Lately I’ve been dealing with a lot of ransomware cases. And often our team runs into issues with the IT staff from the victim organization.
33
260
56
1,306
Whether they’re embarrassed or afraid of being shown up or for whatever other reason, they’re uncooperative or in some cases actively working against our investigation.
2
6
1
252
So on a recent case, during our engagement kick-off call, I laid it out like this. “We’re going to investigate and figure out where this started. And it will be an unpatched system, or somebody clicking a link, or somebody just being unlucky with a web site they visited.”
3
14
3
263
“And NONE of that is YOUR FAULT. All organizations are vulnerable, because I have yet to meet an org whose security budget exceeds their attack surface.”
4
22
3
377
“You are not the assholes here. The assholes are the ones who took that vulnerability and used it to drop ransomware all over your network. Just because you forgot and left your door unlocked doesn’t make it right for somebody to come in and trash your place.”
4
15
1
303
Did you actually use the word "asshole" in your kickoff?
2
Replying to @tbrzl
Yes, I actually did. It was at least authentic, if not completely professional.

Jul 19, 2021 · 3:05 AM UTC

1
2
Replying to @hal_pomeranz
If the audience is right, it works 👍