Earlier quoted context omitted.
In a lot of situations we've heard about, the cybersecurity team could consist of one person with a bullhorn walking around shouting "don't connect critical infrastructure to the Internet". Whether they'd listen to them still is another matter but that's the same with a regular cybersecurity team. And that is to say we have institutional standards where unsafe practices are considered OK and will be followed because…
I don't agree - that won't work as critical infrastructure can't be not connected to internet; perhaps we have a different understanding of what "critical infrastructure" means? You can have disconnected industrial networks, but the ransomware cases aren't really about those. For example, let's look at the recent major Colonial Pipeline case. Their pipeline systems weren't connected to the Internet, and did not get c…
When Colonial attack happened, there was a person posting who described Colonial's situation from the inside. Colonial shutdown because their system their billing was compromised and their pipleline could have been compromised.
The pipeline was connected two way in hardware but one-way in software. But software can be compromised. Why not one way in hardware? 'cause the company was. Once billing was compromised, they had to assume the pipeline was compromised.
I suggest you read:
https://news.ycombinator.com/item?id=27101756
Not connecting is helpful in some cases, but it's nowhere close to a sufficient solution.
Sure, my comment above involves some hyperbole. The main point is that companies allow a ragbag of profligate connections between various subsystems to be default OK because this saves them money now and costs other people money later. And then expect outsourced security to solve this.
I'm sure a lot of the companies hit by the solarwinds exploit had cybersecurity teams. It's just these teams can't say something like "don't allow some shitty third party to autoupdate their software into your system - if you view security as important, as maybe a government agency should."