One in three security professionals recommend negotiating with cybercriminals to return or recover encrypted files, according to Threat Track Security.
While a survey found that 70% of respondents would not attempt to negotiate at all, 86% of security believe that their colleagues make intermediary agreements with cybercriminals.
About 40% of security professionals said that the company they work for is targeting cyber-criminals, and 55% of them are willing to negotiate.
Stuart Itkin, vice president of Threat Track, tells us:
[blockquote right=”pull-right”]“Whether data has been stolen by APTs or targeted attacks, or lost to ransomware infections, companies should reevaluate their cybersecurity strategies and incorporate the most advanced defenses as well as become somewhat “obsessive” about creating copies of their data. Rapid detection and elimination of threats, as well as the ability to recover encrypted data, will neutralize the incentives of criminals and ensure that security professionals do not have to face such dilemmas.”[/blockquote]
Security professionals working in industries such as healthcare and financial services responded that they were less likely to suggest negotiations with cyber-extortionists , with the “no” rates reaching 92% and 98% respectively.
The figures then show that 66% are concerned about the reactions of customers or employees whose data will be at risk of being exposed, should they learn that their company chose not to negotiate with the extortionists for the return of their data after the breach.
When asked what type of data would be traded, they replied:
- 50% would not negotiate for any reason
- 37% responded that they would negotiate for employee data, such as addresses, security numbers, etc.
- 36% would only negotiate for customer data (credit card numbers, passwords, email addresses, etc.)
- 30% for intellectual property reasons, such as software codes, R&D, etc.
- 26% for confidential data
- And 22% for financial data.
When asked what role they believe the government should have in investigating cyber extortion cases, they replied:
- 44% believe that the government should not be notified immediately and gain full access to corporate networks to aggressively investigate such an incident.
- 38% responded that the government should establish a legal framework and offer guidance to companies that are victims of cyber crime.
- 30% believe companies should have the option to notify the government
- And 10% say the government should consider negotiating with cybercriminals a crime.



