Ransomware in 2026: Encryption Is the Last Step. Detect the Four That Come Before It
The encryptor is the terminal event, not the attack. Detection didn't vanish when breakout hit 29 minutes. It relocated to the pre-encryption phases.
14 posts
The encryptor is the terminal event, not the attack. Detection didn't vanish when breakout hit 29 minutes. It relocated to the pre-encryption phases.
CTEM is not new, the integration is genuinely valuable, and the 'CTEM platform' is mostly rebranded BAS/ASM/RBVM. Buy the operating model, not the acronym.
The de-skilling fear has a long track record, and it usually turns into upskilling. Whether AI does that for your SOC is a deployment choice, not fate.
Lateral movement moved to the cloud control plane. Each hop is individually authorized, so single-event rules miss the chain.
216 technique IDs are not a decision surface. Translate detection coverage into named threats against crown-jewel assets, in dollars, with drill-down.
LOTL didn't add binaries. It commoditized chaining and moved to where EDR can't run. Stop detecting the binary. Detect the chain.
MTTD and dwell time only exist after a breach and reward alert volume. Keep them as the board scoreboard; steer your program on leading indicators.
XZ, tj-actions, Shai-Hulud, Codecov all owned the build, not the code. Scanning is blind to a poisoned build in flight. Detect the runner instead.
92% of identities are over-permissioned and creep leaves no log line. Stop treating the blast radius as cleanup. Instrument it instead.
Most CTI programs measure IOCs ingested and reports published: activity, not effect. Here's what operationalized intelligence actually looks like.
Most teams 'do DaC' by putting Sigma in a repo. That's the easy 20%. The capability that scales is a tested lifecycle, not a toolchain.
You have ~45 non-human identities per human, and the signals your detection runs on (MFA, impossible travel, login geo) don't exist for any of them.
MFA fatigue has a MITRE technique ID. SOC alert flooding doesn't. Same deliberate tactic, different target, and why your defenses keep failing.
ATT&CK coverage % looks good in board decks. Here's why it compounds into a ~6% actual catch rate, and what Threat Detection Coverage actually means.