{"id":137883,"date":"2023-09-02T04:53:54","date_gmt":"2023-09-01T23:23:54","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=137883"},"modified":"2023-09-02T04:53:54","modified_gmt":"2023-09-01T23:23:54","slug":"an-attractive-but-dangerous-idea-cointelegraph-magazine-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/an-attractive-but-dangerous-idea-cointelegraph-magazine-crypto-news\/","title":{"rendered":"An attractive but dangerous idea \u2013 Cointelegraph Magazine &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<div>\n<p><strong>A successful cyberattack on critical infrastructure \u2014 such as electricity grids, transportation networks or healthcare systems \u2014 could cause severe disruption and put lives at risk.\u00a0<\/strong><\/p>\n<p>Our understanding of the threat is far from complete since organizations have historically not been required to report data breaches, but attacks are on the rise <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/privacyrights.org\/data-breaches\">according<\/a> to the Privacy Rights Clearinghouse. A <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-139\">recent rule<\/a> from the United States Securities and Exchange Commission should help clarify matters further by now requiring that organizations \u201cdisclose material cybersecurity incidents they experience.\u201d<\/p>\n<p>As the digital world continues to expand and integrate into every facet of society, the looming specter of cyber threats becomes increasingly more critical. Today, these cyber threats have taken the form of sophisticated ransomware attacks and debilitating data breaches, particularly targeting essential infrastructure.<\/p>\n<p>A major question coming from policymakers, however, is whether businesses faced with crippling ransomware attacks and potentially life threatening consequences should have the option to pay out large amounts of cryptocurrency to make the problem go away. Some believe ransoms be banned for fear of encouraging ever more attacks.\u00a0<\/p>\n<p>Following a major ransomware attack in <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/push-to-ban-ransomware-payments-following-australia-s-biggest-cyber-attack\">Australia<\/a>, its government has been considering a ban on paying ransoms. The <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/white-house-considers-ransom-payment-ban\/649673\/\">United States<\/a> has also more recently been exploring a ban. But other <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.afr.com\/politics\/federal\/don-t-ban-paying-cyber-ransoms-ex-us-spy-chief-warns-australia-20230806-p5du9q\">leading cybersecurity experts<\/a> argue that a ban does little to solve the root problem.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\" \/>\n<h2 id=\"h-ransomware-and-the-ethical-dilemma-of-whether-to-pay-the-ransom\">Ransomware and the ethical dilemma of whether to pay the ransom<\/h2>\n<p>At the most basic level, ransomware is simply a form of malware that encrypts the victim\u2019s data and demands a ransom for its release. A <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.chainalysis.com\/reports\/crypto-crime-midyear-2023-update-ransomware-scams\/\">recent study<\/a> by Chainalysis shows that crypto cybercrime is down by 65% over the past year, with the exception of ransomware, which saw an increase.\u00a0<\/p>\n<p>\u201cRansomware is the one form of cryptocurrency-based crime on the rise so far in 2023. In fact, ransomware attackers are on pace for their second-biggest year ever, having extorted at least $449.1 million through June,\u201d said Chainalysis.<\/p>\n<p>Even though there has been a decline in the number of crypto transactions, malicious actors have been going after larger organizations more aggressively. Chainalysis continued:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201cBig game hunting \u2014 that is, the targeting of large, deep-pocketed organizations by ransomware attackers \u2014 seems to have bounced back after a lull in 2022. At the same time, the number of successful small attacks has also grown.\u201d <\/p>\n<\/blockquote>\n<p>The crippling effect of ransomware is especially pronounced for businesses that heavily rely on data and system availability.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"370\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Cumulative-yearly-ransomware-revenue-2022-vs-2023.png\" alt=\"Cumulative yearly ransomware revenue 2022 vs 2023\" class=\"wp-image-22933\" \/><figcaption class=\"wp-element-caption\">Ransomware revenue is up. (Chainalysis)<\/figcaption><\/figure>\n<p>The dilemma of whether to pay the ransom is contentious. On one hand, paying the ransom might be seen as the quickest way to restore operations, especially when lives or livelihoods are at stake. On the other hand, succumbing to the demands of criminals creates a vicious cycle, encouraging and financing future attacks.<\/p>\n<section class=\"adv-banner adbutler-ad adbutler-ad__desktop\">\n<div class=\"container\"><!