How is applying good security controls not in their best interest? Right now, companies are transferring the risk to insurance, instead of investing in good security.
It is in their best interest. That's my point. As time goes by, companies will put more effort into security and other mitigation procedure. They are already starting to. I know the company I work for is. Without having a law that outlaws paying ransom I might add.
Regardless, the problem gets worse over time as payments are made, making the RISKS greater for everyone! Paying ransoms is a short term fix that creates a long term cancer. Without change, more and more companies will go out of business because of ransomware (current stats show between 60%-90% of SMB are out of business within 2 years of a cybersecurity incident).
Isn't it the responsibility of those companies to do what is necessary to mitigate those risks? If 60-90% of companies go out of business now because of ransomware (it would seem to me that "cybersecurity incident" might encompass a lot more than ransomware though?), what will that percentage be if paying ransoms are outlawed? Fewer attacks? Maybe... A higher percentage of those attacked going out of business? Almost certainly.
There are no silver-bullet technical solutions! There won't ever be anything that can block all the potential attack vectors. The way to stop these attacks is to target the motivation of the attackers themselves.
There are no silver bullet laws either. And while there are no silver-bullet technical solutions that will block all ransomware, having good backup plans and procedures in place IN COMBINATION WITH whatever technical prevention solutions are available can make successful attacks less likely and recovery cheaper than ransom thereby solving the problem, at least better than any law. Why is it you think having proper backup procedures in place won't accomplish this? Why would you need to pay a ransom if you can restore the vast majority of your data from your own backups? I wonder how many companies have paid a ransom a second time because of another attack?
RE: Paying Ransomware Should be Illegal