Should we ever pay a cyber ransom? Or are we simply asking the wrong question?
To pay or not to pay a cyber ransom – that is the question. Or is it? Frustratingly, there is no right or wrong answer to this million-dollar question after a data breach, writes Jacqueline Jayne, Security Awareness Advocate APAC at KnowBe4.
Some may argue that if businesses backed up everything, then they would never need to pay a ransom. This is not wrong; however, part of the ransom payment involves not only the return of data, it also can include the ‘promise’ not to release the data anywhere else, such as on the dark web for others to purchase and use.
We are dealing with cyber criminals here and is there any honour amongst thieves? What’s to stop them releasing the data once the ransom is paid and then dumping it on the dark web for all the other criminals to use?
We can argue all day about whether businesses should pay or not pay, and there will never be a definitive answer.
What I would like to address are us – the humans, the consumers, employers, customers, volunteers, students and everyone else. The government, big business and all the other industry bodies are focused on the ‘who should do what’ and ‘who should get fined’ and ‘what new laws do we need’ and pointing fingers and blaming everyone.
Cyber security is everyone’s responsibility and YOU – yes you – are not doing enough to keep yourself safe online and now is the time to step up and protect yourselves.
There are a few facts that I believe we, as consumers, need to accept whether we like it or not.
They are:
To provide an answer, let’s look at a non-cyber analogy for a moment – driving a car. You can be the safest driver in the world, have the most secure and safe car in the world, be driving on the best roads, supported by the best tyres – and despite your best efforts, you can have an accident.
How about securing your house? You can have a ridiculously secure perimeter, guards, alarms, locks everywhere – and if someone really wanted to break in they could tunnel under the ground to gain access.
My point here is that we, as consumers, need to accept that our basic and unique identifier data is going to be stolen. What we need to do is apply more levels of protection and basic cyber hygiene.

As I mentioned above, there are two levels of data cyber criminals are after: basic data and unique identifiers.
Yours is probably available online already. Our names, date of birth, addresses, emails, phone numbers, jobs we have, credit card numbers and their expiry dates are all basic data.
Your basic level one data is probably already out there – check your emails and mobile numbers here to confirm if they are involved in a known data breach and don’t panic when you find it there.
See tips below for what to do next.
This set of data is the next level. Medicare number, passport number, driver’s licence number, tax file number, the CVV number on the back of a credit card, or an account number for a service such as electricity, gas or phone.
It’s the unique identifiers that the cyber criminals really want. They can add it to the basic data they already have and then use it for fraudulent activities and even to steal our identity.
It is natural for people to feel scared and nervous when they realise some of their personal identifiable information has been stolen. Our data is valuable and it’s everywhere.
Don’t believe me? Consider your basic data and unique identifiers listed above and then think about the amount of data you have shared over the years, and the information you have shared during day-to-day life.
Everything a cyber criminal needs is already there.
And the answer is: yes and no.
Yes, because the majority of organisations do everything they can to keep it safe because it’s in their best interest to do so. No one wants a data breach, just like no one wants a car accident.
However, let’s for a moment put ourselves in the world of a cyber criminal. They know how valuable your data is and the more data the better. They could:
It makes sense that they will focus on the big data haul because it’s more financially beneficial for them.

Are there any tell-tale signs that someone has your data?
If your data was part of a data breach, the organisation in question will inform you and provide you with the details you need to know. Outside of that, pay attention to:
What should you do when you find out your information has been leaked, stolen or is already part of a previous data breach?
The first thing to do is to act quickly. Don’t wait a week or two; it’s better to be safe than sorry.

If you have more than 20 login combinations of username and passwords, get yourself a password manager tool so you only have to remember one strong passphrase.
There are many to choose from and you can start your research here.
MFA gives you a second layer of authentication and protection from cybercriminals. It means that once you have entered your username and password (first authentication), a second authentication is required to access your account or app.
There are a few options when it comes to MFA. The best option for most of us is using a third-party authenticator app, such as Google Authenticator or Microsoft Authenticator.
This includes the software that runs your devices, laptops and all the software and apps you use on all your devices.
Make sure you take the time to back up your important information, data, photos and memories
This article was first published on Flying Solo, read the original here.
Want more? Get our newsletter delivered straight to your inbox!ย Follow Kochieโs Business Builders onย Facebook,ย Twitter,ย Instagram, andย LinkedIn.
Comments