Linus Neumann: „Wir schützen keine IT, wir schützen Unternehmen.“
Linus Neumann is an IT security consultant, qualified psychologist and spokesperson for the Chaos Computer Club (CCC). Based in Berlin, he has worked on cybersecurity, digitalisation and digital policy issues for many years and regularly contributes expert evidence to political and public debate, including before the German Bundestag. Neumann is also widely known as the co-host of the weekly podcast “Logbuch:Netzpolitik”, which he produces with Tim Pritlove. His incisive analysis and ability to explain complex issues clearly have made him a prominent voice in Germany’s digital policy and IT security community.
Mr Neumann, you often negotiate with cybercriminals on behalf of companies. What do those conversations involve?
Linus Neumann: Let me begin by saying that, as a cybersecurity expert, my priority is to ensure my clients never reach the point where those conversations become necessary.
But sometimes they are unavoidable …
Of course. The ransom note is usually left as a text file wherever the ransomware has spread. The attackers usually leave a ransom note as a text file across every part of the system reached by the ransomware. It typically contains a link to a hidden service on the dark web, together with a username and identification code, although some groups communicate through Telegram or other platforms.
What happens next?
Then the negotiation begins. As both a psychologist and a hacker, I find the dynamics particularly interesting. Although the process generally follows a fairly simple game-theory model, people often misunderstand how extortion works. I can usually tell very quickly whether we are dealing with experienced criminals or amateurs, whereas companies understandably find that much harder to assess s while facing the potential consequences of interrupted sales operations or the publication of sensitive data. My role is to give them the information they need to weigh those risks and reach a rational decision.
But surely paying should never be an option?
Paying criminals is never desirable. We all have a shared interest in stopping these attacks and dismantling the business model behind them, but an individual company facing an existential crisis sees things very differently. It can be difficult to argue that victims should act for the common good by refusing to pay if doing so could destroy their business. I do everything I can to give companies compelling reasons not to meet the attackers’ demands, but payment cannot always be avoided. The only real solution is to prevent companies from reaching that point by having secure backups and effective recovery and protection plans in place. Businesses need to recognise that prevention and resilience are the only way to put an end to ransomware. One security officer once told me that his company’s website states it will never pay a ransom, in the hope of deterring attackers. Since publishing that statement, he said, the company had paid only twice. Unfortunately, I repeatedly encounter a similarly troubling attitude, even after a security incident. Some companies still decide they would rather pay criminals every two years than invest in making their business more resilient.
That would clearly make more sense. What can companies do?
There are many aspects to consider, but backups are an obvious priority. Many companies have them, yet they may be outdated, difficult to access or so extensive that restoring them would take weeks. Companies need to identify the data they genuinely require to resume operations the following day. Usually, only a few gigabytes are essential, but those critical files need to be identified in advance, securely stored and immediately accessible.
Returning to the negotiation itself, what matters most to you?
I try to convince the attackers that the company can recover without them and does not need their help to decrypt its data. Projecting that level of confidence is difficult for people directly affected by the crisis, whereas I am not emotionally involved, understand the technical issues and know how these cases unfold. The attackers want something, usually money, so destroying every prospect of an agreement is rarely in their interests. The company and I can use that to our advantage. The growing frequency with which stolen data is published on the dark web also suggests that the original ransomware model is no longer effective enough on its own to remain sufficiently profitable for criminals.
If everyone wants to avoid these negotiations, why do so many companies still find themselves in this position?
After 15 years in consulting, I still encounter the same silos: the business operates here, IT over there and cybersecurity somewhere else entirely. In most companies, the three groups rarely communicate properly, which is a serious problem. Their performance is also measured and rewarded differently, sometimes against conflicting objectives. I do not have a simple solution, but I do know that these teams need to work far more closely together and fundamentally rethink their approach. We’re not protecting IT. We’re protecting businesses. Once you adopt that perspective, IT systems have to be resilient enough for someone to click the wrong link in the wrong email without causing serious harm.
Companies can prepare for that before a crisis occurs.
Exactly, during what we might call peacetime. That is the opportunity to examine the company’s processes, organisational structures and IT environment as a whole and ensure they work together. Once a crisis hits, organisations often go into headless-chicken mode, with everyone rushing around in different directions.
How do you respond?
By remaining calm, restoring order, establishing priorities, communicating objectives and asking the right questions. What would emergency operations look like? Nobody knows? Fine, then we work it out together. We also establish the status of the backups, because reliable backups are ransomware’s natural enemy.
What does a secure backup setup look like?
The first rule is never to connect the backup server to Active Directory. If attackers gain access, they can simply instruct the server to reformat the drives and then continue their attack once that vital defence has been removed. Companies also need to reduce their attack surface as far as possible, which includes restricting administrative access. Effective backups require careful planning, but there are plenty of viable options, both on premises and in the cloud. They are the starting point for a recovery plan that companies can develop calmly and thoroughly before an attack places them under acute pressure.
Is AI putting even greater pressure on cybersecurity?
AI is already making highly sophisticated social engineering possible, but that is only the beginning. Claude Mythos recently attracted considerable attention because it taught itself to identify security flaws in code without having been explicitly trained to do so. When Anthropic’s red team evaluated the model’s cyber capabilities, Mythos discovered numerous serious vulnerabilities, including in decades-old code that had long been considered highly secure. It can also write working exploits for those vulnerabilities at remarkable speed and with a high success rate.
Where is AI making a practical difference today?
AI can identify vulnerabilities, but it can also help developers write more secure code, and I say that as someone who works for a company offering code audits. Through Project Glasswing, Anthropic has made Mythos available to teams responsible for major software products and projects, including the Linux kernel, key open-source packages, Microsoft, Apple and Firefox. All of them are now working through large numbers of vulnerabilities and developing the necessary fixes.
What does that mean for companies?
The time between discovering a vulnerability and exploiting it is shrinking dramatically. With Mythos, and soon other models too, that window is approaching zero. Companies therefore need infrastructure that can be patched both quickly and frequently, which many existing environments were never designed to support. Containerised architectures, for example, are much better suited to that requirement.
Let’s turn to one final issue. How much do regulation, legislation and compliance actually improve security?
We certainly do not suffer from a lack of regulation, and I believe each additional requirement now offers only marginal benefits. More importantly, the overall system of rules and incentives often encourages companies to treat security as a compliance exercise rather than a technical, organisational and cultural responsibility. Meeting compliance requirements and achieving genuine technical security are not always the same thing.
And that creates problems.
Absolutely. Organisations end up focusing on compliance rather than security, treating completed checklists as evidence that they have done everything required. If an incident occurs, those responsible can simply say, “Look, we ticked every box. We did what was expected of us, so you can’t blame us.” Put bluntly, how much do policymakers really understand about cybersecurity?
Who bears the brunt of this?
Small and medium-sized businesses. Their already limited staff spend far too much time working through compliance checklists. In the worst-case scenario, they turn to a small local provider that applies the same security model to every business in the area, magnifying the risk even further.
Because it fails to account for different business models and requirements?
Yes, but the deeper problem is the divide between those who understand the business, such as managing directors and team leaders, and those responsible for IT. No one sees the whole picture. I’m convinced that the right solutions can only be found when business, IT and security work together.