Image: Getty Images
The threat of ransomware dominates the cyber news right now, and rightly so. But this week Rachael Falk, chief executive officer of Australia's Cyber Security Cooperative Research Centre, made a very good point.
Ransomware is "totally foreseeable and preventable because it's a known problem", Falk told a panel discussion at the Australian Strategy Policy Institute (ASPI) on Tuesday.
"It's known that ransomware is out there. And it's known that, invariably, the cyber criminals get into organisations through stealing credentials that they get on the dark web [or a user] clicking on a link and a vulnerability," she said.
"We're not talking about some sort of nation-state really funky sort of zero day that's happening. This is going on the world over, so it's entirely foreseeable."
There are "four or five steps you could take that could significantly mitigate this risk," Falk said. These are patching, multi-factor authentication, and all the stuff in the Australian Signals Directorate's Essential Eight baseline mitigation strategies.
The latest Essential Eight Maturity Model even comes with detailed checklists for Windows-based networks.
"Companies are on notice that this is a risk for them," Falk said. "There's a known problem often, and a known fix, but people haven't done it."
So given this laziness, given that cyber wake-up calls have been ignored since the 1970s, and given that organisations continue to willfully fail to follow the advice they're given, your correspondent has a question.
Has the time come to let Darwinism loose? Should we let all these lazy organisations get hacked, and just let God sort them out?
"I love that approach," Falk said. "It is glacial-like movement, and I think the only change now that might accelerate it is legislation, which obviously government is potentially seeking to introduce at the moment," she said, referring to proposed changes to critical infrastructure laws.
Maybe we'll only start paying attention when there's more 5G, more device-to-device communication, and more personal dependence on the network.
"I kind of wonder, though, in a macabre kind of way, will the test be when people just can't use their phones for half an hour," Falk said.
"That's when you'll get people going, oh, we just have to have law about this because we can't cope with [no] iPhones, internet, fridge, streaming, Netflix, you name it."
OK, we're joking. Probably.
In cybersecurity as in public health, blaming the victim is counterproductive. And in many cases it's the customers and citizens who'd really suffer from ransomware and other cyber attacks that take out an organisation.
"It could really, really impact life, and be a threat and risk to life. So I think people have to start thinking about this as not some sort of a joke," Falk said.
"The fact that we joke about, oh, the internet being down for 30 minutes, it could be the matter of a medical procedure is stopped and someone dies halfway through."
In Germany last year, for example, a patient died following a ransomware attack on a hospital in Duesseldorf, which caused her to be re-routed to a hospital more than 30 kilometres away. A police investigation found that she probably would have died anyway, but next time we may not be so lucky.
Fortunately, a global consensus on how to tackle ransomware does seem to be emerging.
Just one example is a new report from ASPI's International Cyber Policy Centre, Exfiltrate, encrypt, extort: The global rise of ransomware and Australia's policy options, of which Falk is co-author.
On the vexed question of whether organisations should pay a ransom or not, the report recommends that paying them should not be criminalised. Instead, there should be a "mandatory reporting regime ... without fear of legal repercussions".
This would be a major step in transparency. Out of all the major ransomware incidents in Australia -- Toll Holdings, BlueScope Steel, Lion Dairy and Drinks, legal document-management services firm Law in Order, Nine Entertainment, Eastern Health in Victoria, Uniting Care Qld, and JBS Foods -- only JBS has admitted to paying a ransom of $11 million.
Such a scheme has already been proposed by Labor in its Ransomware Payments Bill 2021 introduced onto parliament last month as part of its national ransomware strategy.
The ASPI report recommends expanding the role of the ASD's Australian Cyber Security Centre (ACSC) to include the real-time distribution of publicly available alerts.
ACSC should also publish a list of ransomware threat actors and aliases, giving details of their modus operandi and key target sectors, along with suggested mitigation methods.
The ASD is already known to be using its classified capabilities to warn of impending ransomware attacks.
The report also recommends tackling the "low-hanging fruit" of incentivisation and education.
This includes incentives such as tax breaks for cyber investment, grants, or subsidy programs; a "concerted nationwide public ransomware education campaign, led by the ACSC, across all media"; and a "business-focused multi-media public education campaign", also led by the ACSC.
"[This campaign should] educate organisations of all sizes and their people about basic cybersecurity and cyber hygiene. It should focus on the key areas of patching, multifactor authentication, legacy technology, and human error."
Finally, the report recommends creating a "dedicated cross-departmental ransomware taskforce", including state and territory representatives, to share threat intelligence and develop policy proposals.
Your correspondent finds none of these recommendations unreasonable, though there are perhaps questions about whether ACSC is currently well-equipped to run an effective and engaging major public information campaign.
Nevertheless, given how slowly Australian organisations have adapted to cyber risks over the last couple of decades, maybe we need a little less carrot and a bit more stick.
