It's so ineffectual, i'm so sick of hearing about data-breaches, and then the outcry for data 'privacy'. We need data-protection. Encrypt that sh##! then, even if it's stolen, the f###ers can't read it !?
It's so IT-infra 101 i can't believe it's still happening. Legislate for encryption, why hasn't that happened? Anywhere?
Tell me of a country that's legislated for encryption of commercially-derived data stored on web servers and i'll give 100 quid in that country's currency to the charity of your choice.
I can't believe it's not the law, it would totally null any data-theft.
I've spent the last 3 weeks helping a local company decrypt and restore data after a Scarab ransomware attack, the attackers not only ran the encrypt with a seperate key on every connected device, they also deleted data from the server that they didn't have space on the victim's local drive to encrypt (Scarab doesn't delete each individual file after the encrypt, it does a bulk-deletion after encryption, that's a design flaw). I did have a point but the beer has erased it.
Encrypt! Encrypt! Encrypt!