BOOK AN APPOINTMENT WITH AN IT SPECIALIST TODAY

Should Government Pay Ransomware?

An IBM Security study found that 60 percent of respondents opposed local governments paying ransomware. Read on to learn more about the implications.  

Government Ransomware

Ransomware attacks are on the rise, and U.S. taxpayers are divided on the issue of who should pay the hackers to recover the data. An IBM Security study surveyed 2,200 U.S. citizens on their understanding of and willingness to fund cybercrime recovery efforts. The respondents also gave their opinion on actions taken by the government to prevent and respond to cyberattacks.

The study found that:

  • 75% of the respondents were concerned about having their personal data held for ransom.
  • About 80% feared the impact of ransomware attacks on U.S. cities.
  • About 60% of U.S. citizens surveyed opposed their local governments using tax dollars to pay the ransom.
  • 60% of respondents preferred their city use tax dollars to fund recovery efforts rather than pay ransom.
  • More than 30% of taxpayers surveyed opposed paying to help emergency services, police departments and schools hit by a cyberattack. In addition, many of those willing to pay would only do so if restoration costs were less than $50,000.
  • About 40% of respondents specifically opposed to providing financial assistance to police departments and public schools.
  • About 90% of taxpayers surveyed supported an increase in federal funding to help local governments improve cybersecurity. In addition, more than 75% of responding citizens supported federal reimbursement to help cities already hit by cyberattacks deal with ongoing recovery efforts.

Can We Stop Cyberattacks?

While there’s no way to eliminate cybercrime completely, preparedness can drastically reduce its incidence. That starts with a collaborative effort from cybersecurity providers, local governments, businesses, and individuals.

Organizations must implement a comprehensive cybersecurity plan that includes recognizing red flags and responding to an attack. The vast majority of cities and businesses hit by attacks failed to take precautions and had no response plan. Understanding how hackers operate and what steps to take to minimize risk is crucial. Helpful precautions include:

  • Choosing strong passwords consisting of lower and uppercase letters, numbers, and symbols
  • Doing research before installing third-party applications
  • Backing up data on an external drive or through a cloud service
  • Keeping operating systems and software up to date
  • Recognizing malicious phishing emails
  • Using multi-factor authentication to access personal accounts

Prevention is the Best Cure

There is a widespread misunderstanding that paying a ransom will restore stolen data. Hackers often take the money without honoring their promise, leaving the victims deeper in the hole. Paying ransoms only guarantees future cyberattacks with higher demands. Even if the hacker agrees to release the data, the victims must still spend time and effort to restore each compromised device and conduct security audits. The high price of ransomware coupled with the untrustworthiness of the hackers make prevention the much better option.

As cybercriminals continue to ramp up attacks on cities and small businesses, cybersecurity is a must. By taking the proper precautions and learning how to recognize signs of malicious activity, individuals and organizations can help thwart hackers and reduce their risk of having their data held for ransom.

More Like This

AA20-227A: Phishing Emails Used to Deploy KONNI Malware

Original release date: August 14, 2020 Summary This Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise framework for all referenced threat actor techniques. The Cybersecurity and Infrastructure Security Agency (CISA) has observed cyber actors using emails containing a Microsoft Word document with a malicious Visual Basic …

AA20-227A: Phishing Emails Used to Deploy KONNI Malware Read More »

Read More

AA20-225A: Malicious Cyber Actor Spoofing COVID-19 Loan Relief Webpage via Phishing Emails

Original release date: August 12, 2020 Summary The Cybersecurity and Infrastructure Security Agency (CISA) is currently tracking an unknown malicious cyber actor who is spoofing the Small Business Administration (SBA) COVID-19 loan relief webpage via phishing emails. These emails include a malicious link to the spoofed SBA website that the cyber actor is using for …

AA20-225A: Malicious Cyber Actor Spoofing COVID-19 Loan Relief Webpage via Phishing Emails Read More »

Read More

AA20-209A: Potential Legacy Risk from Malware Targeting QNAP NAS Devices

Original release date: July 27, 2020 Summary This is a joint alert from the United States Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). CISA and NCSC are investigating a strain of malware known as QSnatch, which attackers used in late 2019 to target Network Attached Storage (NAS) …

AA20-209A: Potential Legacy Risk from Malware Targeting QNAP NAS Devices Read More »

Read More

AA20-206A: Threat Actor Exploitation of F5 BIG-IP CVE-2020-5902

Original release date: July 24, 2020 Summary The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this alert in response to recently disclosed exploits that target F5 BIG-IP devices that are vulnerable to CVE-2020-5902. F5 Networks, Inc. (F5) released a patch for CVE-2020-5902 on June 30, 2020.[1] Unpatched F5 BIG-IP devices are an attractive target …

AA20-206A: Threat Actor Exploitation of F5 BIG-IP CVE-2020-5902 Read More »

Read More

AA20-205A: NSA and CISA Recommend Immediate Actions to Reduce Exposure Across Operational Technologies and Control Systems

Original release date: July 23, 2020 Summary Note: This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise and ATT&CK for Industrial Control Systems frameworks for all referenced threat actor techniques and mitigations. Over recent months, cyber actors have demonstrated their continued willingness to conduct malicious cyber activity …

AA20-205A: NSA and CISA Recommend Immediate Actions to Reduce Exposure Across Operational Technologies and Control Systems Read More »

Read More

AA20-198A: Malicious Cyber Actor Use of Network Tunneling and Spoofing to Obfuscate Geolocation

Original release date: July 16, 2020 Summary This Activity Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK™) and Pre-ATT&CK frameworks. See the MITRE ATT&CK for Enterprise and Pre-ATT&CK frameworks for referenced threat actor techniques. Attributing malicious cyber activity that uses network tunneling and spoofing techniques to a specific threat actor is difficult. …

AA20-198A: Malicious Cyber Actor Use of Network Tunneling and Spoofing to Obfuscate Geolocation Read More »

Read More