(Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)
(Of course, a year or so pre-warning of this kind of law would be required to allow for companies to lock their data down.)
Compare this to a street crime: One might say that muggers would be deterred if it were illegal for their victims to cooperate; if you have to fight back instead of handing over your wallet. But, at what cost for the victims?
If we don’t think that companies are doing enough to protect their systems, then we should pass laws that require certain demonstrable standards at all times. We shouldn’t wait for them to become a victim before the law requires them to do anything. It’s too indirect and situationally unaware of a solution.
I think laws should be written so it’s easy to know when you’re in compliance, and easy to know when you’re not. “Don’t get hacked” is basically an impossible moving target, particularly for small organizations. “Follow these best practices” is a much more reasonable standard. And we already have government organizations that put together standards for this, all lawmakers need to do is cite them.
That's not to say it shouldn't also be made illegal or in some other way difficult to pay (they could, for example, ban crypto currency use for the purpose of paying ransoms, or whatever-- just tossing out ideas)
Banning ransoms alone isn't going to work. Companies already have liability for things like customer data breaches, and that hasn't eliminated them. We also need some sort of legal framework-- especially for large pieces of infrastructure-- for defining appropriate security procedures that must be followed. Also tie it to the ability to get government subsidies/grants etc. That's how it works in Higher Education: If colleges don't adhere to to DoE regs, they simply can't accept financial aid money given to students by the government. It's actually something that's audited with fines levied on a regular basis. Few schools if any ever lose the ability to get aid, but that's because the regs are enforced and fines are high enough to hurt.
Really though I don't think you can stop this completely. We might say "every company can afford to get security right" etc., but they won't: Some will barely even try, others will simply be unlucky and out of 3,000 employees, one will slip up. The nature of this sort of attack is that on defense, you have to be 100% successful all of the time or you're done, and always having a perfect record is not a realistic expectation for all organizations.
The problem is that for the hackers, this is a low risk, inexpensive, high reward process. As much as security has to improve, so does that equation. If there was a physical attack that shutdown the pipeline it would easily be labelled an act of terrorism, and these should be seen the same way, with the same level of resources used to go after anyone involved in these attacks.
https://www.bloomberg.com/news/articles/2021-05-13/colonial-...
The US Treasury Office of Foreign Assets Control specifically warns about the legal risk you take by paying a ransom here: https://home.treasury.gov/system/files/126/ofac_ransomware_a...
If you can't buy the coins, you can't pay the ransom.
But hey, I guess you could use cryptocurrency to pay the runners.