Newsletter Article

THREAT SPOTLIGHT:RANSOMWARE IS NOW AN INVESTIGATION OF ACCESS, THEFT, AND DISRUPTION

Snare Insider Newsletter Series Article

Make sure you Subscribe

This issue’s spotlight follows straight on from Issue 12’s SIEM Cost Paradox: ransomware is where indiscriminate ingestion fails most visibly, and where investigation-ready logging pays for itself most directly. Encryption is frequently only one stage of a broader intrusion — and by the time it triggers an alert, the evidence an investigation needs may already be sitting in the wrong tier, or may never have been collected at all.

77%

of ransomware intrusions Mandiant responded to in 2025 involved suspected data theft — up from 57% in 2024. Virtualisation infrastructure was targeted in ~43% of incidents, up from 29%. [6]

Recent reporting also described an incident in which attackers moved from an IIS webshell to network-wide encryption in less than 24 hours, using administrative tools to move laterally, disrupt backups, and disable security services. Waiting for encryption activity to trigger an investigation is already too late — the evidence of ransomware often appears much earlier:

  • Exploitation of an internet-facing system, or unusual remote administration.
  • Credential dumping, authentication anomalies, or privileged account creation.
  • Lateral movement and endpoint security-control changes.
  • Backup discovery or deletion, and virtualisation-management access.
  • Large-scale file enumeration, data staging, and exfiltration.

The Logging Implication

Ransomware readiness depends on being able to reconstruct the entire intrusion, not just the final encryption event. Security teams should be able to answer:

  • What was the original point of entry, and which account was first compromised?
  • Where did the attacker move, and which administrative tools were used?
  • Were endpoint protections modified, and were backups accessed or disabled?
  • Was data exfiltrated before encryption?
  • Which systems require isolation or credential rotation, and is there evidence of an additional backdoor?

Why this matters more after Issue 12

An organisation that pays for high-volume, low-fidelity SIEM ingestion can still be blind at the exact moment it matters most.

Reconstructing a ransomware intrusion end-to-end requires endpoint, identity, network, application, remote-access, backup, and virtualisation logs to be available together but only if they were collected, normalised, and retained with intent, not simply ingested at volume.

Free eBook

The Ransomware Investigation Playbook

What to log, retain, and query before, during, and after a ransomware intrusion — mapped to the intrusion stages above, with source-by-source retention guidance.

Snare Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.