• undefined@links.hackliberty.org
    link
    fedilink
    English
    arrow-up
    25
    ·
    2 days ago

    I like the “ransomware scumbag” language but at the same time, it feels like companies only give a shit about security after an incident.

    • Buelldozer@lemmy.today
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      2 days ago

      I dunno, with Healthcare the larger the organization the more serious they take it. A small practice may basically ignore it but by the time you get to be the size of UMC, the Hospital named in the article, they’re typically spending many millions of dollars annually on CyberSecurity.

      The problem is that they’re stuck playing defense. They have to get it right every time but the attackers only have to get lucky once. They could successfully repel 10,000 attempts Monday through Saturday but then on Sunday they only repel 9,999 'cuz Bored Bob the maintenance guy clicked a new zero-day in their email and now they’re in the news.