Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
55% of SMBs Would Pay Up Post-Ransomware Attack
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2019 | 4:16:44 PM
Re: Unbelieveable
But I guess companies are still waiting to be burnt by the stove unfortunately. This makes sense. I think it identifies the major problem we face. No action unless got hit.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2019 | 4:14:32 PM
Re: Unbelieveable
t's amazing how much headache you can forgo if you have a DR plan. Sometime a DR plan may not save us. You should be able to get data back, historical data may be encrypted too.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2019 | 4:12:47 PM
Re: Unbelieveable
I saved a museum I supported by HAVING a good plan and using it so that within 3 hours 98% of everything was back. That is good. Everybody needs a backup plant that goes against a ransomware attack. They should be able to go back as much past as needed.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2019 | 4:10:24 PM
Re: Unbelieveable
Proof positive that small business IT lacks the brains to come up with a good disaster recovery plan. This makes very good sense. If they do not have a backup to go then they loose data and that is a bigger problem.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
4/28/2019 | 4:08:43 PM
Anternative?
Security experts typically advise against paying for stolen data after ransomware attacks, but 55% of executives at small to midsize businesses say they would do exactly that. That may be because they do not have an alternative?
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/26/2019 | 9:52:54 AM
Re: Unbelieveable
About 18 years ago on a lovely September morning, my data center crashed 103 floors along with the building and I was lucky to get down from the 101st floor. South tower.  So I am big into disaster recovery.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/26/2019 | 9:26:56 AM
Re: Unbelieveable
Agree. It's amazing how much headache you can forgo if you have a DR plan. It still amazes me that this solution has been evident for so long and still many are resistant to implement. It has more than just security benefits but data preservation benefits as you have pointed out. 

But I guess companies are still waiting to be burnt by the stove unfortunately.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/25/2019 | 3:36:26 PM
Unbelieveable
Proof positive that small business IT lacks the brains to come up with a good disaster recovery plan.  What if a server itself crashes --- then all data is "encrypted" really good on a dead drive or system.  So WHO would you pay to restore that?  I saved a museum I supported by HAVING a good plan and using it so that within 3 hours 98% of everything was back.  I mean - COME ON, GET WITH THE PROGRAM.   There is way too much of this and everytime a ransomware story comes up---- PAY and that solves the issue  Incredible.  


Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31769
PUBLISHED: 2021-06-21
MyQ Server in MyQ X Smart before 8.2 allows remote code execution by unprivileged users because administrative session data can be read in the %PROGRAMFILES%\MyQ\PHP\Sessions directory. The "Select server file" feature is only intended for administrators but actually does not require autho...
CVE-2020-20469
PUBLISHED: 2021-06-21
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20470
PUBLISHED: 2021-06-21
White Shark System (WSS) 1.3.2 has web site physical path leakage vulnerability.
CVE-2020-20471
PUBLISHED: 2021-06-21
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.
CVE-2020-20472
PUBLISHED: 2021-06-21
White Shark System (WSS) 1.3.2 has a sensitive information disclosure vulnerability. The if_get_addbook.php file does not have an authentication operation. Remote attackers can obtain username information for all users of the current site.