WannaCry: Sometimes you can blame the victims

Last week’s big malware outbreak caused a lot of damage, but organisations that made good decisions ahead of time weren’t affected

By Ira Winkler
May 17, 2017

As I write in Advanced Persistent Security, there is nothing wrong with making a decision to not mitigate a vulnerability if that decision is based upon a reasonable consideration of the potential risk. In the case of decisions to not properly patch systems or implement compensating controls, though, we have more than a decade of wake-up calls to demonstrate the potential for loss. Unfortunately, too many organizations apparently hit the snooze button.


