Surviving modern ransomware
Ransomware attackers now have AI on their side. Get the playbooks IT teams use to detect, contain, and recover—plus a hands-on breach simulator.
Over the past few years, ransomware has evolved into one of the most pressing threats facing organizations and the IT professionals tasked with defending them. Ransomware attackers have embraced AI and cutting-edge tools to more effectively deceive employees, encrypt stolen data, and target vulnerable infrastructure.
Yes, it’s an intimidating problem, but cybersecurity experts have done excellent work figuring out how to mitigate this threat. In addition to employee education (“Don’t click on those suspicious links!”), organizations everywhere are adopting effective playbooks for ransomware attacks, including whether to pay ransoms, how to shield the tech stack against future attempts, and how to detect intruders before they penetrate too many systems.
This e-book will cover some of those defensive techniques, as well as the long-term impacts of attacks. In addition to articles, there’s also “Block the Breach,” an interactive ransomware simulator that gives you the reins of an IT team during a (hypothetical) ransomware intrusion, offering first-person insight into tactics that can help transform a potentially catastrophic day at the office into merely a bad one.
What’s Inside
Table of Contents
Chapter One
Evolving threat
- Not-so-fun facts to know about ransomware in 2026
- How a ransomware attacker thinks
- What to expect when you’re expecting a ransomware attack
- How much control does an IT pro really have when a third-party platform gets hit
Chapter Two
Fighting back
- The costs of protecting identity
- What they’re saying: How to handle a ransomware attack
- Should you pay ransomware actors?
- How to communicate during a ransomware attack
- How to start talks with a ransomware group
Chapter Three
Deepening IT defense
- Developer tips: How to keep malicious packages out of your codebase
- Asking around: When does ransomware threat intelligence become noise?
- Cybersecurity professionals say high-profile incidents boost execs’ credibility
- Block the breach: a ransomware game

Not-so-fun facts to know about ransomware in 2026
Even ransomware groups celebrate Black Friday.
Like a Pokémon with just the right number of experience points, the ransomware industry is expected to evolve in 2026.
That’s according to NetNordic Threat Intelligence Lead Analyst Santeri Anttila, who told IT Brew on the sidelines of the Live! 360 Tech Con in Orlando that the threat is growing more sophisticated as malicious actors gain access to tools like ransomware-as-a-service and initial access brokers, who are threat actors selling unauthorized access to corporate networks.
“Previously, there was only one group, and now there’s maybe more than 10 different specialized types of predators,” Anttila said.
Sami Laiho, chief research officer at IT company Adminize and speaker alongside Anttila at a Nov. 18 keynote on the state of ransomware, added attackers are hurling more double extortion attacks, which is when they encrypt stolen data and threaten to sell it.
“You basically extort it for two different types of attacks now, and usually both are done at the same time,” Laiho said.
Ransomware not-so-fun facts
During the keynote on the state of the ransomware industry, Laiho said many people still believe that ransomware attacks are deployed by “nerds in the basement with two computers and 1,000 SIM cards.” However, the reality is that ransomware groups are far more sophisticated entities.
“They don’t understand that these groups are very big. They’re like companies,” Laiho said during the panel, adding that ransomware groups can employ so many people that they require their own HR departments.
Anttila said ransomware demands today can range anywhere between $20,000 to $80 million.
“They have a really good financial department over there, so they can really estimate the ransom demand in a way that they most likely get paid,” he said.
But fear not: Laiho said malicious actors aren’t above holiday discounts and other seasonal promotions.
“I actually have a customer that got 50% off the ransom because it was Christmas,” Laiho said. “So, that’s really nice. That’s the customer service I know we really value,” he joked.
Avoiding security theater in 2026
With growing ransomware threats, the conversation is no longer about how to avoid breaches, but rather, how to mitigate the impact, according to Laiho.
“What I try to tell everyone that I ever speak about security to [is]...that your job is not to stop the enemy,” Laiho said. “Your job is to slow it down.”
Laiho and Anttila’s tips for organizations to better defend themselves against ransomware attacks in 2026 aren’t anything out of the ordinary. Anttila recommended companies keep users educated on ongoing threats and what to do in the event something goes wrong, and Laiho advised companies to master the principles of least privilege and zero trust.
“If you have an attacker that gets a straight line into the company, it doesn’t look that different,” Laiho said. “But when we make them swim sideways multiple times, then it becomes an anomaly, which is then easier for the reactive side to actually detect because it’s abnormal behavior.”
