report their financials to the IRS. Most companies aren't going to cook their books over this.
Most companies aren't going to unfuck their entire IT infrastructure which was just encrypted and then turned off ? I mean, sure, if the only computer affected is the cafeteria cash register system, they shrug it off and reinstall. But more than a few of these attacks have absolutely crippled the victims, to the point that it would take months/years to roll out a scrubbed system, and even then data is irrevocably los…
Re: The push to ban ransom payments is gaining momentum
#138Re: The push to ban ransom payments is gaining momentum
#139Earlier quoted context omitted.
Are the world police implementing this ban? And are they starting a world war to enforce it? Or how does this ban go into effect in your view?
Well we start with say you, you trade some of your bitcoin holdings, the feds seize your winnings, fine you and toss you in prison.
Is the US sending seal team 6 to interrogate every person trading bitcoin on earth? Or, is that maybe a bit unrealistic?
Re: The push to ban ransom payments is gaining momentum
#140Earlier quoted context omitted.
good on your employee who pulled the plug first and asked questions later-- that's the sign of an organization where people aren't afraid to do the right thing. very scary situation.
It's always easy to say good on the employee who acted and stopped the problem The question is what happens with an employee who acted when there wasn't a problem?
It was an employee today, but the cord was going to get yanked anyways. A data center tech who pulled the wrong cable out, a power cut, a backhoe with a taste for fiber, whatever.
So long as the employee was acting as best they could with the information they had, the resultant business implications are really the businesses' fault. Having a system that cannot be recovered is risky. Assuming that system will never die is foolish. Blaming the employee is pointless.
My vote would be to understand why the employee thought it was necessary to shut the system down, and then educate them (and the rest of the department, since it's probably a collective problem) on why it wasn't necessary and what they could have done instead or how they could have known it wasn't an issue.
That employee probably also deserves a couple days off once the system is recovered (delivered in person, by their manager). It sends a message that they're not in trouble, but more importantly, they're likely fried from trying to juggle internalizing their mistake, getting the system back up, and worrying they're going to get fired because _this_ is how the CEO learned their name. They probably shouldn't be near a prod system for a couple of days until they've come down from the adrenaline and had some time to internalize what happened.