Skip to content

Menu

LexBlog, Inc. logo
CommunitySub-MenuPublishersChannelsProductsSub-MenuBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAboutContactResourcesSubscribeSupport
Join
Search
Close

Ransom Payment Debate Is Reminder to Stick to Cybersecurity Fundamentals

Ransom Payment Debate Is Reminder to Stick to Cybersecurity Fundamentals
By A. Kate Margolis on June 6, 2022
Email this postTweet this postLike this postShare this post on LinkedIn

Criminal cyber attacks that deprive access to vital digital information and hold it for ransom are a constant and ever-increasing threat. No organization is immune. 

Due to the exponential rise in ransomware attacks, cyber insurance coverage for ransom payments – one of the tools for mitigating cyber risk – now requires steeper premiums for much less coverage. Some argue that insurers’ payments have contributed to the increase in attacks.  Meanwhile, the FBI continues to warn that paying a ransom is never a guarantee that encrypted data will be recovered. 

Whether to pay a ransom has now become a matter of state public policy. In an effort to deter ransomware attacks on state agencies, North Carolina became the first state to enact laws prohibiting the use of tax dollars to pay ransoms (N.C.G.S. 143‑800). Pennsylvania is considering following suit. A proposed ban on ransom payments in New York would extend to private companies (see New York State Senate Bill S6806A). Whether these efforts will successfully deter cybercrime remains to be seen.  

These developments serve as a reminder to focus on cybersecurity fundamentals.  Organizations should review their cybersecurity measures on a regular basis as a matter of good governance. Simple security measures such as multifactor authentication and providing regular employee training on phishing and other social engineering scams can make all the difference.

Whether paying ransoms causes an increase in ransomware attacks by emboldening criminals will continue to be debated. But any such increase likely pales in comparison to the risks associated with the failure to institute appropriate cybersecurity measures. Too many organizations remain easy pickings. 

For more information and other updates and alerts regarding privacy law developments, subscribe to Bradley’s privacy blog, Online and On Point.

Photo of A. Kate Margolis A. Kate Margolis

Kate Margolis provides insurance coverage advice for policyholders. She knows that insurance coverage is essential to the long-term viability of any business. Kate helps policyholders preserve coverage both before and after a claim arises. She advises regarding terms and conditions and potential gaps…

Kate Margolis provides insurance coverage advice for policyholders. She knows that insurance coverage is essential to the long-term viability of any business. Kate helps policyholders preserve coverage both before and after a claim arises. She advises regarding terms and conditions and potential gaps in coverage when clients are evaluating their insurance programs.  For example, cyber insurance has fast become a crucial part of any insurance program. Kate recently co-authored the Guide to Cyber Insurance: Building a Program, Procuring Coverage, Managing Claims and Litigating Disputes, published by RIMS, the Risk Management SocietyTM.

When coverage disputes do arise, Kate is committed to cost-effective and creative solutions to achieve a satisfactory business resolution if possible and unrelenting advocacy when litigation is warranted. Kate has helped clients navigate roadblocks to coverage for nearly 20 years.

Read more about A. Kate MargolisEmail
Show more Show less
  • Posted in:
    Featured Posts, Privacy & Data Security
  • Blog:
    Online & On Point
  • Organization:
    Bradley Arant Boult Cummings LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center

New to the Network

  • The FTI Award Journal
  • International Dispute Resolution
  • China Law Update Blog
  • Law of The Ledger
  • Antitrust Law Blog
Copyright © 2022, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo