Is there a BBB for ransomware hackers that informs the insurance whether the deal will be honored?
I've been engaged on a few of these, my general impression so far is that the technical support you get from the ransomware gangs is better than the contracted support I get from Microsoft.
...that's a pretty low bar.
It seems to me that they'd have to be quite reliable and responsive to be able to routinely collect.
Nope, they rely on compliance to collect. So many compliance/regulatory schemes are like "Do you have vendor support on all your software, including OSes?" so you end up paying Microsoft money or paying Red Hat money.
I meant that the ransomware admins need to be reliable and responsive.
If so, how do you establish that the ransom group is actually the group with the good reputation?
I guess I'm intrigued by how you achieve all that when you're talking about the perpetrator of a crime that is obfuscating their identity.
If they can prove they can decrypt, they have very little to lose by not releasing the decryption key after being paid.
There's no BBB, but, yes, insurance carriers keep notes on the different ransomware gangs.
I guess my next question is how do you establish that it's actually the group with the "good" reputation, and not just one claiming or pretending to be them?
Only if the victims are communicating with each other. It seems like most victims are not interested in publicizing their experience. These incentives might be even stronger if one got scammed for the ransom. It's not a good look.
All the ham radio clubs I've been with have been living hand to mouth lol. Always having to beg everyone for money if something big needed doing.
Sad though that they wasted it on rewarding cybercrime actors.
https://www.arrl.org/files/file/About%20ARRL/Annual%20Report... - pg 44(ish)
Is the insurance cheaper than the impact and costs of preventing it in the first place?
Ransomware: Should paying hacker ransoms be illegal? (2021) https://www.bbc.co.uk/news/technology-57173096
A better law would be one that requires institutions above a certain size to create backups every 24hrs and maintain basic security practices to prevent this sort of thing.
I guess there are two ways you could implement this, the legal and the regulatory route.
The legal route would say that upon discovery of the lack of said backups, they would be subject to penalties. So if they get hit by a ransomeware attack, then while they are down, they get kicked. Pretty rough.
The regulatory route would say that every company above a certain size needs to document its policies around backups, and either standardize on a fixed set of backup techniques or have an auditor that verifies that the backup technique used by a company satisfies some set of requirements. The former approach means a ton of paperwork for the company to get the certification, and the latter approach means that the regulatory body has to be very large and have a great deal of subject matter expertise. All of this is fairly horrible.
I'm not sure that either of these would be "better" than making the payments themselves illegal. Not to say that such a law would be "good" either -- it basically means that companies will have to not involve the authorities because recovering their data is more important (and may be essential to the continuity of the company).
Bad as it is, the best solution here is probably to keep going like we're going -- law enforcement will try to hunt down the ransomers and bring them to justice (since this is already illegal), companies are incentivized to follow some sort of best practices around backups.