You are running the company. You spend all your life getting to CEO position. And then boom breach and your company has massive loss, lawsuits and you are out of the job. Probably 9/10 CEO types will just engage in a crime to avoid that situation.
Current situation is way better. All breaches are public, prices are public, so the correct answer is to invest in security and if you get caught with your pants down, just pay the fee Let justice department handle it from that point on.
The way bank robberies are handled is the best. Just give them everything they ask for. In the end of the day it is either insured and even if it is not, it is stupid to risk anyones life for money created in fractional-reserve banking system.
It's somewhat more difficult for actual businesses to buy drugs, though, isn't it? The money would show up in audits and all that.
If drugs distributor has money in cash, they will probably engage in loaning short-term to ligitimate businessses with very predictable massive cashflows that pay in cash: construction, cleaning, farming, gambling etc. They don't even have to pay in cash, as long as they have cash receivables that will work as well.
They probably called something like Farming Loans Inc and deliver cash in the beginning of the month for business to meet their cash requirements. They either use it to pay their workers or will just deposit into their account as revenue. Month later they just send me back the check,that is loan pay back that is 100% clean money.
Obviously they will need to manage Farming Loans Inc balance sheet to explain where the seed money for loans are coming from, but that's where white colar crime comes in, where not so good accountants and lawyers will cook books.
For ransom money, the system will be even more cleaner. Somebody will create offshore consulting security firm, that will engage clients in return for consulting fees. So if somebody has breach, they will call them and like we need some consulting. Consulting firm will talk to ransom guys, get keys and then bill the client. So if you accountant and look at the balance sheet of multimillion dollar company, you will see consulting fee invoice and that is pretty much it. For IRS or FBI to dig any evidence, they will have to get a whistleblower plus somehow get the documents of offshore company, which makes it impossible.
In the end of the day white colar crime is 100x bigger then anything to do with drugs/ ransomware and it starts early, because the system pushes people to behave this way and 100% trust base and a lot of behaviours are 100% legal.
The good example is retail brokerage companies that encourage day trading, options trading, FX pares trading. This is just a scam, but hey why not.
I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know that there’s no proof these attackers acted in good faith past the actual decryption, but now CWT can at least say they attempted to recover lost data.
I think we can only realistically hold companies liable for transactions like this when we have better government resourcing and oversight. Getting the FBI involved in stuff like this is difficult, as they’re over loaded with such cases.
I also feel we should never hold individuals liable for stuff like this. It’s unreasonable to expect people who aren’t security professionals to know how to defend or respond to threats like this given how rapidly the landscape changes.
Figuring out a good way to holistically deal with cyber criminals will probably be a problem we struggle with for years, if not decades.
1. Taxing only the victims is adding salt to a wound: these companies are already hurting from being attacked, lost money to the ransomer, and are likely to lose more shortly thereafter due to bad PR. They'll need this money to fix things and hire/consult appropriate experts.
2. Taxing all parties likely to be hit by stuff like this spread the financial burden amount companies of all sizes. Larger companies/targets can thus help protect smaller outfits that aren't well enough funded to field a robust security team or program.
3. Some kind of revenue stream is required here to beef up federal/regional programs relating to cybersecurity. There's no real source of funding for this that doesn't come out of a larger budget. The scope of the problem is large enough that I feel it justifies a specialized agency with it's own budget. Having a dedicated tax applied to parties with need for the service/support seems fair and progressive to me.
Jokes aside, I absolutely agree that this is a failure of the US federal government and congress. We should have answers for these things for now, or at least the beginnings of a national security program to combat cyber crime. The FBI is seriously overwhelmed and the other three letter agencies can't be bothered to play the blue team as far as I'm aware.
Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.
Uh, have you looked at all the corporate scandals of the last, say, 40 years?
White collar execs never do hard time anyway. At the absolute worst they get 6 months at some cushy minimum security... aka Club Fed.
But really, I expect such a law would provide for exceptions, with a maximum payout capability. And for such a law to come after an offsite airgap backup requirement for such entities.
But really, the answer is that the equivalent physical criminal action: walking into a hospital and absconding with all of their medical records, would result in criminal action against the thief. Their actions may be akin to manslaughter if deaths result.
[1]: https://www.ucsf.edu/news/2020/06/417911/update-it-security-...
Cut deeply enough - take out entire companies - and people lose their jobs.
People can't eat. People lose their health insurance that allows them to afford their life-saving medication.
At some point, it's not just "big corporations"; it's the people that work for them, too.
Only in one country on the planet.
Now take this scenario to every major financial crisis (e.g. USA today, Latin America for the past couple of decades, some EU countries hit 20-30% unemployment a decade ago, and are still recovering).
It won't kill them instantly but consider what it does to them, if it turns them to crime, alcoholism, depression, and the general impact on the quality of life.
There's a very specific value of human life: https://www.npr.org/transcripts/835571843
The idea that there are fundamental differences between human lives and corporate assets is flawed. There's a very specific value of human life: https://www.npr.org/transcripts/835571843
Human life appreciates the same way. In some number of years the government will decide that the economy can sustain valuing human life at a trillion dollars. And they'll look back at us and see that we undervalued life in the same way that we can look back and see that the Romans undervalued human life. Lives are worth whatever we can afford.
They said they saw a difference.
They didn’t say other people didn’t see a difference.
Which would be the point, that there are no fundamental differences between corporate assets and human lives.
You seem to think they said that ‘everyone sees a difference’. They didn’t. They said ‘I see a difference’. They’re only ‘wrong’ about that if you think they’re lying to us about their own personal position.
Thank you for your logic lesson but I fail to see how this changes the discussion.
Our current legal framework doesn’t support such a draconian suggestion as presented imho.
You want poor security practices to be painful, not fatal, to the corporate entity.
I’ve done a lot of infrastructure work, so my home network is...robust. Quite unusual; even for many corporations.
Two DMZs, three routers, three WiFi networks, two NAS units, etc. Also lots of redundant backups.
Banning ransomware payments just makes it more difficult; someone will still find a way to save their business by paying. You want to resolve the root issue: a business not taking security seriously.
Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations, I really don't have a problem with them going under. It's less burdensome than being compliant with the local tax code, which all businesses have to do already.
Incorrect. The black hats almost always encrypt backups, too. You could say "what about offline, glacial backups?" But then you're no longer talking about "the simplest of backup solutions"
How many people you meet everyday that are not in IT even knows what offline redundancy means?
I think what your suggestion amounts to, is effectively a mandate on SMBs having either an in house security team, or a contract with a consultancy on cyber security. That's a huge burden. It's not really easier than local tax code. These things change much more frequently and it's not like you can just walk into a local H&R Block to take care of your cybersecurity needs. Ransomeware, as it is now, didn't even exist (or is that popular) 10 years ago.
A big part of the threat is the disclosure of sensitive data that they exfiltrated. Backups don't help this.
Not to mention that the pros delay encryption until they've managed to screw up backups, too.
Even though not paying the ransom is recommended, some companies are instead paying the ransom as part of their insurance coverage. For example, earlier this year Lake City, Florida was a victim of a ransomware attack. After receiving approval from their insurer. Lake City paid $460,000 in order to restore their systems. Since they had cyber insurance, the city only had to pay a $10,000 deductible.
It shouldn't be the criminals penalizing them, but here they are filling the gap that the regulators ignored.