How a ransomware attacker thinks
“It’s Whac-a-Mole, or a game of cat and mouse, between defenders and attackers,” one cybersecurity leader says.
What are they thinking?
When it comes to ransomware criminals, the answers can vary. Some organizations are sophisticated businesses where hackers are treated as employees with HR departments and paid time-off, while others are more ramshackle.
But they’re all dangerous—and after your data. Mike Puglia, general manager of cybersecurity labs at Kaseya, told IT Brew that financial motivation has been the constant motive of ransomware attackers. The tactics are much the same between groups: gaining access, exploiting vulnerabilities, escalating privileges, and deploying an encrypter to hold the data for payment.
“It’s Whac-a-Mole, or a game of cat and mouse, between defenders and attackers, and as soon as one hole is closed, suddenly the next wave comes,” Puglia said.
Undetected
Threat actors can lurk inside systems for months before taking action. They infiltrate via a number of different techniques, including social engineering, and once inside they conduct reconnaissance to get ready to exfiltrate data, encrypt your backups, or both.
Meanwhile, attack speed and efficiency are increasing. Attackers often work as teams with different workflows and responsibilities. It’s important to understand that these groups can be as professional as the institutions they target, said Chris Hendricks, head of incident response at Coalition.
“This isn’t just a slapdash setup; this is big money and big organization and a lot of people, and as they get better at running their nefarious business, it means a faster impact on the side of our customers,” Hendricks said. “The good news, of course, is that our customers are getting smarter about responding. So, it’s a back-and-forth.”
Ways in. Attackers use varied tactics, including software-as-a-service and outsourcing to third-party vendors who charge for their services, often asking for a portion of the proceeds in cash or crypto.
“Ransomware gangs have great partner programs,” Puglia said. “They will allow access and they will get 30% of the take; you’ll use their systems, and they’ll collect the cryptocurrency, and they’ll keep 30% of it.”
It pays off, as Maël Le Touz, senior threat researcher at Infoblox, told IT Brew in January.
“These criminal gangs are not just doing this because it’s fun. They’re doing this because it’s very, very profitable, and there is very little law enforcement and very little risk for them being involved,” Le Touz said.
Tactical demand
Once they’ve compromised a system, attackers reach out with the ransom demand. Paul Caiazzo, the chief threat officer at Quorum Cyber, emphasized the importance of using a third party to conduct negotiations. In some cases, a threat actor will leave instructions for how to get in touch with them that is typically “a chat you’re going to find on the dark web someplace.”
“We would never recommend any clients jump on one of those negotiation chats with a threat actor, don’t even click the link,” Caiazzo said. “By going to the threat actors page, they’re going to be able to learn some things about you, and there’s a potential for additional risk to come to you as a result of that.”
If an untrained individual does interact with them, Caiazzo warned that saying the wrong thing could derail the entire defense operation quickly. Hendricks agreed, advising that organizations shouldn’t engage with attackers without talking to a professional first.
“Even if you don’t choose to make a payment, you might still choose to talk to them, but through a third party,” Hendricks said. “It can be really beneficial to learn that you have these options, that there are people who can do this in a smart way and protect you, whatever decision you choose to make.”
What to expect when you’re expecting a ransomware attack
“It’s like when you’re trying to walk through a muddy area or something, you’re going to get dirty at some point,” Kaseya CISO says.
What’s the best piece of advice a seasoned cybersecurity professional can give? Cybersecurity is a team sport.
“Take time now to understand how others think, how to relate to others, how to communicate effectively to others,” Jason Manar, CISO at software company Kaseya, told IT Brew. “We are totally reliant on other members throughout the company to implement cybersecurity practices that we are recommending.”
Manar, who was previously with the FBI as a cyber supervisory special agent, said there’s never been more pressure to keep organizations secure. With that in mind, he sat down to discuss the best practices for a ransomware attack.
This interview has been edited for length and clarity.
When we’re thinking about ransomware attacks, we know that some folks might get swept into the moment and chaos. In your experience, how worthwhile is having a good plan for if an incident occurs?
You do not come away unscathed in any kind of cyberattack. It’s like when you’re trying to walk through a muddy area or something, you’re going to get dirty at some point. So, those that usually navigate this the best are those that have planned and have had preparation. The “why” is because they will have…training that they can fall back on. Not every scenario is the same, but they know who to contact. They know who to get inside war rooms. They will know who’s going to be the incident commander, and they already have all this preplanned. In fact, they’ll have cyber insurance.
