Bonanza Offer FLAT 20% off & $20 sign up bonus Order Now
PICT2001
AU
Macquarie University
Ransomware, a form of computer malware, has quickly become one of the top cybersecurity threats faced by today’s organizations. In recent years, ransomware assaults have risen, when an attacker encrypts the data of a user, and then requires a payment in return for the decryption key. Whereas paying the ransomware helps the user to swiftly release the encrypted data and prevent possibly bigger losses, it also improves the attacker's hand and raises the likelihood of further assault (Dey and Lahiri 2021). We investigate the dilemma of the victims and their behaviours with a game-theoretical model in conjunction with the Probabilistic decision-making process. In certain instances, prohibitions can be successful in resolving economic externality, but otherwise might diminish public welfare. The ensuing balance leads towards various intriguing points, for instance, where legal ransom payment prohibitions may not always be of the desired economic impact. Our conclusions get a significant impact on policymakers now discussing legislation that would prohibit ransom payments to attackers if implemented. Paying hackers isn't the best solution when it comes to ransomware attacks on governments. To begin with, there's no guarantee that hackers will return important information. Second, whether the data is returned or not, there's no assurance that hackers won't use and profit from it. To properly combat ransomware, we must make ransomware payments illegal and build a robust industry of cyber specialists, a digital army of sorts, to boost security awareness and data protection in a proactive manner.
At first appearance, one could believe that there are advantages to not encouraging ransomware offenders. When examined more closely, however, the scenario may not appear to be favourable in actuality. A law that would punish businesses and organisations, and may even imprison employees, is very contentious and will face opposition if it is implemented. Furthermore, paying for the ransomware report is not unlawful because the decision to pay for the ransomware demand is extremely practical if the damage surpasses the advantages. But at the other side, refusing to pay for the ransomware demands is a successful tactic since it prevents criminals from being marketed and encouraged to engage in ransom demands (Irwin and Dawson 2019).
Over the duration of its prominence, Ransomware assaults have altered. Although some may assume that just because the typical aim is not individuals, but big companies, they are personally secure, the fact is that the vulnerabilities have only increased for people and businesses. While a person would have known before if his data had been received (Hosfelt et al. 2020), it is more probable that data he has entrusted to something like a third party (often committed to some other third party), are being collected, leaked or sold and the person is only notified by the larger organisation, usually after long period of time, since incidents are normally only announced when required.
The problem with ransomware is probably not one that anybody can challenge. It will require a united effort to starve the ransomware "business" and the cyber criminals behind the whole ecosystem such that this isn't a profitable fraud any more. It frequently appears to be the least resistant way to pay ransom (Pogrebna and Skilton 2019), yet the problem is indeed sustained by this approach. A voluntary ban on ransom payments is improbable, which will prohibit individuals from bargaining with cyber criminals under societal and political pressure. Authorities might make paying or otherwise discouraging a request for ransomware criminal. Or, we may consider the cyber-insurance impact on ransomware assaults, and the fact that the impact covers payments for ransomware (Broadhurst 2018). If regulations reject insurance covering such payments by criminals and reject cover organisations that do not adopt the minimum cyber safety precautions necessary to safeguard private information, then we may have ransomware as a practise.
To do so, all companies need either raise their information security to both the point that are (doubtful) impregnable or obtain the consent of all companies to avoid paying the ransom demand, independent of individual corporate disruptions to "disturb" the criminals. It is all too tempting to consider paying the ransom as the quickest, cheapest, and most effective option. In addition to the financial impact, the victims have limited financial, operational or even reputational costs (Hoy 2017). And then cyber insurance coverage, aside from the monetary loss, there is minimal consequence to the victim in terms of money, operations, or even reputation. Then there are cyber insurance packages that cover ransomware, which reduces the cost strain even further. In a public consultation, however, the Treasury Department is currently in the process of establishing advice. It warns that if ransom payments are made to certain identified nodes, any companies or contractors a hacked organisation works with, including those providing insurance, incident response, and digital forensics, as well as all financial services that help facilitate or process ransom payments, might face fines from the Office of Foreign Assets Control in addition to the victimised organisation itself (Williams, Donaldson and Siegel 2020).
