These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.
Ransomware negotiations: What CISOs should know before negotiating
Intel 471 has written an article discussing how organizational leaders should approach ransomware negotiations. Deciding to engage in negotiations should be a careful business decision, not a rushed technical response. It stresses that owners should plan in advance who will make decisions, involve legal and insurance advisors early, and understand that negotiating is often about gaining time, confirming whether attackers can actually unlock systems or delete stolen data, and limiting damage, rather than simply paying to “make it go away.” The article cautions that communicating directly with attackers without experience can increase costs and risks to the organization and recommends using trusted third‑party incident response or negotiation specialists when possible.
Analyst Comments: Despite their nonprofit status and smaller size, Houses of Worship (HOWs) face ransomware risks similar to other critical infrastructure sectors, particularly from opportunistic “spray‑and‑pray” attacks exploiting common network vulnerabilities. Leadership should proactively plan their ransomware response, including whether and how to engage with attackers. Organizations with cyber insurance may be required to work through an approved negotiator, while those without coverage should carefully plan any direct engagement in advance, as rushed decisions often benefit threat actors.
The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.