Cybersecurity As Management Fuction Example: Ransomware
At Pythia Cyber we keep bumping into managers and leaders who are surprised to hear that cybersecurity (C/S) isn't an IT function. At least they pretend to be surprised. We suspect that they really want C/S to be an IT function because then they wouldn't have to take any responsibility for it.
As we have written about before, part of this reluctance to embrace C/S comes from fear of the unknown: most managers and leaders are quite familiar with accounting, marketing, sales, legal and HR. They are not familiar with C/S.
Part of this reluctance comes from fear of the scary way in which C/S is presented, as an arcane dark technological enterprise marrying crime and science. Hooded figures in the dark type away on black keyboards, surrounded by so many monitors, all of which have green text on a black background.
As we will see in a subsequent post, this image is the result of laziness and fatigue. In this post we will give a counter example that any business person can understand: a policy of just paying the ransom when attacked by ransomware.
To our dismay, we see a number of organizations respond to the threat of ransomware this way:
- Make a policy of just paying the ransom.
- Budget for ransom payments, usually with a bogus name and in cryptocurrency.
- Wait for the next attack.
- Pay the ransom with the budgeted crytocurrency.
- Budget more money for next time.
Note that this process involves IT at no point. While we are not very pleased with the outcome, we applaud the process which, ironically, is more-or-less NIST CSF compliant:
- Identify asset & risk: the system to be held for ransom.
- Protect asset: put aside money to pay the ranom.
- Detect the problem: the ransomware does this for you.
- Respond to the problem: pay the ransom.
- Recover from the problem: set aside money for next time.
Try to put this on IT, we dare you. IT doesn't make this kind of policy. IT doesn't set organizational priorities or allocate resources. IT doesn't have the authority to release funds.
Here is a prime example of C/S which is clearly not an IT function at all, but a leadership function.
Don't hide behind the unknown. Don't refuse to leave your comfort zone. C/S probably touches your areas of responsibility somehow. Find out how and do your part. Figuring out where the lines are can be difficult. We can help. Ask us how.
PS is paying the ransom illegal in the US? The answer is "probably not," at least according to Google's AI summary: Paying ransomware is not outright illegal under federal law in the United States, but it can become illegal if the payment violates government sanctions. [1, 2]
Comments
Post a Comment