It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, we've had Grafana go with the "no pay" approach, and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom". I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which really waters down the severity of the whole thing. It looks like, for the time being, "pay or leak" is the new norm... along with nonsensical statements like "the data was returned to us" 🤷♂️
Weekly update- Homepage
- International
- Weekly Update 504
Related
Name That Toon: Mark of (Cybersecurity) Progress
11 hours ago
2
Asia's Cyber Insurance Market Shows Signs of Life
17 hours ago
5
'The Com' Cyberattacks Support Violence & Sexploitation
20 hours ago
5
Name That Toon Contest
1 day ago
13
Dutch Raid Fails to Dent Russian Bulletproof Host
1 day ago
14
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
1 day ago
17






.png?width=1280&auto=webp&quality=80&disable=upscale)