When you’re talking about resiliency and getting back up on your feet and limiting the impact to the business, that’s what you want. So, you have to be prepared, and you have to go through it, and you have to have buy-in at the top levels. As we say, it’s not a matter of if something happens, it’s when something [happens]. There is going to be an action that you have to take, whether it’s in relation to a ransomware or another actor inside your environment is going to cause you to initiate your incident response plan, which is why it’s so important to prepare.
What is something that you can’t plan for when your organization is experiencing a ransomware attack?
You can’t plan for the unexpected, and there’s always going to be something unexpected.
There was a company that was getting ransomware in real time, they reached out to their [CISO] who was overseas…the CISO had shut off his phone, ceased communication with the company, and tendered his resignation within six hours of the event.
Trying to expect the unexpected just comes back to resiliency, and it comes back to our planning and preparation conversation that we had originally, which is why it’s so important and so critical to understand what your critical systems, your crown tools are, so that you have resilience planned into when something happens. Not necessarily just an incident, but any kind of interruption of services, any kind of interruption of services, whether you’re a cloud entity or in a data center, so that you’re prepared and you have an additional plan that you can revert to, so you don’t lose your continuity of…the system that you’re working with.
Which experiences have you had that lead to what, in your opinion, is the most successful way of handling a ransomware incident?
The most successful that I’ve seen are those where everyone understands—when I say everyone, I mean the board, the executive level, all the way down to the individual contributor—understands not only their role, but understands that you are dealing with an event that is constantly evolving and constantly changing. So, understanding that takes preparation, and that’s why these tabletop exercises and communication are so important.
Typically companies that would do really well had regular security briefings, not only at the executive level, but also at the board level.
I can’t tell you how many boards of even Fortune 500 companies…I talked to about cybersecurity, and not only nation-state threats, but just threat actors in general, and providing them an overview of what the landscape looks like. Walking out of there, it was very clear that of at least 95% of the board that I talked to, they didn’t fully understand the risk of the adversary that they were up against, or they believed that their security personnel was overexaggerating the risk.
Whether it’s [an] independent third party come in, whether it’s having a law enforcement agency come in, having someone else come in…that tells that story to the board. Because at the end of the day, while we say boards are driven by metric KPIs, OKRs, etcetera, most boards, they’re interested in what that chief revenue officer says, and then every other metric taken with a grain of salt a lot of times.
I have found that, typically, those that are great storytellers are able to communicate and get across what that level of risk is and what that looks like.
How much control does an IT pro really have when a third-party platform gets hit?
We spoke with pros who advised on early preparations.
The school day was “a bit of a logistical nightmare” on May 8, according to Nikita Borisov, a professor of electrical and computer engineering at the University of Illinois Urbana-Champaign’s Grainger College of Engineering.
But it wasn’t your typical chaos: A cyberattack against widely used edtech platform Canvas locked college professors, high school teachers, and students out of assignments, messaging, video content, grades, and other classroom materials.
While the global downtime caused minimal disruption for Borisov (whose final presentations for students did not explicitly rely on Canvas, he said), some teachers had to figure out a plan when campus canceled exams on May 9.
Threat actors exploited a vulnerability related to the company’s “Free for Teacher” environment, according to a statement from Steve Daly, Canvas parent company Instructure’s CEO. The chief exec said the incident involved unauthorized access to information like usernames, email addresses, course names, enrollment information, and messages.
The hacking group ShinyHunters posted on their own site that they had stolen terabytes of data from Canvas linked to nearly 9,000 schools worldwide.
When platforms go down, either by misconfiguration or miscreant, can an IT pro actually soften the impact? We spoke with two security pros about important preparations.
Map your dependencies
According to Brandon Blankenship, CISO at cybersecurity company ProCircular, a team involving IT, legal, operations, and main players (say, professors) need to do an internal audit ahead of any compromise to define:
- Critical business processes (teaching and grading, for example)
- The core systems supporting those business processes (say, Canvas)
- The under-the-hood systems (dependencies) that the core systems need (like databases or identity management)
Next, Blankenship recommends that leaders discuss reasonable expectations for recovery time and how much downtime an organization can tolerate.
“Senior leadership has to understand this too-big-to-fail company can and probably will fail for 48 hours, or 24 to 72 hours, and if that happens, either we tell people, ‘Go home and we’ll do tests three days later,’ or we try to have a completely redundant system, which is almost always too expensive at that scale,” Blankenship said.
