Encryption is the last step, not the attack
The moment files become unreadable is the end of the attack, not the beginning. By then an intruder has typically been present for days or weeks. That dwell time is the defensive opportunity: every stage before encryption is a chance to detect and interrupt.
The typical sequence
- Initial access through phishing, exposed remote access, unpatched internet-facing services, or credentials bought from a broker
- Persistence, so access survives reboots and password changes
- Privilege escalation toward administrative accounts
- Lateral movement to map the environment and locate valuable systems
- Targeting backups, because recoverable backups remove the leverage
- Data theft before encryption, enabling extortion even if you can restore
- Encryption, usually timed for evenings, weekends, or public holidays
Why extortion changed the calculation
Reliable backups used to be a fairly complete answer. Attackers adapted by stealing data first, then threatening publication. Restoring from backup solves availability but does nothing about a threatened leak of customer records. Under POPIA and similar regimes, that leak is also a reportable breach with regulatory consequences.
Some groups add further pressure by contacting customers, partners, or regulators directly.
What genuinely reduces risk
- Offline or immutable backups an intruder with administrator rights cannot delete
- Multi-factor authentication on all remote access, which closes a large share of initial access
- Prompt patching of internet-facing systems, prioritised by known active exploitation
- Network segmentation, so one compromised machine does not expose the whole estate
- A tested recovery plan, because untested backups fail at the worst possible moment
- Detection tuned for the middle stages, particularly unusual privilege use and mass file access
Related in the Knowledge Base
- Social Engineering: Why People Remain the Reliable Attack Path
- Incident Response: Playbooks, Forensics, and Why Preparation Wins
- IAM and PAM: Controlling Who Can Reach What
Know what an attacker sees before they do.
A practical exposure checklist covering the gaps that cause most breaches, plus what POPIA actually requires you to have in place.
Free PDF · No spam · Unsubscribe anytime