- One question that vexes security engineers, incident responders and lawyers is whether a ransomware attack constitutes a reportable data breach under any of the various data breach disclosure laws, regulations or other requirements.
- As a general rule, a ransomware attack, such as a DDoS attack, demonstrates a vulnerability in a system but probably (always equivocate) does not result in the exposure of the data.
– Mark Rasch | August 24, 2020