-- 1456x180 [img] --><br \/>\n<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/servedbyadbutler.com\/go2\/;ID=169476;size=728x90;setID=601214;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F\"><img decoding=\"async\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" data-lazy-src=\"https:\/\/servedbyadbutler.com\/adserve\/;ID=169476;size=728x90;setID=601214;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F;type=img\" \/><img decoding=\"async\" src=\"https:\/\/servedbyadbutler.com\/adserve\/;ID=169476;size=728x90;setID=601214;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F;type=img\" \/><\/a><\/div>\n<\/section>\n<section class=\"adv-banner adbutler-ad adbutler-ad__mobile\">\n<div class=\"container\"><!-- 600x500 [img] --><br \/>\n<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/servedbyadbutler.com\/go2\/;ID=169476;size=300x250;setID=601213;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F\"><img decoding=\"async\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" data-lazy-src=\"https:\/\/servedbyadbutler.com\/adserve\/;ID=169476;size=300x250;setID=601213;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F;type=img\" \/><img decoding=\"async\" src=\"https:\/\/servedbyadbutler.com\/adserve\/;ID=169476;size=300x250;setID=601213;referrer=https%3A%2F%2Fcointelegraph.com%2Fmagazine%2Fbanning-ransomware-payments-attractive-dangerous-idea%2F;type=img\" \/><\/a><\/div>\n<\/section>\n<p>Organizations grappling with this decision must weigh several factors, including the potential loss if operations cannot be restored promptly, the likelihood of regaining access after payment, and the broader societal implications of incentivizing cybercrime. For some, the decision is purely pragmatic; for others, it\u2019s deeply ethical.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"263\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"Breaches by org. type over time\" class=\"wp-image-22932\" data-lazy-srcset=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Breaches-by-org.-type-over-time.png 600w, https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Breaches-by-org.-type-over-time-300x132.png 300w\" data-lazy-sizes=\"(max-width: 600px) 100vw, 600px\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Breaches-by-org.-type-over-time.png\" \/><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"263\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Breaches-by-org.-type-over-time.png\" alt=\"Breaches by org. type over time\" class=\"wp-image-22932\" \/><figcaption class=\"wp-element-caption\">Attacks by organization type. (Chainalysis)<\/figcaption><\/figure>\n<h2>Should paying ransoms be banned?<\/h2>\n<p>The increasing incidence of ransomware attacks has ignited a policy debate: Should the payment of ransoms be banned? Following a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/push-to-ban-ransomware-payments-following-australia-s-biggest-cyber-attack\">major ransomware attack<\/a> on Australian consumer lender Latitude Financial, in which millions of customer records and IDs were stolen, some have begun to advocate for a ban on paying the ransom as a way of deterring attacks and depriving cybercriminals of their financial incentives.\u00a0<\/p>\n<p>In the United States, the White House has <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/white-house-considers-ransom-payment-ban\/649673\/\">voiced<\/a> its qualified support for a ban. \u201cFundamentally, money drives ransomware and for an individual entity it may be that they make a decision to pay, but for the larger problem of ransomware that is the wrong decision\u2026 We have to ask ourselves, would that be helpful more broadly if companies and others didn\u2019t make ransom payments?\u201d said Anne Neuberger, deputy national security advisor for cyber and emerging technologies in the White House.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"400\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"There are good reasons not to pay a ransom, but good reasons to pay as well\" class=\"wp-image-22935\" data-lazy-srcset=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/There-are-good-reasons-not-to-pay-a-ransom-but-good-reasons-to-pay-as-well.jpg 600w, https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/There-are-good-reasons-not-to-pay-a-ransom-but-good-reasons-to-pay-as-well-300x200.jpg 300w\" data-lazy-sizes=\"(max-width: 600px) 100vw, 600px\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/There-are-good-reasons-not-to-pay-a-ransom-but-good-reasons-to-pay-as-well.jpg\" \/><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"400\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/There-are-good-reasons-not-to-pay-a-ransom-but-good-reasons-to-pay-as-well.jpg\" alt=\"There are good reasons not to pay a ransom, but good reasons to pay as well\" class=\"wp-image-22935\" \/><figcaption class=\"wp-element-caption\"><em>There are good reasons not to pay a ransom, but good reasons to pay as well. (Pexels)<\/em><\/figcaption><\/figure>\n<p>While <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/hbr.org\/2023\/08\/how-a-federal-ban-on-ransomware-payments-could-help-cisos\">proponents argue<\/a> that it will deter criminals and reorient priorities for C-suite executives, critics, however, warn that a ban might leave victims in an untenable position, particularly when a data breach could lead to loss of life, as in the case of attacks on healthcare facilities.