Admittedly human nature, particularly in the corporate sector, follows the road of least resistance, but ransomware should be viewed as organised crime. Though in the past maybe, cooperating with criminals that attack your business was easy and perhaps viewed as "a price of doing business," law has led to the freeing of depredatory gangs of companies and individuals. Similar measures should be enacted to combat Ransomware gangs, which are even stricter than the Commerce Department standards; especially as huge public organizations are becoming the target of choices for attackers. Some of these organizations, such as the University Of Michigan, and even towns like Atlanta or Baltimore, had done their best to counter ransomware crime. Perhaps it ought to be the law. An involving cybercriminal as the victim of their plans – support and encourages further crimes. Maze ransomware, a well-known hacker organisation in the beginning of summer hit MaxLinear, a maker of chipsets (Carrazana and Colloquium 2018). However, MaxLinear was prepared to quote in a declaration to the SEC that the ransom was not paid since the attack did not impact the capacity of the attack. "The Ransomware attack did not considerably interfere with our production and delivery capabilities and the order compliance was maintained without major disruption. We do not have any intention to meet the monetary demands of the attacker." MaxLinear maintained their claim that they did not receive money under increasing pressure from the attackers, including stolen breaches of material and the threat of more breaches. "Although the forensic investigation and remediation have incurred and will incur further costs, we do not presently foresee that the event will affect our operating expenditures significantly or adversely (Abedin 2018). We are subject to deductions and policy restrictions. We have cybersecurity insurance. We have also contacted the proper criminal enforcement agencies.”
While cyber-security insurance is cited as a precautionary measure that enables MaxLinear to refuse to pay ransom demands in the case of many companies, it enables them to make such payments and, as such, can actually discourage organisations from implementing policies and practises that prevent all payments necessary, for example consistent backup of data (Joshi 2020).
Paying of ransom payments helps to keep ransomware assaults alive as a criminal enterprise. Successful trades exacerbate the threat of ransomware since they:
With every successful assault, these organisations' offensive capacity and resources are increased and new organisations and frequently previous victims are continued to be extorted. While payers anticipate the ransom to be paid back, this is seldom ever the case (Sales 2018). One would expect these crooks to follow their word to promote successful exchanges in future, but researchers have found that just a quarter of corporations are truly releasing their files, paying ransom claims. As thieves have also began collecting important information, they can potentially conduct more crimes by selling or exploiting personal data in future attacks (Iyer 2017).
Ransomware assaults have stifled its IT functioning globally, shattered civic life and wasted millions of dollars on local governments, from major cities through communities. The easiest way for a company to do so is to reduce and recoup the payment insurance policy, with the attackers surrendering their data, after a sometimes (Irwin and Dawson 2019). While the coverage may compensate our payment costs, it cannot cover ones business's trouble and waste of time, somewhat less your customers' effect. You can't restore your reputation. There is no additional prevention of our cyber insurance, and rather, if you are attacked again it is more expensive, as ransomware claims are followed by a rise in premiums. Cyber insurance isn't meant to be a safeguard or a preventative measure. If anything, being insured makes you a more appealing target since you are more likely to be able and ready to pay. Cyber insurance must be part of a risk reduction scheme but it must be complemented by really protecting and preventing measures, as the automobile insurance undermines but does not prevent the financial consequences of losses. This would include secure backups, vendor management, and intrusion detection in a car; in cybersecurity, it would include locking doors, airbags, seat belts, or safe design (Basori and Malebary 2020). There will be enterprises who consider ransomware as their best practise as long as there is the erroneous idea that it can be avoided swiftly by paying criminals' demands. To destroy it as a danger, the whole cybersecurity community, as well as the business community at large, must unite and announce their utter refusal to engage with the attacker. Obviously, a voluntary attempt to remove malware as a danger is ambitious, and the only means of promoting this type of movement is probably by exerting external pressure - whether it be policy, laws and regulations, or simply economic burden that goes above fines that somehow still consider it useful paying instead of dealing with the aftermath. Lawmakers and federal cyber-crime authorities might study what they may do to prevent ransomware demands from being paid in their entirety (Broadhead 2018). Assurance firms should evaluate the impact on the larger ecosystem of their readiness to pay for ransomware, and insurance consumers should reassess what this implies after an assault. In the end, compliance is what drives cybersecurity, and ransomware will be rendered obsolete by compliance with some norm, policy, or legislation.
