TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
IT Security

To pay or not to pay?

by Mark Rowe

We are in a vicious cycle of ransomware payments leading to more attacks, and more payments, says James Watts, Managing Director at the IT disaster recovery services company Databarracks. Watts said: “Ransomware must be addressed as a global, societal issue. It is like the โ€™tragedy of the commonsโ€™. Individuals acting independently in their own best interest against the common good. A business might think they are right to pay the ransom to minimise their costs, but when thousands of organisations do the same, they feed into that vicious cycle.

โ€œAn outright ban is attractive because it would break the cycle. But although itโ€™s a good argument, in practice it will lead to organisations going out of business or being unable to serve their customers, patients and citizens. That is not a viable situation.

โ€œAustralia came close to banning payment before ultimately backing down. The closest to a โ€˜banโ€™ in several countries is a restriction on payments to terrorist organisations โ€“ although often it is not possible for the victim to know exactly who the attacker is.

โ€œThe best route for organisations is to be able to choose not to make the payment. In order to do that, they first need to have an air-gapped, immutable backup that canโ€™t be compromised. They also need to want to refuse the ransom. In some cases, the ransom will cost less than carrying out your own recovery.

โ€œWithout legislation and left to make decisions independently, some organisations will opt for the lower cost ransom payment rather than the hard work of recovery. The way to influence that behaviour is through cyber insurance. If your insurer tells you that your losses are only covered if you recover your systems and business rather than paying the attacker, organisations are guided to make the right choice.

โ€œCyber insurance is one of the few levers that can impact ransomware payments. For it to help raise the base level of preparedness, uptake needs to increase too. It is positive to see that despite the increase in cost and demand, the number of organisations with cyber insurance has also increased.”

Infosec talks

Ransomware is the topic numerous times over the three days of the conference inside the Infosecurity Europe 2024 show at Excel in London Docklands. Speakers on day one, Tuesday, June 4 include Insp Charlie Morrison, Cyber Griffin – City of London Police; day two, Martin Zugec, Technical Solutions Director, Bitdefender; and on the keynote stage on the final morning, a panel including Gareth Bateman, UK Cyber Growth Leader, Marsh; Jon Davies, Senior Director – Cyber Defense, News Corp; and Det Supt Paul Peters, Managing Director of the Cyber Resilience Centre for Wales. Visit https://www.infosecurityeurope.com/.