<\/p>\n<p>\u201cThe prevailing advice from the FBI and other law enforcement agencies is to discourage organizations from paying ransoms to attackers,\u201d Jacqueline Burns Koven, head of cyber threat intelligence for Chainalysis, tells Magazine.<\/p>\n<p>\u201cThis stance is rooted in the understanding that paying ransoms perpetuates the problem, as it incentivizes attackers to continue their malicious activities, knowing that they can effectively hold organizations hostage for financial gain. However, some situations may be exceptionally dire, where organizations and perhaps even individuals face existential threats due to ransomware attacks. In such cases, the decision to pay the ransom may be an agonizing but necessary choice. Testimony from the FBI recognizes this nuance, allowing room for organizations to make their own decisions in these high-stakes scenarios, and voiced opposition to an all out ban on payments.\u201d\u00a0<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Our report out today highlights the reversal of last year\u2019s steep decline in ransom payments. As will surprise no one in the IR field, 2023 is on pace to be one of, if not the highest grossing years ever for ransomware.<\/p>\n<p>So what\u2019s changed?\ud83e\uddf5 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/JwkWCwuG24\">pic.twitter.com\/JwkWCwuG24<\/a><\/p>\n<p>\u2014 J. Burns Koven (@JBurnsKoven) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/JBurnsKoven\/status\/1679122466390589443?ref_src=twsrc%5Etfw\">July 12, 2023<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Another complicating factor is that an increasing number of ransomware attacks, according to Chainalysis, may not have financial demands but instead focus on blackmail and other espionage purposes.\u00a0<\/p>\n<p>\u201cIn such cases, there may be no feasible way to pay the attackers, as their demands may go beyond monetary compensation\u2026 In the event that an organization finds itself in a situation where paying the ransom is the only viable option, it is essential to emphasize the importance of reporting the incident to relevant authorities.\u201d\u00a0<\/p>\n<p>\u201cTransparency in reporting ransomware attacks is crucial for tracking and understanding the tactics, techniques and procedures employed by malicious actors. By sharing information about attacks and their aftermath, the broader cybersecurity community can collaborate to improve defenses and countermeasures against future threats,\u201d Koven continues.<\/p>\n<h2>Could we enforce a ban on paying ransomware attackers?<\/h2>\n<p>Even if a ban were implemented, a key challenge is the difficulty in enforcing it. The clandestine nature of these transactions complicates tracing and regulation. Furthermore, international cooperation is necessary to curb these crimes, and achieving a global consensus on a ransom payment ban might be challenging.\u00a0<\/p>\n<figure class=\"wp-block-image alignright size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"369\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"Banning ransomware payments risks criminalizing victims\" class=\"wp-image-22931\" data-lazy-srcset=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Banning-ransomware-payments-risks-criminalizing-victims.jpg 300w, https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Banning-ransomware-payments-risks-criminalizing-victims-244x300.jpg 244w\" data-lazy-sizes=\"(max-width: 300px) 100vw, 300px\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Banning-ransomware-payments-risks-criminalizing-victims.jpg\" \/><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"369\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Banning-ransomware-payments-risks-criminalizing-victims.jpg\" alt=\"Banning ransomware payments risks criminalizing victims\" class=\"wp-image-22931\" \/><figcaption class=\"wp-element-caption\"><em>Banning ransomware payments risks criminalizing victims. (Pexels)<\/em><\/figcaption><\/figure>\n<p>While banning ransom payments could encourage some organizations to invest more in robust cybersecurity measures, disaster recovery plans and incident response teams to prevent, detect and mitigate the impact of cyberattacks, it still amounts to penalizing the victim and making the decision for them.