Ransomware attempts are becoming popular these days, while the quantity requested for ransom has been steadily increasing. Since it may be exceedingly expensive to refuse payment, the victim typically pays for the restitution. However, each individual company has an externality to such an activity. The company basically reinforces the attacker's hand by paying the ransom, and so raises the intensity of these attacks in the future. In this regard, we intended to examine whether the market can resolve this externality properly and how policy makers might act if the market does not absorb it entirely. We observed that while overcrowding may be a full prohibition on ransom payments, the policymaker may actually lead victims towards non-payments by the adoption of appropriate subsidies and/or levies. Naturally, our findings must not imply that we advise that politicians across the board should seek to interfere immediately. Our consequences, if any, are that a policymaker should pause and carefully evaluate the unforeseen effects before taking action. And it should not be draconian if an intervention is required.
Abedin, K., 2018. Ransomware: Hostage Situation.
Basori, A.H. and Malebary, S.J., 2020. Deep Reinforcement Learning for Adaptive Cyber Defense and Attacker’s Pattern Identification. In Advances in Cyber Security Analytics and Decision Systems (pp. 15-25). Springer, Cham.
Broadhead, S., 2018. The contemporary cybercrime ecosystem: A multi-disciplinary overview of the state of affairs and developments. Computer Law & Security Review, 34(6), pp.1180-1196.
Broadhurst, R., 2017. Cybercrime: thieves, swindlers, bandits and privateers in cyberspace. Swindlers, Bandits and Privateers in Cyberspace (July 27, 2017).
Broadhurst, R., Lord, D., Maxim, D., Woodford-Smith, H., Johnston, C., Chung, H.W., Carroll, S., Trivedi, H. and Sabol, B., 2018. Malware trends on ‘darknet’crypto-markets: Research review. Available at SSRN 3226758.
Carrazana, L. and Colloquium, E.C.O.N., 2018. The Economics of Cybersecurity and Cyberwarfare: A Case Study.
Dey, D. and Lahiri, A., 2021, January. Should We Outlaw Ransomware Payments?. In Proceedings of the 54th Hawaii International Conference on System Sciences (p. 6609).
Hosfelt, D., Outlaw, J., Snow, T. and Carbonneau, S., 2020. Look Before You Leap: Trusted User Interfaces for the Immersive Web. arXiv preprint arXiv:2011.03570.
Hoy, M.B., 2017. An introduction to the blockchain and its implications for libraries and medicine. Medical reference services quarterly, 36(3), pp.273-279.
Irwin, A.S. and Dawson, C., 2019. Following the cyber money trail: global challenges when investigating ransomware attacks and how regulation can help. Journal of money laundering control, 22(1), pp.110-131.
Irwin, A.S. and Dawson, C., 2019. Following the cyber money trail. Journal of Money Laundering Control.
Iyer, S.M., 2017. A Case Study on Monetary Fraud in a Cashless Economy (Doctoral dissertation, Purdue University).
Joshi, V.C., 2020. Cyber-Risk Management. In Digital Finance, Bits and Bytes (pp. 131-150). Palgrave Macmillan, Singapore.
Pogrebna, G. and Skilton, M., 2019. Cybersecurity Threats: Past and Present. In Navigating New Cyber Risks (pp. 13-29). Palgrave Macmillan, Cham.
Sales, N.A., 2018. Privatizing cybersecurity. UCLA L. Rev., 65, p.620.
Williams, C., Donaldson, S. and Siegel, S., 2020. Ever-Present Cyber Threats. In Building an Effective Security Program (pp. 16-40). De Gruyter.
Looking for affordable assignment help online? Need someone to offer you prices that would go easy on your pocketbook? Bothered, “Can I pay someone to do my assignment at the best industry price?” Of course, you can. MyAssignmenthelp.co.uk has the finest paper writers. They are dedicatedly available to back you up with well-knit assignment papers at the best industry price.
Sign up for finance assignment help or management assignment help and enjoy a flat 20% off along with an additional $20 sign-up bonus. How cool is that? So, think no more and count on our expertise for affordable assignment help in the UK.
Upload your Assignment and improve Your Grade
Boost Grades