I imagine, to use our vernacular, some chancing gobshite is talking his way our of responsibility for their shitty tender as we speak.
Irish health service hit by cyber attack
81–90 of 156 posts
Re: Irish health service hit by cyber attack
#82I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…
Is there a service that could regularly fetch data from s3 or even connect to postgres, and regularly send a physical copy of the data by mail?
Does it make sense to offer airgapped backups as a service to smaller companies? Over mail?
Re: Irish health service hit by cyber attack
#83Earlier quoted context omitted.
Complete, tested tape backups would cure many, many ills. They're out of fashion, but..
The bigger IMO problem with ransomware attacks isn't necessarily that they're holding your data hostage, it's that they can and will publish it. You might be able to tell them to kiss your ass because you have backups, but then they'll publish that information. It's a bit more of a rock-and-a-hard-place situation than most people realize.
Scary, scary place to be. Especially for a health service.
Re: Irish health service hit by cyber attack
#84However, the latter requires a huge mindset and experience shift from the very top of the organisation. And groups and individuals of that organisation having strong interest in their survivability are, of course, not going to change that.
Re: Irish health service hit by cyber attack
#85One of the major issues I've seen while working with large organisation on software development is one of mindset. These are organisations who predominantly think: "We are an 'x' organisation that happens to develop software". The more productive and safer way of thinking is: "We are a software development organisation that is within 'x' market". However, the latter requires a huge mindset and experience shift from t…
Re: Irish health service hit by cyber attack
#86Earlier quoted context omitted.
1. It can only be an act of war if it was done by a nation state. Even though the US likes to declare war on abstract concepts like "drugs" and "crime", that is not how it works in international law. 2. Terrorism has similarly precise definitions, usually along the lines of "the act has to be in pursuit of political aims". Just because its a big and important target does not make it political, ransomware is an econom…
If the attackers are acting under the protection or tacit approval of a foreign government then you can bet that somewhere, someone is prepping a policy paper for kenetic responses. Given the recent pipeline issue and its national security implications I am not going to be surprised at all if some hackers in Russia end up dead from 'accidents' that are so obviously not accidents that no one is fooled.
Re: Irish health service hit by cyber attack
#87Earlier quoted context omitted.
Complete, tested tape backups would cure many, many ills. They're out of fashion, but..
The bigger IMO problem with ransomware attacks isn't necessarily that they're holding your data hostage, it's that they can and will publish it. You might be able to tell them to kiss your ass because you have backups, but then they'll publish that information. It's a bit more of a rock-and-a-hard-place situation than most people realize.
https://www.macworld.co.uk/cmsdata/features/3659100/how_to_r...
Re: Irish health service hit by cyber attack
#88I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years. * Keep all systems up to date with the latest patches. * Have a DR plan and test it regularly. * Make frequent backups, verify them, and keep them offline . Historically organizations have been so bad at backups that the advice has bee…
I typically work in situations where the entire data to be backed up (file storage, database) is on the order of 10-100Gb. The projects I’m working on don’t fit the high profile of a Colonial but I’d rather err on the side of safety. Is there a service that could regularly fetch data from s3 or even connect to postgres, and regularly send a physical copy of the data by mail? Does it make sense to offer airgapped back…
Re: Irish health service hit by cyber attack
#89Ever-relevant XKCD: https://xkcd.com/2030/
Re: Irish health service hit by cyber attack
#90There's a trend of paying these ransomware attacks which are sometimes in the order of millions. Imagine if those millions were _proactively_ invested into the computer security of these systems?
I tried to imagine, but my mind told me that a couple of millions would not prevent these issues. Did I imagine it wrong? You would likely end up with better security. Would it be good enough to prevent breaches? Doubt it.