<\/p>\n<p>\u201cUnfortunately, bans on extortions have traditionally not been an effective way to reduce crime \u2014 it simply criminalizes victims who need to pay or shifts criminals to new tactics,\u201d says Davis Hake, co-founder of Resilience Insurance who says claims data over the past year shows that while ransomware is still a growing crisis, some clients are already taking steps toward becoming more cyber-resilient and able to withstand an attack.\u00a0<\/p>\n<p>\u201cBy preparing executive teams to deal with an attack, implementing controls that help companies restore from backups, and investing in technologies like EDR and MFA, we\u2019ve found that clients are significantly less likely to pay extortion, with a significant number not needing to pay it at all. The insurance market can be a positive force for incentivizing these changes among enterprises and hit cybercriminals where it hurts: their wallets,\u201d Hake continues.<\/p>\n<h2>The growing threat and risk of cyberattacks on critical infrastructure<\/h2>\n<p>The costs of ransomware attacks on infrastructure are often ultimately borne by taxpayers and municipalities that are stuck with cleaning up the mess.<\/p>\n<p>To understand the economic effects of cyberattacks on municipalities, I released a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=4473545\">research paper<\/a> with several faculty colleagues, drawing on all publicly reported data breaches and municipal bond market data. In fact, a 1% increase in the county-level cyberattacks covered by the media leads to an increase in offering yields ranging from 3.7 to 5.9 basis points, depending on the level of attack exposure. Evaluating these estimates at the average annual issuance of $235 million per county implies $13 million in additional annual interest costs per county.<\/p>\n<p>One reason for the significant adverse effects of data breaches on municipalities and critical infrastructure stems from all the interdependencies in these systems. Vulnerabilities related to Internet of Things (IoT) and industrial control systems (ICS) increased at an \u201ceven faster rate than overall vulnerabilities, with these two categories experiencing a 16% and 50% year over year increase, respectively, compared to a 0.4% growth rate in the number of vulnerabilities overall, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.ibm.com\/downloads\/cas\/ADLMYLAZ\">according<\/a> to the X-Force Threat Intelligence Index 2022 by IBM.<\/p>\n<div class=\"article-suggest\">\n<p>Read also<\/p>\n<div class=\"article-suggest__items\">\n<div class=\"article-suggest__item\">\n                        <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/bitcoin-payday-crypto-to-revolutionize-job-wages-or-not\/\" class=\"article-suggest__subtitle display4\"><br \/>\n                            <span>Features<\/span><\/p>\n<p>Bitcoin payday? Crypto to revolutionize job wages\u2026 or not<\/p>\n<p>                        <\/a>\n                    <\/div>\n<div class=\"article-suggest__item\">\n                        <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/cointelegraph.com\/magazine\/powers-on-why-arent-more-law-schools-teaching-blockchain-defi-and-nfts\/\" class=\"article-suggest__subtitle display4\"><br \/>\n                            <span>Features<\/span><\/p>\n<p>Powers On\u2026 Why aren\u2019t more law schools teaching blockchain, DeFi and NFTs?<\/p>\n<p>                        <\/a>\n                    <\/div>\n<\/div>\n<\/div>\n<p>A key factor contributing to this escalating threat is the rapid expansion of the attack surface due to IoT, remote work environments and increased reliance on cloud services. With more endpoints to exploit, threat actors have more opportunities to gain unauthorized access and wreak havoc.\u00a0<\/p>\n<p>\u201cLocal governments face a significant dilemma\u2026 On one hand, they are charged with safeguarding a great deal of digital records that contain their citizens\u2019 private information. On the other hand, their cyber and IT experts must fight to get sufficient financial support needed to properly defend their networks,\u201d says Brian de Vallance, former DHS assistant secretary.<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>\u201cPublic entities face a number of challenges in managing their cyber risk \u2014 the top most is budget. IT spending accounted for less than 0.1% of overall municipal budgets, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"http:\/\/www.govtech.com\/security\/Local-Governments-Attractive-Targets-for-Cybercriminals.html\">according<\/a> to M.K. Hamilton &amp; Associates. This traditional underinvestment in security has made it more and more challenging for these entities to obtain insurance from the traditional market.\u201d<\/p>\n<\/blockquote>\n<p>Cybersecurity reform should involve rigorous regulatory standards, incentives for improving cybersecurity measures and support for victims of cyberattacks. Public-private partnerships can facilitate sharing of threat intelligence, providing organizations with the information they need to defend against attacks. Furthermore, federal support, in the form of resources or subsidies, can also help smaller organizations \u2013 whether small business or municipalities \u2013 that are clearly resource constrained so they have funds to invest more in cybersecurity.