06 / AFTER THE RANSOMWARE
Why the ANCPI follow-up matters.
After a confirmed ransomware incident, public statements emphasized recovery, safety and remediation. A later public audit still observed controls worth fixing or explaining, including HTTP without forced HTTPS and DMARC p=none. Those observations do not identify the ransomware entry point. They do create specific, answerable technical questions.
Questions an administrator can answer directly
Why is the public root still reachable over HTTP without forced HTTPS in the captured request?
Why is DMARC still p=none, and what is the staged enforcement plan?
Why did captured ANAF responses issue JSESSIONID without Secure, HttpOnly and SameSite?
Which captured hardening gaps have since been remediated, and on what date?