On ransomware, typically covered through cyber insurance, the industry is doing less well in governing the market. Insurers unquestioningly paid hackers’ initially small ransom amounts, prioritising business continuity: “Ransoms kept growing and growing. Once the hackers were inside a business, they could look at its profit and loss accounts or charge them a percentage of turnover.”
She adds that cyber insurance is now encouraging hackers to “do ransomware better” as if they “want to have a business, they better make sure that data isn’t wiped when it’s stolen, that it can be recovered and given back to the business.”
Anja’s latest book, We Know You Can Pay a Million, charts the growth of ransomware from acts of mischief in the late twentieth century to the catastrophic impacts it’s had on today’s society.
Recent examples include a significant attack on the NHS, and on M&S, which disrupted the business for months. The reason Anja wrote the book, was to not only provide a history of ransomware, but also to emphasise the human and social aspects of data piracy to help us learn from previous attacks.
“I wanted to write this book as a human-interest story that teaches people the language that they need to engage with their own cyber security. Most of the attacks that we’re seeing are based around social engineering.”
She says there is not necessarily an imminent existential and national threat from ransomware, but it makes sense to think about how our government should prepare and we can learn from the COVID pandemic.
“We know what on the hoof policy making looks like in a crisis. Is this how we want to deal with a national emergency where all or part of the country is without water or electricity? Would it be reassuring to have a plan? I think it probably would.”