US mayors adopt resolution to not pay hackers over ransomware attacks
cnet.com
cnet.com
They should have passed a resolution to implement a 1-2-3 Backup Strategy with mandatory offline & offsite backups and testing protocols. But that would cost money and require competent management/oversight, instead they'd prefer to pass a meaningless fiat that won't do jack.
Honestly until there are consequences for government officials/management nothing will change. This is 95% about poor resource management and 5% about CrytoMalware. Nobody should be paying, because they should ALREADY have multiple tiers of backups, that are audited, tested, and reviewed.
PS - "It also encrypted our backups" is also pure incompetence. They just didn't want to manage rotated backups or pay the storage fee/costs of high density tape.
So backup is a fairly big management & IT challenge that goes way beyond guidelines like 1-2-3. That, and due to legal restrictions, local governments are rarely empowered to hire the right IT staff capable of making it happen.
So no user education, desktop administration, or specific policies are required. You just need not to alter the defaults and you'll get a centrally managed set of user files perfectly suited to regular backups.
The only thing that remains a challenge is offsite users/traveling. But an edge case isn't a justification for why you wouldn't use folder redirection within a monolithic organization like a local government.
> That, and due to legal restrictions, local governments are rarely empowered to hire the right IT staff capable of making it happen.
What "legal restrictions" stop government from hiring IT Staff?
This has to be set up and configured, it is not default by any means. That and most places I have seen a mix of macOS and Windows, and people use their personal devices all the time, or put something in DropBox / Google Drive etc to share things, etc. This is not a button to press.
> What "legal restrictions" stop government from hiring IT Staff?
Have you seen IT budgets in local government? That, and salary guidelines set by law. It's not a simple question of whether or not it's possible to hire IT staff, but a question of whether you can pay enough to attract the talent you need, whether you can afford the opex+capex for the level of service you think is standard, etc.
When I've worked at larger organizations like universities, things were usually handled very well with everything set up the way you describe, automated, and hands-off. But there's a lot of variation when it comes to things like city governments.
If you use the GPO templates it absolutely is the default. You have to go out of your way to turn it off (and some people do for both good and bad reasons).
> whether you can pay enough to attract the talent you need, whether you can afford the opex+capex for the level of service you think is standard, etc.
Luckily a 3-2-1 backup strategy doesn't require top tier talent. It is mostly policy, costs, and time. You could literally have an intern do it if the business took the time to set a policy and buy the prerequisites.
The difficult part has always been getting business/government buy-in because they'd prefer to be apathetic until something goes wrong or under-spend on something that won't pay dividend immediately.
Talk to government IT some time. I've worked in that environment. There's no lack of talent, there's a lack of funds for things like backups and nobody in management (political appointed or otherwise) wants to make actual decisions/do any managing. I had colleagues "borrow" a spare HDD, copy the data off onto it, then take it home with them because that was the only backup an entire County had (because nothing else was funded/authorized).
You can try to bike-shed/excuse this issue away, but at its core it is managerial incompetence/apathy. If they wanted the money for it, they'd find it, if they wanted the time to produce policy they'd find it, and if there was real consequences to their incompetence you can bet they would have already.
Even banks are moving from vendor managed solutions to cloud based in-house supported software of late, and this group is the most difficult to change their ways (lot-o-hoops).
I do agree with you that many biz/org's might pay for a system and fail to understand the costs around maintaining/future upgrading - that's a management issue and should be dealt with via accountability/consequences.
It could probably even work quarterly without too much lost productivity...
Then again, doing it weekly might work out such that you get really good and fast at doing these wipes, so it becomes unnoticed.
Hmmm, maybe we should review these annual plans...
You redirect a user's folders to the network share, and people get used to it fairly quickly.
I'm mostly saying this out loud for the chance someone will point out an issue or optimization for my strategy.
It is cheaper that way. :D
https://www.zdnet.com/article/georgia-county-pays-a-whopping...
Malware is not a single target attack. Whether or not it's probably beneficial to attack one of these cities is not considered. Instead of making gestures, these mayors should be investing in better cybersecurity.
If the malware author manages to infiltrate your network and quietly starts infecting files and devices on your network over 6 months, even if you restore from a 7 month old backup, what about all of the files that were created between then and now -- are they all going to be recoverable even if you can find and remove the malware? Can you reliably detect all of the malware or will the attack sprout again from your printer in a few months?
I assume the malware fucks stole a copy to auction off.
just having the software won't do you any good
paying the ransom ware folks should be considered the cost of doing business. it’s cheaper than actually securing the data.
anyway it’s expected. the same mayors that underfund IT would be the same ones to make this ridiculous “red line”.
good opportunity here for a cookie cutter IT consultancy to come in to all of these cities and offer cookie cutter service.
If they can't afford to have good backups of their data, they can't afford to have digital records in the first place. This is the equivalent of a community saying they can't afford filing cabinets so they just stack paper on the floor in the boiler room. Nobody would find that acceptable, and they shouldn't find this acceptable either.