Here is the original post:
May ransomware blight all the cyber stragglers and let God sort them out - ZDNet
- Why Darwinism Is False | Center for Science and Culture [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- Darwinism - Wikipedia, the free encyclopedia [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Why Darwinism Is False | Center for Science and Culture [Last Updated On: June 13th, 2016] [Originally Added On: June 13th, 2016]
- Darwinism | Define Darwinism at Dictionary.com [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- Darwinism | Darwinism Definition by Merriam-Webster [Last Updated On: June 16th, 2016] [Originally Added On: June 16th, 2016]
- Digital Darwinism: How Disruptive Technology Is Changing ... [Last Updated On: June 17th, 2016] [Originally Added On: June 17th, 2016]
- What is Social Darwinism - AllAboutScience.org [Last Updated On: June 17th, 2016] [Originally Added On: June 17th, 2016]
- Social Darwinism - Wikipedia, the free encyclopedia [Last Updated On: June 17th, 2016] [Originally Added On: June 17th, 2016]
- Neo-Darwinism : The Current Paradigm. by Brig Klyce [Last Updated On: June 19th, 2016] [Originally Added On: June 19th, 2016]
- What is Darwinism? - TalkOrigins Archive [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Free social darwinism Essays and Papers - 123helpme [Last Updated On: June 29th, 2016] [Originally Added On: June 29th, 2016]
- Darwinism - New World Encyclopedia [Last Updated On: July 3rd, 2016] [Originally Added On: July 3rd, 2016]
- Evolution and Philosophy: Social Darwinism [Last Updated On: July 5th, 2016] [Originally Added On: July 5th, 2016]
- Social Darwinism - University of Colorado Boulder [Last Updated On: July 14th, 2016] [Originally Added On: July 14th, 2016]
- Darwinism - RationalWiki [Last Updated On: July 14th, 2016] [Originally Added On: July 14th, 2016]
- Urban Dictionary: Darwinism [Last Updated On: July 14th, 2016] [Originally Added On: July 14th, 2016]
- What Is Darwinism? - Christian Research Institute [Last Updated On: July 14th, 2016] [Originally Added On: July 14th, 2016]
- Darwinism - The Economist [Last Updated On: November 6th, 2016] [Originally Added On: November 6th, 2016]
- Social Darwinism - Wikipedia [Last Updated On: November 6th, 2016] [Originally Added On: November 6th, 2016]
- Darwinism - Wikipedia [Last Updated On: November 6th, 2016] [Originally Added On: November 6th, 2016]
- Social Darwinism: The Theory of Evolution Applied to Human ... [Last Updated On: November 8th, 2016] [Originally Added On: November 8th, 2016]
- Harun Yahya [Last Updated On: November 8th, 2016] [Originally Added On: November 8th, 2016]
- Natural selection - Wikipedia [Last Updated On: November 8th, 2016] [Originally Added On: November 8th, 2016]
- Social Darwinism - Dr. Hartnell's Nutty the A.D.D. Squirrel [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Modern evolutionary synthesis - Wikipedia [Last Updated On: November 25th, 2016] [Originally Added On: November 25th, 2016]
- Difference between Darwinism and Neo-Darwinism | Major ... [Last Updated On: November 29th, 2016] [Originally Added On: November 29th, 2016]
- The Effect of Darwinism on Morality and Christianity | The ... [Last Updated On: January 4th, 2017] [Originally Added On: January 4th, 2017]
- Biologist Ann Gauger: Apoptosis (Cell Death) Is an Enigma for Darwinism - Discovery Institute [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Tom Bethell's Rebuke to Fellow Journalists: A Skeptical Look at Evolution Is Not Beyond Your Powers - Discovery Institute [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Tom Bethell on Mind, Matter, and Self-Defeating Darwinism - Discovery Institute [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- The Curious Romance of Darwinism and Creationism -- And Why Intelligent Design Must Be Silenced - Discovery Institute [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Darwin Americanus - lareviewofbooks [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- With Darwin Day Approaching, It's Time for a Look Back at Evolution ... - Discovery Institute [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- With Darwin Day Coming Tomorrow, Here's Tom Bethell on Darwin's Deception - Discovery Institute [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- The Lord's Day, Meet Darwin Day and Shudder | The American ... - American Spectator [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- The Truth about Soviet Science and Darwinian Evolution Isn't as Darwinists Would Like Us to Believe - Discovery Institute [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- In Mouse and Human Embryo Development, Critical Transition Points Beyond Neo-Darwinism - Discovery Institute [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Criticism of Darwinism - MOLWICK [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Happy Darwin Day! German Natural History Museum Is Our 2017 Censor of the Year - Discovery Institute [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- What Darwinists Don't Tell You: Valentine's Day Edition - Discovery Institute [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- COLUMN: Trump Train driving a new type of Darwinism - Jacksonville Daily News [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Disregarding Fake News from Darwin Promoters, South Dakota Scientist Applauds Academic Freedom Bill - Discovery Institute [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Astronomers Use Darwinism To Plot Stellar Family Tree - Forbes [Last Updated On: February 23rd, 2017] [Originally Added On: February 23rd, 2017]
- Doug Axe: Hidden Figures and the Engineering Challenge to Darwinism - Discovery Institute [Last Updated On: February 25th, 2017] [Originally Added On: February 25th, 2017]
- Darwinism and the Nazi race Holocaust - creation.com [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- The Envelope, Please? Doug Axe and Undeniable Are World Magazine 2016 Science Book of the Year! - Discovery Institute [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- HOWS THAT MINIMUM WAGE LAW WORKING?: Increase sets social Darwinism in motion - Aztec Press [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- "Darwin's Dice" -- Michael Flannery on the Role of Chance in ... - Discovery Institute [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Darwinism and the evolution of IR: Evolve or perish - IR Magazine [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Reps. McEachin, Scott, Beyer, Connolly; Sens. Kaine, Warner Blast Trump's Draconian, Social Darwinism Budget ... - Blue Virginia (press release)... [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Bill Marvel: Mechanical Darwinism - Conway Daily Sun [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Pity the Unwanted Orphan Genes An Awkward Topic for Darwinism - Discovery Institute [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Darwinism: Survival without Purpose | The Institute for ... [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Digital Darwinism Predicted as Changes in Consumer Behavior Transform Marketing Landscape - MarTech Advisor [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Budgeting Social Darwinism - Huffington Post [Last Updated On: March 19th, 2017] [Originally Added On: March 19th, 2017]
- Have Human Beings Stopped Evolving? - Huffington Post [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Trump Making Social Darwinism Sexy Again - Santa Barbara Independent [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Noblett: Health care and social Darwinism - Roanoke Times [Last Updated On: March 27th, 2017] [Originally Added On: March 27th, 2017]
- The Rise of Retail Darwinism - PYMNTS.com [Last Updated On: March 27th, 2017] [Originally Added On: March 27th, 2017]
- Geneticist Wolf-Ekkehard Lnnig on Darwinism and Gregor Mendel's Sleeping Beauty - Discovery Institute [Last Updated On: March 27th, 2017] [Originally Added On: March 27th, 2017]
- Did medical Darwinism doom the GOP health plan? - The Conversation US [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- The Rise Of Retail Darwinism | Seeking Alpha - Seeking Alpha [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Survival of the Pithiest - The Weekly Standard [Last Updated On: March 31st, 2017] [Originally Added On: March 31st, 2017]
- Did medical Darwinism doom the GOP health plan? - Raw Story [Last Updated On: March 31st, 2017] [Originally Added On: March 31st, 2017]
- How Charles Darwin Got New England Talking - The Weekly Standard [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- 'Mating' Robots Take a Fast-Forward Leap in Digital Darwinism - Seeker [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- 'Mating' Robots Take a Fast-Forward Leap in Digital Darwinism - Live Science [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Octopus Genetic Editing Animals Defy Their Own Neo-Darwinism - Discovery Institute [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- Meet the congressman who is pushing for a Charles Darwin Day ... - WJLA [Last Updated On: April 13th, 2017] [Originally Added On: April 13th, 2017]
- The 100-year-old challenge to Darwin that is still making waves in research - Nature.com [Last Updated On: April 17th, 2017] [Originally Added On: April 17th, 2017]
- Connecticut congressman pushing for a Charles Darwin Day - New Haven Register [Last Updated On: April 19th, 2017] [Originally Added On: April 19th, 2017]
- Meet the congressman who is pushing for a Charles Darwin Day ... - Tulsa World [Last Updated On: April 21st, 2017] [Originally Added On: April 21st, 2017]
- Meteorology Pioneer Borrows from Darwinism for Latest Forecast Innovation - Laboratory Equipment [Last Updated On: April 23rd, 2017] [Originally Added On: April 23rd, 2017]
- LETTER: Trump and social darwinism - Greenville News [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Evolutionary Informatics: Marks, Dembski, and Ewert Demonstrate the Limits of Darwinism - Discovery Institute [Last Updated On: May 2nd, 2017] [Originally Added On: May 2nd, 2017]
- How Two New York Rabbis Responded To The 1925 Scopes Monkey Trial - The Jewish Press - JewishPress.com [Last Updated On: May 4th, 2017] [Originally Added On: May 4th, 2017]
- How do we fix our 21st century economy? Look to Darwin - The Guardian [Last Updated On: May 6th, 2017] [Originally Added On: May 6th, 2017]
- Darwinism in Question with Discovery: Octopi Edit Their Own Genes - CNSNews.com [Last Updated On: May 9th, 2017] [Originally Added On: May 9th, 2017]
- Five rational arguments why God (very probably) exists - Religion News Service [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]
- More on Octopus RNA Editing A Problem for Neo-Darwinism - Discovery Institute [Last Updated On: May 11th, 2017] [Originally Added On: May 11th, 2017]