Etay Maor, VP of intelligence at network security platform Cato Networks and an adjunct professor at Boston College (who thankfully got his grades in before the incident), said school leaders need to identify high-risk assets, and strategize redundancies where necessary. Maybe grades and lecture videos are considered critical and must therefore be backed up on an external system; maybe messaging is less important and schools can resort to usual email.
“You need to [know]: What happens if Canvas goes dark on me?” Maor said.
A business continuity assessment “should absolutely be done beforehand with the systems that matter the most, and I would usually recommend, the fewer the better,” Blankenship said, adding there’s no need to build up in-depth plans for a dozen systems. Pick the “absolutely most critical” ones and run through what needs to happen when those go down.
Make outages part of your disaster recovery plan, Blankenship and Maor advised.
Be ready to answer the ransom question
Instructure “reached an agreement” with the threat actors, according to the CEO’s statement. Orgs should also prepare to answer ransom-related questions and work with insurance companies (in advance!) to determine set points for payment, Blankenship advised.
“Thinking about paying or not paying is such an emotionally charged conversation that should be guided by people who have been through incidents before,” Blankenship said.
According to calculations from pro-consumer site Comparitech, ransomware actors took credit for 251 attacks in 2025—a steady number compared to 2024’s 247 incidents. However, 2025 saw a jump in compromised records: 3.96 million compared to 3.11 million in 2024.
Wait, wait, backup. Both organizations and individuals need to prepare for an outage. Borisov luckily didn’t rely too heavily on the Campus platform.
“Having copies of your grades, having copies of your course materials in multiple places might make sense to be more agile in responding to these things,” he said.
Blankenship wants to see more backup and planning instead of a blame game.
“The control we put in place is: stop blaming IT, and stop blaming Canvas and having professors and TAs, whoever’s in operations, have a viable workaround if that system is unavailable for 48 hours,” he said. “That’s the real answer, and that’s a conversation that not many people want to have.”

The costs of protecting identity
Is it better to pay now or later?
How much is your organization’s identity access security worth? With the average cost of recovery after a breach surpassing $1.6 million, according to a new study, it’s critical for organizations to balance the budgets for their cybersecurity needs.
Cybersecurity and threat intelligence company Sophos surveyed 5,000 IT and security leaders to understand how IT leadership is approaching issues around identity and cybersecurity. The report states 71% of organizations reported at least one identity-related security breach in the past year, with an average of three attacks per victimized organization.
Delinea defines identities as digital versions of employees that can access specific services and resources. As IBM details, threat actors target identities via phishing, credential theft, and more, with the goal of impersonating users and accessing systems. IT professionals can attempt to counter these attacks via stringent identity and access management (IAM) to manage users and access privileges.
John Shier, field CISO for Sophos, told IT Brew that organizations can’t ignore identity breaches, especially given the high costs of recovery. “That’s a lot of money, and in some instances, that money could be something that is very material to the business, especially when you’re talking [about] smaller, medium-sized businesses who just can’t afford this kind of thing,” Shier said. “They are also material to bigger organizations.”
Remediation costs could be dependent on the size of an organization. Shier wrote in an email that victims could incur incident response and forensic services, IT-related costs, downtime penalties, and post-incident investments.
“IT recovery and remediation costs for rebuilding systems, restoring data, and hardening controls after the attack,” Shier said. “Downtime and operational disruption costs represent lost revenue and interrupted business processes. Security uplift costs include post-incident investments in new tools, services, and improved readiness capabilities.”
The balancing act
Shier said that, before crafting a budget to secure enterprise IT, CISOs have to understand all of the risks, as well as the cost of mitigation, which can include technology, people, and other resources.
It’s not that organizations don’t understand the issue, Shier said, but rather that they face trade-offs. For example, a hospital system instituting cybersecurity measures like stronger authentication might risk slowing down patient care.
“Identity is really important, it’s just not always the most important in context to the business,” Shier said. “If it’s not central to the revenue generation or the delivery of your service, the investment decisions look a little bit differently sometimes.”
But identifying where organizations can effectively invest in identity protection and head off costs associated with recovery and mediation.
“Organizations don’t wake up every morning wanting better identity,” Shier said. “They want fewer support tickets, they want faster onboarding for new employees, they want smoother user experiences and lower costs, and sometimes identity is what actually makes those happen, but it’s not necessarily the end itself to those means.”
