Newsletter Article
THREAT SPOTLIGHT:RANSOMWARE IS NOW AN INVESTIGATION OF ACCESS, THEFT, AND DISRUPTION
Snare Insider Newsletter Series Article
Make sure you Subscribe
This issue’s spotlight follows straight on from Issue 12’s SIEM Cost Paradox: ransomware is where indiscriminate ingestion fails most visibly, and where investigation-ready logging pays for itself most directly. Encryption is frequently only one stage of a broader intrusion — and by the time it triggers an alert, the evidence an investigation needs may already be sitting in the wrong tier, or may never have been collected at all.
77%
of ransomware intrusions Mandiant responded to in 2025 involved suspected data theft — up from 57% in 2024. Virtualisation infrastructure was targeted in ~43% of incidents, up from 29%. [6]
Recent reporting also described an incident in which attackers moved from an IIS webshell to network-wide encryption in less than 24 hours, using administrative tools to move laterally, disrupt backups, and disable security services. Waiting for encryption activity to trigger an investigation is already too late — the evidence of ransomware often appears much earlier:
An organisation that pays for high-volume, low-fidelity SIEM ingestion can still be blind at the exact moment it matters most.
Reconstructing a ransomware intrusion end-to-end requires endpoint, identity, network, application, remote-access, backup, and virtualisation logs to be available together but only if they were collected, normalised, and retained with intent, not simply ingested at volume.
Free eBook
The Ransomware Investigation Playbook
What to log, retain, and query before, during, and after a ransomware intrusion — mapped to the intrusion stages above, with source-by-source retention guidance.

Identity Has Become the Attack Path