<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dude, Just Pay the Ransom... in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27364#M1729</link>
    <description>&lt;P&gt;I was actually a bit surprised that the insurers were willing to pay the ransom.&amp;nbsp; It seemed like they are paying out for poor security on the part of their clients.&amp;nbsp; This is actually something I've seen a few times with companies who think they can get cybersecurity insurance INSTEAD of addressing their shortcomings in security (lack of policies/procedures, lack of systems to detect/prevent issues, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would think that most cybersecurity insurances would require measures be in place.&amp;nbsp; Or at least to get better rates (similar to getting better home owner insurance rates if you have alarms, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess we'll see how this shakes out.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2019 16:49:58 GMT</pubDate>
    <dc:creator>emb021</dc:creator>
    <dc:date>2019-08-28T16:49:58Z</dc:date>
    <item>
      <title>Dude, Just Pay the Ransom...</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27363#M1728</link>
      <description>&lt;P&gt;That's the phrase echoing in city hall council chambers across America. Many municipalities &lt;A href="https://arstechnica.com/information-technology/2019/08/how-insurance-companies-are-fueling-a-rise-in-ransomware-attacks/" target="_blank" rel="noopener"&gt;choose to pay&lt;/A&gt; and get back to business.When will the madness end in Texas? Sure deductibles are a small price to pay, but just wait until cyber insurance premiums go through the roof. Then who are you going to call?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 16:31:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27363#M1728</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2019-08-28T16:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dude, Just Pay the Ransom...</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27364#M1729</link>
      <description>&lt;P&gt;I was actually a bit surprised that the insurers were willing to pay the ransom.&amp;nbsp; It seemed like they are paying out for poor security on the part of their clients.&amp;nbsp; This is actually something I've seen a few times with companies who think they can get cybersecurity insurance INSTEAD of addressing their shortcomings in security (lack of policies/procedures, lack of systems to detect/prevent issues, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would think that most cybersecurity insurances would require measures be in place.&amp;nbsp; Or at least to get better rates (similar to getting better home owner insurance rates if you have alarms, etc).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess we'll see how this shakes out.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 16:49:58 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27364#M1729</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-08-28T16:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dude, Just Pay the Ransom...</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27379#M1737</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's look at how all the parties --- organizations, insurance providers and hackers --- fit into this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Organizations&lt;/STRONG&gt;: The objective is business continuity, while maximizing profits &amp;amp; minimizing costs. Unless they're willing to accept cyber-security risks --- or can somehow avoid them entirely --- the options are to mitigate or transfer them. If the former requires significant investment with little / no short-term ROI, the latter would be more attractive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Insurance providers&lt;/STRONG&gt;: Essentially the same objective. The more policies they sell, the higher the profits, and the fewer claims they have to cater to, the lower the costs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Hackers&lt;/STRONG&gt;: Varying objectives, achieved by targeting organizations, and --- apparently --- taking advantage of a preference for transfer over mitigation, when treating cyber-security risks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Referring to that article, I can understand why they opted to pay the ransom; but what surprised me is that it's not so hard to claim the insurance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've usually observed that while purchasing a policy is relatively easy, claiming it can often be a challenge, so I'd have assumed that organizations would only be able to avail of claims if they've met certain requirements.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To 'maintain the balance,' both hackers and insurance providers should keep their charges --- ransoms &amp;amp; policy costs --- reasonable, so that organizations stay in the game...&amp;nbsp; &amp;nbsp;&lt;img id="manwink" class="emoticon emoticon-manwink" src="https://community.isc2.org/i/smilies/16x16_man-wink.png" alt="Man Wink" title="Man Wink" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2019 21:52:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Dude-Just-Pay-the-Ransom/m-p/27379#M1737</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-08-28T21:52:32Z</dc:date>
    </item>
  </channel>
</rss>

