Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security.
This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good defense over dedicated phishing attacks.
Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected].
Anonymity is available upon request.
Both stories come courtesy of Dave Hatter, a cybersecurity and compliance consultant with Intrust IT.
In his many years of experience with the company, Hatter has had to work for a variety of small companies that needed help with their security, whether they knew it or not.
One time several years ago, the new CFO at a small construction company phoned Intrust and expressed interest in hiring them.
However, the proposal was vetoed by the owner of the company, an older gentleman who thought his business was too small to interest hackers and that his existing, one-person IT staff was all he could afford.
“We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys,” Hatter quotes the owner as saying.
“We hear this all the time.
Thanks for shopping.
You’re too expensive.” Three weeks later, Hatter got a call from a local accountant friend who begged him to help a client who'd been hit with a ransomware attack.
Hatter said he couldn’t really give more than general guidance, but would talk to the victim anyway.
As soon as he called the number, Hatter realized that the ransomware victim was actually the same construction company that had turned down his services a few weeks earlier.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.