90% of Financial Institutions Targeted By Ransomware in the Last Year (betanews.com)
An anonymous reader shares a report: A new report from cloud security specialist Carbon Black, based on responses from CISOs at 40 major financial institutions -- including six of the top 10 global banks -- seeks to better understand the attack landscape. Among the findings are that 90 percent of financial institutions report being the subject of a ransomware attack in 2017. In addition one in 10 respondents report encountering destructive attacks unrelated to ransomware, such as application attacks and fileless malware. These potentially enable cybercriminals to move freely and laterally within an organization's network and often go completely overlooked until it's too late.
If ransom ware could find a way in, then it was successful.
Big organizations are easy picking because they have large existing networks, with decades of "Business Decisions" deems acceptable risks, vs paying to get it fixed, installed in the system. With delayed upgrades, because it may effect business flow, and legacy systems that are too critical to be upgraded.
The guys in IT try to warn them, but because they are cost center, such fixes are exceeding their budget.
If something is so important that you feel the need to post it on the internet... It probably isn't that important.
Fascinating, this very quickly ended up at -1. It appears the management may be suppressing efforts to insist that Slashdot comply with the GDPR. Is Slashdot management so hypocritical that they complain when others engage in poor privacy practices, but refuse to engage practice the same data protection practices they condemn others for ignoring?
Slackers! Looks like 4 of the 40 institutions are so incompetent they don't even know they're being attacked.
Your post had been flagged and your IP logged, kamarad. We will be sending creimer to update your network to the latest government IT standards. Please prepare 500 pounds of snack bars or he might mistake your arm for food.
If you do not wish a visit from creimer, please build a wall out of fresh fruit and vegetables, it's like Kryptonite to creimer.
The butthurt is strong with this one.
Disclaimer: I work with financial institutions.
Maybe they were targeted, but in my experience we have had few problems, and I would be one of the FPOC if there was an issue.
Therefore the 90% number is scare mongering. Maybe, they were targeted, but I doubt those financial institutions even know they were unless it was successful, and like I said. It hasn't been that successful, at least among my clients.
90% reported being attacked and the other 10% lied about being attacked.
PC Matic is a software whitelisting utility. PC Matic users don't get ransomware for the same reason game console users don't get ransomware. It's similar to the AppLocker functionality in Windows Enterprise edition but does not require the Enterprise upgrade.
Even before ransomware, it was always cheapest just to make and keep good backups and then when (not if) something happend on your network, you simply nuke the affected nodes to bare metal, reinstall, and restore. Seriously, fuck these guys.
The other 10% reported absolutely no problems have been detected, and that they have not had any breaches either. Sometimes a browser window pops up on its own or client information appears in a TXT file on the root directory but computers are weird like that.
I just tried to imagine a cybercriminal moving laterally... and ruined my keyboard. Thanks!