\u00a0<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\" \/>\n<h2>Toward solutions<\/h2>\n<p>So, is the solution a market for cybersecurity insurance? A competitive market to hedge against cyber risk will likely emerge as organizations are increasingly required to report material incidents. A cyber insurance market would still not solve the root of the problem: Organizations need help becoming resilient. Small and mid-sized businesses, according to my <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/yjolt.org\/defining-reasonable-cybersecurity-lessons-states\">research<\/a> with professors Annie Boustead and Scott Shackelford, are especially vulnerable.<\/p>\n<p>\u201cInvestment in digital transformation is expected to reach $2T in 2023 according to IDC and all of this infrastructure presents an unimaginable target for cybercriminals. While insurance is excellent at transferring financial risk from cybercrime, it does nothing to actually ensure this investment remains available for the business,\u201d says Hake, who says there is a \u201chuge opportunity\u201d for insurance companies to help clients improve \u201ccyber hygiene, reduce incident costs, and support financial incentives for investing in security controls.\u201d\u00a0<\/p>\n<p>Encouragingly, Hake has noticed a trend for more companies to \u201cwork with clients to provide insights on vulnerabilities and incentivize action on patching critical vulnerabilities.\u201d<\/p>\n<p>\u201cOne pure-technology mitigation that could help is SnapShield, a \u2018ransomware activated fuse,\u2019 which works through behavioral analysis,\u201d says Doug Milburn, founder of 45Drives. \u201cThis is agentless software that runs on your server and listens to traffic from clients. If it detects any ransomware content, SnapShield pops the connection to your server, just like a fuse. Damage is stopped, and it is business as usual for the rest of your network, while your IT personnel clean out the infected workstation. It also keeps a detailed log of the malicious activity and has a restore function that instantly repairs any damage that may have occurred to your data,\u201d he continues.<\/p>\n<p>Ransomware attacks are also present within the crypto market, and there is a growing recognition that new tools are needed to build on-chain resilience. \u201cWhile preventative measures are important, access controlled data backups are imperative. If a business is using a solution, like Jackal Protocol, to routinely back up its state and files, it could reboot without paying ransoms with minimal losses,\u201d said Eric Waisanen, co-founder of Astrovault.<\/p>\n<p>Ultimately, tackling the growing menace of cyber threats requires a holistic approach that combines policy measures, technological solutions and human vigilance. Whether a ban on ransom payments is implemented, the urgency of investing in robust cybersecurity frameworks cannot be overstated. As we navigate an increasingly digital future, our approach to cybersecurity will play a pivotal role in determining how secure that future will be.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"400\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"Mandatory disclosure and the threat of getting sued may force companies to improve cybersecurity\" class=\"wp-image-22934\" data-lazy-srcset=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Mandatory-disclosure-and-the-threat-of-getting-sued-may-force-companies-to-improve-cybersecurity.jpg 600w, https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Mandatory-disclosure-and-the-threat-of-getting-sued-may-force-companies-to-improve-cybersecurity-300x200.jpg 300w\" data-lazy-sizes=\"(max-width: 600px) 100vw, 600px\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Mandatory-disclosure-and-the-threat-of-getting-sued-may-force-companies-to-improve-cybersecurity.jpg\" \/><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"400\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2023\/08\/Mandatory-disclosure-and-the-threat-of-getting-sued-may-force-companies-to-improve-cybersecurity.jpg\" alt=\"Mandatory disclosure and the threat of getting sued may force companies to improve cybersecurity\" class=\"wp-image-22934\" \/><figcaption class=\"wp-element-caption\"><em>Mandatory disclosure and the threat of getting sued may force companies to improve cybersecurity. (Pexels)<\/em><\/figcaption><\/figure>\n<p>Emory Roane, policy counsel at PRCD, says that mandatory disclosure of cyber breaches and offering identity theft protection services are essential, but it \u201cstill leaves consumers left to pick up the pieces for, potentially, a business\u2019 poor security practices.