• 1 Post
  • 10 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2023

help-circle






  • I agree with the author’s solution to organizations of protection and resilience and that paying ultimately hurts everyone. If everyone refused to pay, we may see these types of attacks diminish.

    The challenge to cyber security professionals will always be the convincing senior leadership to understand why not paying is better in the long run.

    Having that conversation in the moment is too late. There needs to be a cyber attack response plan communicated and approved before disaster strikes.

    Even so, there will always be the friction of cost. Senior leaders will weigh the cost of paying to the cost of downtime/repair and the social stigma if your company provides a service to customers. If your original argument isn’t strong enough, cost will win.

    One more point is paying is also a systemic issue. Cyber insurance is becoming popular for business. What we have seen with some insurers, their solution for ransomware is coverage to pay the ransom, perpetuating the problem.