Skip to content

Problem

In a wiper attack there is nothing to decrypt.

The only way back is restoration.

With ransomware there is at least a key. With a wiper there is none. Nothing to negotiate, nothing to decrypt, nobody to pay. The only way back is restoration.

Two cases, both publicly documented:

~6 months NotPetya 2017 at Merck: tens of thousands of machines disabled; restoration took around six months.
9 days At Maersk roughly 49,000 endpoints were affected. Bringing back the identity infrastructure alone took nine days.

Both companies had detection. Both had backups. What was missing was the layer in between: a verified, ordered, automatic return to operation.

Reader view