Ransomware & Incident Response
Ransomware Initial Access
Most ransomware intrusions begin with phishing or exposed remote access services.
What it is
Ransomware groups gain initial access through phishing emails delivering malware loaders, exploitation of public-facing vulnerabilities in VPN appliances and RDP servers, or purchase of access from Initial Access Brokers (IABs) who sell pre-compromised environments. CISA's Known Exploited Vulnerabilities catalog tracks dozens of perimeter device CVEs actively exploited by ransomware groups.
Attack techniques
- Phishing with malware attachment (T1566.001)
- Exploit of VPN/RDP vulnerability (T1190)
- Purchased initial access via IABs
- Valid account abuse (T1078)
- Drive-by compromise (T1189)
Business impact
Initial access is the start of a multi-day intrusion that culminates in encryption. The window between initial access and encryption has been shrinking — averaging 2–5 days in recent ransomware campaigns. Detection during this dwell period prevents the ransomware event entirely.