\u201d<\/p>\n<p>But the combination of mandatory disclosure and the threat of getting sued may be the most effective. He highlights the California Consumer Privacy Act.<\/p>\n<p>\u201cIt provides a private right of action allowing consumers to sue businesses directly in the event that a business suffers a data breach that exposes a consumer\u2019s personal information and that breach was caused by the business\u2019 failure to use reasonable security measures,\u201d Roane explains. That dovetails with a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.wsj.com\/articles\/data-is-the-new-currency-big-tech-antitrust-free-services-platform-consumer-welfare-e5c74fb5?mod=opinion_lead_pos8\">growing recognition<\/a> that data is an important consumer asset that has long been overlooked and transferred to companies without remuneration. <\/p>\n<p>Greater education around cybersecurity and data sovereignty will not only help consumers stay alert to ongoing threats \u2014 e.g., phishing emails \u2014 but also empower them to pursue and value more holistic solutions to information security and data sharing so that the incidence of ransomware attacks is lower and less severe when they do happen.<\/p>\n<p>Bans rarely work, if for no other reason than enforcement is either physically impossible or prohibitively expensive. Giving into ransoms is not ideal, but neither is penalizing the entity that is going through a crisis. What organizations need are better tools and techniques \u2013 and that is something that the cybersecurity industry, in collaboration with policymakers, can help with through new technologies and the adoption of best practices.<\/p>\n<div class=\"subscribe subscribe--inner\">\n<div class=\"container\">\n<div class=\"subscribe__inner\">\n<div class=\"subscribe__content\">\n<p>Subscribe<\/p>\n<p>The most engaging reads in blockchain. Delivered once a<br \/>\n        week.<\/p>\n<\/div>\n<div class=\"subscribe__img\">\n    <img decoding=\"async\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"Subscribe to Magazine by Cointelegraph Newsletter.\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2022\/10\/reading-copy.png\" \/><img decoding=\"async\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2022\/10\/reading-copy.png\" alt=\"Subscribe to Magazine by Cointelegraph Newsletter.\" \/>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"author category_page\">\n<div class=\"author__img\">\n\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" src=\"image\/svg+xml,%3Csvg%20xmlns=\" alt=\"Christos A Makridis\" height=\"300\" width=\"300\" data-lazy-src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2022\/02\/Portrait_about_us_ChristosMakridis.jpg\" \/><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cointelegraph.com\/magazine\/wp-content\/uploads\/2022\/02\/Portrait_about_us_ChristosMakridis.jpg\" alt=\"Christos A Makridis\" height=\"300\" width=\"300\" \/>\n\t\t\t\t\t\t<\/div>\n<div class=\"author__content\">\n<h2 class=\"author__name\">Christos Makridis<\/h2>\n<p>Christos A. Makridis is the Chief Technology Officer and Head of Research at Living Opera. He is also a research affiliate at Stanford University\u2019s Digital Economy Lab and Columbia Business School\u2019s Chazen Institute, and holds dual doctorates in economics and management science and engineering from Stanford University. Follow at @living_opera.<\/p>\n<div class=\"author__follow body-l\">\n\t\t\t\t\tFollow the author \t\t\t\t\t\t\t<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/living_opera\">@living_opera<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<section class=\"news\">\n<\/section>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A successful cyberattack on critical infrastructure \u2014 such as electricity grids, transportation networks or healthcare systems \u2014 could cause severe disruption and put lives at risk.\u00a0 Our understanding of the threat is far from complete since organizations have historically not been required to report data breaches, but attacks are on the rise according to the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":137884,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[235,203,210,234,231,232,237,238,236,233],"class_list":["post-137883","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-bitcoin","tag-crypto-currency","tag-elon-musk","tag-ethereum","tag-hyperledger","tag-ibm","tag-mining","tag-nodes","tag-spacex","tag-tesla"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/137883","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=137883"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/137883\/revisions"}],"predecessor-version":[{"id":148273,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/137883\/revisions\/148273"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/137884"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=137883"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=137883"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=137883"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}