Saving by spending first
When protecting IT infrastructure against identity-based attacks, IT pros should look to eliminate friction, something that Shier said can wreck identity projects because of business priorities requiring that departments fix the most urgent things with the given resources, staffing, and money.
There’s also a need for preventative measures. Shier said organizations should incorporate continuous monitoring (for unusual login attempts) and similar tools. Additionally, Shier wrote in an email that investing in things like recovery capabilities can help in reducing post-incident costs
“Organizations reduce costs by detecting and stopping attacks earlier, limiting how far incidents progress and reducing downstream impact,” Shier wrote. “They improve outcomes by investing in incident readiness, including tested response plans and reliable, restorable backups.”
It’s also important for organizations to consider cybersecurity insurance against potential breaches. Shier suggested that identity protection could be critical in securing a policy, especially with insurance companies instituting stricter requirements.
“It’s a bit complicated, but it is a balancing act,” Shier said. “I don’t think that there’s a really great equation, or necessarily a rule of thumb that says you should do all this. It’s based on our business, our risk tolerances, our ability to respond.”
What they’re saying: How to handle a ransomware attack
Experts want those in IT to know about preparing for a potential ransomware attack, and organizations’ risk levels.
According to some experts, ransomware is one of the biggest cybersecurity threats facing the private sector today. It’s crucial that organizations understand the risk of being attacked and how to handle the event if it happens—including an emergency plan.
How much risk am I at? Ransomware affects “everybody left, right, and center,” according to Rishika Desai, a threat researcher and technical writer at BforeAI.
Experts like Paul Caiazzo, the chief threat officer at Quorum Cyber, agree with that assessment. He said that ransomware is “the most salient, pressing threat” for many organizations.
“There’s not a bigger, more disruptive cybersecurity threat that your average organization is going to face,” Caiazzo said. “There are some organizations that may be more concerned about espionage-related adversaries or attacks, but the ransomware scourge is so prolific that [it] doesn’t matter what size organization you are, whether or not you think you’re a target—you are a target, even opportunistically.”
Many ransomware attacks are identified and stopped before the actual ransom attempt, which makes it difficult to ascertain the attackers’ ultimate plans. However, according to Sophos Principal Threat Researcher Keith Jarvis, ransomware is “probably the largest slice” of the cybercrime pie.
Plans, plans, plans
It’s important for organizations to plan how to best deal with data held for ransom, and spend time with stakeholders to discuss a strategy to counter an attack.
Jarvis said, in an additional interview, that implementing strategies like end-point detection response and other tertiary response monitoring solutions can be helpful to know when a bad actor has slipped through a crack.
While preventing a ransomware attack isn’t always possible, early detection is a significant way to prevent bad actors from accessing a more important system or dataset after they have found access, Jarvis noted.
“The key there is to have monitoring of systems, which is where [endpoint detect and response] comes in, of what’s actually happening on a critical asset like a server or an appliance that’s out on the internet,” Jarvis said. “Maybe the threat actor can successfully exploit that and land on that system and start to do the reconnaissance and post-intrusion type activity that we expect, but a lot of that stuff is going to then raise flags.”
Additionally, having back-ups on hand through methods like 3-2-1 (the practice in which an organization is equipped with three copies of data, two types of storage, and one copy off-site), can keep data in a protected physical location or at a facility to ensure that there’s multiple records of data without worrying about additional tampering.
Caiazzo said the best-prepared enterprises spend time doing the “homework in advance, usually months in advance” through things like incident response planning, tabletop exercises, and more.
“They’ll have realized, if they’re doing…tabletop exercises, that they need to ensure that, first off, technical controls like backups have been implemented robustly and are available for recovery, should they need them in the event [of] ransom impact,” Caiazzo said.
He continued: “Maybe even more importantly, the group of executive stakeholders that always is involved in a ransomware situation has gotten together and talked through the scenario so they know who’s got what responsibility.”
Too many cooks
In the case of a ransomware attack, employees may want to be helpful where they can, even if they’re not included in the defense plan. This can quickly become an issue.
“We always talk to organizations about having an incident response plan, but also exercising that plan,” Alex Rose from Sophos said. “I think it’s really important that people know their roles and responsibilities and that you communicate. Because…[when] you don’t communicate, people fill that vacuum with whatever they’re thinking and try to do that both internally and externally.”
Rose said that employees reflexively trying to help can add chaos to an already tumultuous situation. That makes it important to clearly delineate everyone’s roles in defense.
Communication
During a ransomware attack, it’s critical for stakeholders to stay in touch with different parts of the organization. Rose said that third-party incident response organizations may provide communication infrastructure, since the threat actors may attempt to compromise communication systems.
If a company doesn’t hire an outside incident response team, Rose said certain employees should be selected to notify people during an event.
“Different levels of people, or different roles and responsibilities are going to require different types of notification,” Rose said. “The big concern we have is, even if you can use some of your comm systems, it’s understanding what’s compromised…because you also don’t want to be coordinating your plan on a system that they’re able to monitor.”
TL;DR
Experts want professionals to have a plan and stick to it in the case of a ransomware attack—which means having clear responsibilities for those in the company to either help or continue on operations in a different way.
Should you pay ransomware actors?
Experts say the choice could depend on the attack and the organization.
No one wants to pay criminals, least of all criminals who are ransoming sensitive data for an enormous sum. That said, should organizations targeted by ransomware consider paying for their data back?
Every organization has a different appetite for obeying cyberattackers’ requests for payment. Paul Caiazzo, chief threat officer for Quorum Cyber, told IT Brew that while some companies may initially refuse to negotiate a ransom, sometimes they’re forced to pay after losing a significant amount of operational time.
“My opinion is, if your organization is completely encrypted and you don’t have backups, their choices are to go out of business or pay the ransom,” Caiazzo said. “Obviously, the better choice is to pay the ransom in those situations, and that would generally be what I would guide a client to do. But again, we’re not there to say you should or shouldn’t pay.”
If you must…
Organizations pay a ransom for a multitude of reasons, Caiazzo said.
If a criminal has locked down a system through encryption, an organization can no longer function. The need to access vital data is one of the main motivators for ransom payments. An attacker’s threat to leak sensitive data can also compel a company to play ball.
“With data theft, I cannot prove that the threat actor is going to not continue to leak the data, and so that’s why I tend to not recommend people pay ransoms—if it’s purely just to suppress a data leak, because you simply can’t trust what the threat actor is telling you in those moments,” Caiazzo said.
There are a number of circumstances in which it makes sense to pay a ransom, said Mike Puglia, GM of cybersecurity labs at Kaseya. The potential danger from exfiltrated or encrypted data may override the risk and precedent-setting potential of the financial hit. Specifically, Puglia said, institutions like energy infrastructure and healthcare providers are at a disadvantage here.
“It is disgusting that hospitals and places like that, where they have a high degree of payouts, that they go after them, but there is no coming back from that if people are injured or dead” as a result of locked-down data, Puglia said.
But if you can…
Paying or not paying is a “personal thing,” Alex Rose, the global head of government partnerships and the counter threat unit team at Sophos, told IT Brew.
“From a research perspective, and from people who don’t want these crimes to continue, we know that paying them helps them continue the work,” Rose said. “That’s why they’re in the business of what they’re in, they want to make money. Some people would say [it] incentivizes them to continue their work and so on.”
But Rose acknowledged that paying the ransom is cheaper for the organization than ceasing operations, and could allow them to remain in business. Whether or not a company offers critical services could also impact the decision to pay.
Some organizations have a “flat-out ‘no’ policy,” Rose added, where they will never pay the ransom.
“We’ve seen organizations where they’ve successfully handled the exposure side of this and the brand and the reputation from it, and they came out really [strong] in their reasoning for why they wouldn’t pay it,” Rose said. “But you don’t know. I think you’re also dealing with that…uncertainty, so I definitely feel for people in the seats to make those decisions.”
TL;DR
It’s hard to hand over a significant amount of cash in exchange for one’s own data. But when organizations need to return to normal operations, experts say doing so might be a necessary evil.
How to communicate during a ransomware attack
Who should be the first to know? Experts have some mixed opinions.
Your organization’s been hit by a ransomware attack—who do you call first?
It can be difficult to know who to contact when your organization’s data is held for ransom, to the point where even experts disagree. Should the stakeholders know first? What about law enforcement, or threat-response professionals?
Do you have cyber insurance?
A victim’s first call or email depends on whether or not they have cybersecurity insurance, according to Paul Caiazzo, Quorum Cyber’s chief threat officer. If they do, calling a broker is the first step.
