Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Edge Articles

12:15 PM
Joan Goodchild
Joan Goodchild
Edge Features

10 Mistakes Companies Make In Their Ransomware Responses

Hit by ransomware? These missteps can take a bad scenario and make it even worse.

(Image: Prostock-studio via Adobe Stock)
(Image: Prostock-studio via Adobe Stock)

From the headline-making incident in May that impacted Colonial Pipeline to this month's hit on Kaseya, ransomware attacks have been nothing short of a plague on businesses in recent months. While they aren't new, they are certainly capturing the public's attention and raising eyebrows among lawmakers.

To pay or not to pay the ransom is a hotly debated issue. While most security professionals oppose paying, in certain situations it might make the most sense.

"Everyone says 'no,' but it really depends on a case-by-case basis," says Steven Schwartz, director of security consulting at Eze Castle Integration. "At the end of the day, you need to get the business back up and running. Colonial paid nearly $5 million in ransom to decrypt its computers. That was a business decision – they needed to get their pipeline back up and running." 

Payment is just one of many issues to contend with while under the duress of a ransomware attack. Following are some of the common mistakes organizations make when it comes to ransomware response.

Joan Goodchild is a veteran journalist, editor, and writer who has been covering security for more than a decade. She has written for several publications and previously served as editor-in-chief for CSO Online. View Full Bio
1 of 11
Print  | 
More Insights
Flash Poll