A tale of 2 casino ransomware attacks: One paid out, one did not - What can be learned from MGM’s and Caesars’ infosec moves::What can be learned from MGM’s and Caesars’ infosec moves

  • JJROKCZ@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    2
    ·
    6 months ago

    Most of our vendors only make products for windows, barely understand windows and certainly don’t understand Linux or as400, and they dont intend to. Those that do run Linux and as400 are actively transitioning their systems to a windows based version as it’s easier for the casinos to maintain.

    Source: IT Director for a casino company and responsible for hundreds of windows servers, thousands of PCs, 12 Linux and half a dozen as400s - I’m not with Caesars or MGM thank god but their breaches caused me a ton of work and lost sleep trust me

    • fruitycoder@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      6 months ago

      Yikes. I’ve seen that strat before. Dinosaur vendors are the worst. My only advice to focus on replacing bad vendors like that wherever and whenever you can, getting stuck actively building out an already legacy system sucks. Good luck!

      The “Adopt, Buy, Build” strategy is good one as well as the “strangler pattern” to help keep you from entrenching your self in shitty systems.