Hacker News new | ask | show | jobs
by gruez 1805 days ago
Make it strict liability? ie. if you paid for a "consultant" and it just so happens that he paid off the ransomware operators without your knowledge, you'll still be liable
2 comments

That's going to be nearly impossible to enforce, because the first thing that will probably happen is that companies will stop reporting ransomware attacks. And these "consultants" could be based anywhere, as well as further outsource their work to independent contractors, shell companies, etc. So getting hard evidence that's there's been a ransom payment will likely be a wild goose chase.
That would run against law as it stands in most places https://en.wikipedia.org/wiki/Mens_rea
That would be the "strict liability" part.