–– Meeting 3 —
Ransomware Negotiations
Attendance
WELCOME!
Updates
Opportunities
Executive Shadowing
Student-Powered SOC at Miami
Club Updates
Elections
Industry Events
Ross Flynn (CrowdStrike) - 10/1
Mark Jeanmougin (Siemens)
Current Events Discussion
Scattered Spider “Retires”
The Hacker News
From there:
Scattered Spider, and 14+ other organized cybercrime groups claimed to “retire.”
Threat intelligence leaders warn that this could mean:
How Do Ransomware Negotiations Work?
Cole LaCamera
What are Ransomware Negotiations?
What people generally assume:
What they don’t consider:
Ransom Negotiation Basics
Cybersecurity Insurance
How Do We Get to Negotiations?
Now the fun starts!
Negotiation Tactics
Stalling
Determining Scope
Demanding Proof
Decryption Key Efficacy
Many people think that paying a ransom means you get all of your data back.
Statistics prove otherwise (Darwin’s Data):
Overall, roughly 70-80% of companies don’t get their data back despite paying a ransom.
So why do companies still pay ransoms?
More Considerations
Regulatory Requirements
There are regulations in place that prohibit or regulate ransom payments:
Other Considerations
Simulation Games
Optional: Read Ransomchats
Game Simulations:
Links:
Financial Times: https://ig.ft.com/ransomware-game
RansomChatGPT: https://www.yeschat.ai/gpts-2OTo9yuE4X-RansomChatGPT
eBanking: https://www.ebas.ch/en/ransomware-game/
Kaspersky: https://www.kaspersky.com/response-game/en/