I’m sitting here wondering what exactly about the release of their financials and internal procedures prompted them to immediately pay $4-5m in the hopes of preventing it from happening?
If the threat was to release sensitive information, surely the firm would be asking the attackers for details of the sensitive information they claim to have.
If the attackers come back with nothing then it was just a bluff.
However if the attackers come back with real information then paying the ransom is just stupid, as the attacker still have the sensitive information and can repeat the payment demands ad infinitum.
I can't even begin to imagine the amount of people that could cause an issue in the size company you are a CISO at.
Clearly, you can never make it literally impossible, but to my knowledge, nobody has ever managed to get malicious software onto a classified production system. Information leaks are, of course, another story.
Are these (i suspect not) published anywhere as "Three letter agency network security standards"?
The types of ransomware attacks we see today might not be preventable as well, every company on the planet will get or was already hit. But, the difference between the attacks: the amount of damage. If money is spent on security, that amount will certainly be smaller.