No matter how much money you spend on security, all it takes is that one dopey employee/intern to trip on malware and fuck your entire network over. In the case of small municipalities like this one, in almost all instances if paying up is really the only pragmatic option because decrypting is unlikely and replacement costs are usually going to be higher. The best defense for this is routine off-network backups.
|