Earlier quoted context omitted.
Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.
Backups might get you up and running again, but the new hotness is threatening to release trade secrets, competitive advantages, and embarrassing emails. Even with an ironclad recovery some people might be inclined to pay in such a situation.
80% of orgs that paid the ransom were hit again
331–340 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#332What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.
Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.
Re: 80% of orgs that paid the ransom were hit again
#333Earlier quoted context omitted.
>> But it only takes one person and these huge companies employ so many people. No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site…
Notice the previous comment about developers not allowed to be admin of their own machines? On computers with a good security model developers don't need to be admin of their own machines, but that wasn't thought of.
Re: 80% of orgs that paid the ransom were hit again
#334Earlier quoted context omitted.
Notice the previous comment about developers not allowed to be admin of their own machines? On computers with a good security model developers don't need to be admin of their own machines, but that wasn't thought of.
I don’t get the point of not allowing administrator to the local machine to employees. The local machine is practically a throwaway in my opinion. Why should we care about it? The shared folder is much more vital to the business.
Re: 80% of orgs that paid the ransom were hit again
#335Earlier quoted context omitted.
I used to care for the security of my work machine. I was sole admin. No corporate crap- or spyware. I was responsible and I learned a lot. We got bought. Big corp enforced Endpoint Management and a whole barrage of corporate spyware. I am not an admin anymore. I can't even use an AdBlock solution anymore. And guess what. I don't give a damn anymore. If the device enforces an update, so he it. If I have to double app…
I have a direct A/B experiment on this: I have one work laptop which is centrally managed by big-corp IT (I'm not the admin), and one laptop which is a project machine which I manage and admin. Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machin…
I kept my machine as it was, explaining that if anything happened to those units (bad updates, blah blah), mine would be unaffected and mine was completely necessary.
Lo, and behold! That very day everyone was complaining how slow their computers were, how even basic websites now took ages to load, and they did.
The owner refused to admit he made a bad decision and stayed with that 'IT' 'company' for over a year, and didn't get rid of them until I'd left and no one was available who could triage, and they saw just how little that 'company' did, and just how much I was made to cover for them
Re: 80% of orgs that paid the ransom were hit again
#336Earlier quoted context omitted.
And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees. Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but…
"I have seen unpstanding guys rub magnets over hard drives over pure apathy." Open up a spinning rust hard drive and you will find two very strong magnets inside, positioned opposite each other.
Re: 80% of orgs that paid the ransom were hit again
#337This isn't true and I'm not sure why people think it is. This is not how the world works. Ransom crews are not cartoons, they are people like the rest of us running a business.
At a very high level, sure, ransom paid then they might be 'hit again' by a random hacker testing the defences next year. Is that 'hit again'? 'Hit again' is not 'ransom again'
If this is cookie cutter ransomware that's automated and you pay an automated system to un-encrypt. Sure the worm or what not will attack again is you don't fix that worms hole.
This has zero to do with REvil and all the famous ransom crews that the title implies. That should be pretty obvious.
Re: 80% of orgs that paid the ransom were hit again
#338Earlier quoted context omitted.
What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.
Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.
Re: 80% of orgs that paid the ransom were hit again
#339Earlier quoted context omitted.
I have a direct A/B experiment on this: I have one work laptop which is centrally managed by big-corp IT (I'm not the admin), and one laptop which is a project machine which I manage and admin. Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machin…
If a developer needs to be admin to do their work the os needs a better security model.
And I'd argue this isn't only true for kernel development. In some cases, sure, but certainly not enough to make such a blanket statement.