• N0body@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    10
    ·
    7 days ago

    I don’t understand how the timing of these announcements work. Do they wait for all their richest clients to pay the ransom money first? Explore every avenue of deniability until they’re exhausted?

    • gwilikers@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      ·
      7 days ago

      They definitely do a risk assessment on the possible costs of announcing a breach vs the costs of hiding one. I’ve seen a talk where it was pointed out that one of America’s biggest vulnerabilities in its tech sector and general cyber infrastructure is the fact that companies are not legally obliged to announce a leak when it happens.