UK Considers Ban on Ransomware Payments by Public Bodies (www.infosecurity-magazine.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 14 Jan 17:30
https://sh.itjust.works/post/31093319

#cybersecurity

threaded - newest

shoulderoforion@fedia.io on 14 Jan 19:24 collapse

Well, this is fine, just so long as those "public bodies" all have backup/recovery plans, and backup storage storing just however many minutes, hours, or days that are acceptable to lose data for, when they get hit with ranswomware encryption. it's all a matter of cost, if you have backups, and systems can be wiped, reset, reconfigured, in an acceptable amount of time, then the ransomewarers can get fucked.

If you get hit, and either don't have the backups before the encryption, or taking the time and expense to staff up IT consultants to wipe/reset/reconfigure/test is financially ruinous, then it's you who are fucked, if you're legally barred from paying the ransom (which 95% of the time works just fine, aside from, you know, financially supporting terrorists and terrorist states).

I'd always suggest being prepared with a backup recovery plan, and educating the principals just how long it's going to take from "go" to "back up to where we were functionally before we got hit", how much that's going to cost upfront pre emergency, and projected costs for downtime back to uptime.

Rogue@feddit.uk on 14 Jan 19:45 collapse

I dunno. The proactive approach you’re describing doesn’t sound very public sector. Why invest money in something when you could just ignore the issue, cross your fingers and hope it happens to someone else, not you.

kurikai@lemmy.world on 14 Jan 19:54 collapse

What you said sounds just like the private sector

Rogue@feddit.uk on 14 Jan 20:38 next collapse

Tbh it was probably a criticism of capitalism more than the public or private sectors. Why consider the long term when you could just cut costs to inflate short term profitability.

Voroxpete@sh.itjust.works on 15 Jan 02:54 collapse

In the private sector, it’s done out of greed. In the public sector, (where nothing is ever properly funded because no one likes taxes) it’s done out of necessity.

Corkyskog@sh.itjust.works on 14 Jan 23:47 collapse

Every sector.

We haven’t had dragons attack in 50 years! Why do we still need that wizard with his protective spells?