1. If you pay the hacker, we want money because you paid a hacker.
2. If you don't pay the hacker, we want money because you leaked your users' data.
The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.
> The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.
The rationale for outlawing ransom payments is that it eliminates the incentive for ransomware attacks.
The real question is whether "no-concessions" policies reduce the incidence of ransomware attacks. The answer to that question isn't obvious. However, conditional on no-concessions working in the case of ransomware, "kicking corps while they're down" is not a relevant consideration. The cooperate-cooperate quadrant of the game has higher expected value than the defect quadrants, so you force cooperation by whatever means necessary, even if that means some actors don't get the best possible outcome from their own perspective.
NB: there's some evidence that no-concessions policies don't work particularly well in the case of kidnapping [1]... I'd take care extending this finding to ransomware gangs. If you read the whole PDF, it'll become clear why this behavior is interesting but might not transfer to today's ransomware gangs. That said, when crafting policy on ransomware attacks, it's worth keeping in mind that ransomware attackers may or may not be of the homo economicus species. At the very least as an assumption that you start with but are open to dropping as new evidence prevents itself.
Penalizing you for being blackmailed doesn’t force cooperation. Because an alternative is paying quietly and not informing the authorities. This is what this model encourages in practice. Less cooperation.
The government should fine the company either way for not properly securing their user's data. Security is serious business, it's time companies took it more seriously.
> Part of a good security posture is protecting yourself against insider threats. If you're not doing this, you're not taking cybersecurity seriously.
How do you protect yourself? There are ways to mitigate, surely, but any failure can be a catastrophic incident, and it is literally impossible to protect against all internal threats (in the sense of guaranteeing that no such threat is ever acted upon). All else aside, it just shifts the responsibility one level up: now you have to worry about a compromise of the people responsible for protecting from internal threats.
Security is hard, and the difficulty of answering this question in any particular org probably takes up a lot of the time of any competent and properly staffed CISO office.
But, basically, the only mechanisms in play are some combination of limiting access and, where that's not possible, decreasing employees' ability/incentive to defect.
This is a bit like the question how to have a system that promotes honest, smart politicians. As you might guess, nobody has figured that out yet.
Ultimately the only way is an omniscient, omnipresent CEO who does all the important stuff alone. Which is probably the core reason why no one has leaked God's files on the Universe, yet.
Oh yeah let's talk about how perfect is the enemy of better, when discussing an idea to bury victims of ransomware into the ground with government penalties on top of ransom and leaks.
Here's another thought in the same vein: let's penalize rape victims for attracting male gaze and not fighting sufficiently to avert contact. Sure, some women will get raped still, but let's not let perfect be the enemy of better. That's how they deal with it in some countries actually. They blame the victim. It doesn't reduce rape at all. In fact it reduces reported rape, because women don't want to face the legal and family repercussions of getting raped.
Let me tell you what will happen in the case of ransomware.
1. You get hit by ransomware.
2. Previously you'd ponder contacting authorities. Nope. They're gonna close your options and fine you either way. Keep your mouth shut.
3. Pay as quickly as possible and hope the word never comes out you were blackmailed at all. As far as the world and the government know, your security is fine, nothing happened. No fines, no lawsuits.
4. Result: ransomware proliferates and grows into the biggest organized crime organizations of this century.
How's that about not letting perfect be the enemy of better?
...In most cases, the CEO and probably a huge number of people in upper management can do any number of things to nuke a company from orbit. But this doesn't happen very often. The things that those people can do to nuke a company from orbit are typically tightly controlled functions, and the people with those responsibilities are carefully selected and extremely well-compensated.
Yes, some employees need to be absolutely trusted. No, you don't need to absolutely trust every employee (or even most employees).
Turning to your Snowden example, if you're a TLA and find yourself completely owned by an outside contractor making low six fiures, then you've utterly failed and managing insider risk.
Think carefully if you care how someone stole the data. Or you care more about how likely it is to steal the data. I can argue that penalizing companies for being blackmailed in fact encourages less cooperation with authorities, which encourages more people to blackmail them
No necessary so as the company may just pay for insurance from future attacks. Granted insurance companies then will demand some compliance with security check lists, but this feedback loop is very slow.
Then the incentive is to avoid becoming a victim to ransomware in the first place by making it more cost effective to hire decent security than to take the risk and end up getting targeted.
Sounds good to me. Why should companies be allowed to save money by exposing our personal data and then pay for it by funding terrorist organizations, organized crime, and totalitarian governments?
Why do you assume that it is personal data that are at risk? Maybe it is your new super-duper tech that hackers will threaten to leak to the rest of the world?
That's the first-order effect. The second-order effect is companies paying less to ransomware creators, making it a worse business to be in. Over time this should result in less business pain.
This will ultimately just create a larger market for ransomware insurance. Insurance premiums are likely the lowest cost compared to 1) paying the fines or 2) actually improving security.
Most businesses already have some form of insurance covering their liability in these situations and those will just price in whatever fines might need to be paid.
> This will ultimately just create a larger market for ransomware insurance.
CEO of Swiss Re to said this[1]:
> He observed that the cyber insurance market is currently worth around $5.5 billion in premium, compared to “gigantic” yearly losses that extend into the hundreds of billions of dollars.
“There’s a cyber market that’s very tiny compared to the total exposure,” he told CNBC. “It’s going to grow but only a tiny minority of cyber is actually insured.”
“And I would actually argue that overall the problem is so big it’s not insurable,” Mumenthaler continued. It’s just too big. Because there are events that can happen at the same time everywhere that are much more worrying than what you just saw.”
Option:
3. Pay your IT/Security department or hire a consultant
Pay for licenses and updates of software and hardware
Don't expect job of 5 people to be done by 1
Don't let bunch of trainees run your infra
Government should make companies pay even more so other companies understand what the proper way to "not getting ransomed" is or spend money finding out. Instead of money going god knows where to finance god knows what.
SolarWinds was blaming some intern for a bad password, if it would be up to me, I would close down whole company for such utter bullshit. I understand at their scale it is still possible to have some loose ends but no one was doing any audits, no one was doing any security awareness? I bet you could blame at least 10 managers there for not even thinking about security and not some intern.
The government's proposal:
1. If you pay the hacker, we want money because you paid a hacker.
2. If you don't pay the hacker, we want money because you leaked your users' data.
The bottom-line is that if you're a victim of ransomware, the government joins the hacker, both of them kicking you while you're down and demanding money.