News: 1715153475

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

(2024/05/08)


Interview This year is an unfortunate anniversary for information security: We're told it's a decade since ransomware started infecting corporations.

Extortionists had been hitting normal folk in the early 2010s with file-scrambling malware. Eventually criminals figured out that there was much more money to be made hitting business networks and demanding big bucks. Since then, attacks have soared, show no sign of letting up, and the computer security industry still hasn't found a full and final fix.

Mikko Hyppönen, chief research officer at WithSecure and all-round infosec industry veteran, will give a [1]keynote talk at the RSA Conference in San Francisco today on just this topic – and he's not optimistic. Growth in both the number of attacks and the value of Bitcoin has created criminal unicorns with net worth in the billions, as he explains in the video below.

[2]

[3]Youtube Video

[4]

He argued that while certain sectors such as government and healthcare are certainly attractive to extortionists, these criminals will go for the lowest-hanging fruit, meaning poorly secured IT environments are just as tempting. And it's increasingly hard for victims not to pay up when they see their stolen corporate data leaking online.

There is one bright light on the horizon, for security folks at least: If you work in the industry, and you're good at it, then it looks like you've got a job for life. ®

Get our [5]Tech Resources



[1] https://www.rsaconference.com/usa/agenda/session/The-First-Decade-of-Corporate-Ransomware

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjtNQiCb46g3C5QIpmCmpwAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.youtube.com/watch?v=bwWkeK-_3Pc

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjtNQiCb46g3C5QIpmCmpwAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://whitepapers.theregister.com/



Not sure I'd want the job

Andy Non

"There is one bright light on the horizon, for security folks at least: If you work in the industry, and you're good at it, then it looks like you've got a job for life."

It assumes you are given the budget to do the job properly and we increasingly hear of the bean-counters seeing money spent in this direction as non-productive so inadequate resources are made available and there is also a lack of pen testing.

Secondly you've got to be at the top of your game all the time, ensure all patches are applied in a timely manner, staff are properly educated against phishing attempts etc. You've got to block and deal with every attempted intrusion, while the scumbags have only got to succeed once for you to be considered to have failed in your role.

Don't think I'd want the stress - or to deal with any politics, intransigent management and indifferent users.

Patrician

"staff are properly educated against phishing attempts"

This is the biggest problem, despite the training users till click links they shouldn't or open attachments....

Andy Non

I agree. I'm surprised that after all these years users still have unfettered access to open random attachments or click random links. A security conscious environment I worked at twenty years ago blocked such access as well as disabling users from plugging in random USB sticks etc. Special permissions had to be approved on a case by case basis by IT security to access potentially hazardous email attachments. Even incoming physical mail and parcels were scanned and searched for anything suspicious.

Unfortunately it still leaves open the risk of gullible users falling for phishing scams by convincing and assertive callers. In mitigation, to a certain extent, the users should be restricted to access only what they need to do their job and nothing more.

A person forgives only when they are in the wrong.