If You Pay Ransomware Will You Have to Pay the US Treasury as Well?

KrebsonSecurity has a post that mentions that the department of the Treasury has a Ransomware Advisory pdf. The Treasury is advising you not to pay Ransomware if your device is ransomed (encrypted unless you pay for a decryption key): Companies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber … Read more

Patching Anomalies Causing Security Problems

Zerologon Patches Roll Out Beyond Microsoft What if you have an older server? Like a Windows Server 2008? The Zerologon was a problem that was patched in August on a patch Tuesday of course. Race to patch as Microsoft confirms Zerologon attacks in the wild article also from ComputerWeekly.com Bottom line is that the vulnerability … Read more

Complacency and Cybersecurity Awareness

Are we being too complacent in our feeling of “nothing will happen to us” with regard to Cybersecurity? 2 stories tie this theme together: Phishing awareness training  wears off after a few months Apparently retraining is required after 6 months. Ransomware and Observations from Recent IR investigations Businesses are still getting ransomware, not how it … Read more

Is Psychology of Security Causing Cybersecurity Problems?

What do I mean by Cybersecurity problems?  How about not patching  or upgrading your devices, taking inventory of your devices.  Making changes to the network or systems and not thinking about security. Or just plain old errors, mistakes, issues that arise after something new happens. Why would we not pay attention to these things? What … Read more