Mike Hamilton, former field CISO for cybersecurity solution provider Lumifi and current chief technology officer for PISCES International, previously told IT Brew that organizations should immediately call their cyber insurance provider, as the latter typically has a response team on contract to deploy.
As part of its strategy, insurance companies will typically make a decision on whether or not to pay the ransom to the threat actors. The ultimate goal is to get the organization out of the ransom situation as soon as possible, Hamilton said.
Law enforcement must be notified at some point about the crime. If an organization uses a cybersecurity firm that deals with ransomware or other threats, Caiazzo said, that firm will take on the task of reaching out to the police.
Talking to the enemy
In ransomware situations, Caiazzo said victims should not be required to negotiate with cybercriminals, even if they’re presented with the opportunity to converse via a link.
“By going to the threat actor’s page, they’re going to be able to learn some things about you, and there’s a potential for additional risk to come to you as a result of that,” Caiazzo said. “If you say the wrong thing in those negotiations, you can really just derail the entire thing very quickly, you’ve got to be delicate with it.”
He said that the threat actor will most likely apply pressure on the victim. Threat responders are trained to help counter that pressure.
Once attackers reach out, organizational heads with the necessary authority to negotiate should do so—but only after communicating with your legal department and cyber insurance provider. Incident response can take many forms, including using third-party companies to conduct negotiations.
Mike Puglia, GM of cybersecurity labs at Kaseya, told IT Brew that outside help can do a lot to project confidence and help to manage the complexity of the cyberattack.
“It is worth bringing them on and into your incident response, because that’s what they do all day—they know the different groups,” Puglia said. “They have a history of how to do it, and what to handle.”
Telling tales
When should a company tell stakeholders and the public about an attack? Should it be as soon as your organization detects an anomaly? Rishika Desai, a threat researcher and technical writer for BforeAI, believes so.
“There can be different phases to that. For example, in some companies, what I have seen is they set up a dedicated page and they give their timely updates,” Desai said. “You can give [stakeholders] timely updates as and when it’s necessary. At least it gives a confidence to the stakeholder that there is some momentum going on in mitigating the damage that has been caused.”
Alex Rose, the global head of government partnerships and the counter threat unit team at Sophos, disagreed (kinda) and told IT Brew that communicating with those outside of the organization depends on the company.
For example, a healthcare provider may communicate differently than a legal office when experiencing a ransomware attack. Additionally, publicly traded companies or organizations that operate certain utilities may have legal obligations for public communication.
“You’re really thinking through, what are your legal obligations, your regulatory obligations, your duty to serve the constituency that you might support,” Rose said. “To be honest, some of those people need to be communicated to before others, because you don’t want to add more chaos to a situation—you don’t want to really freak people out.”
TL;DR
If an organization does have cybersecurity insurance, industry leaders believe that the first call during a ransomware attack should be to the cyber broker. Experts agree that organizations should communicate to whomever will help them during a ransomware attack, such as their cybersecurity vendor, as well as those with a vested interest in resolving a ransomware crisis, including the corporate IT team.
How to start talks with a ransomware group
GuidePoint Security’s Mark Lance talks life in the cybercriminal group chat.
First impressions are important, even when you’re confronting a cybercriminal.
Mark Lance, a ransomware negotiator and VP of digital forensics and incident response (DFIR) and threat intelligence at GuidePoint Security since 2022, often has to initiate interactions with his clients’ cyberattackers, using chat functionality on a ransomware as a service platform or a dark-web site.
And these days, there are way more groups to track, each with their own track record of encrypting, decrypting, deleting, or posting sensitive information online. In Q2 of last year, Lance told IT Brew that he and his team were tracking 45 threat groups; today the number has grown to 71. Lance said he takes the groups’ histories and backgrounds into account during the negotiation process.
“You have to look at these groups and what their primary motivation is,” he told us.
Lance spoke with us about how the conversation begins with today’s (many) adversaries.
These responses have been edited for length and clarity.
What is your first message, and what’s important to establish in it?
It really is dependent upon the intent of what a client is trying to get out of the negotiations. They might believe they have a drastic need to potentially consider making a ransom payment. Other times, it’s about just delaying the process and figuring out what ransomware amounts are. Generally our first message, in most circumstances, is going to be more acknowledgement that we know that they’ve impacted us, and we’re opening up the channels for communication. It’s like, ‘Hey, we received your note. Can you tell us more about what we have going on in the environment?”
What are you trying to discover in these early interactions with the adversary?
Typically, we can ask them, “Hey, you’re asking for X amount. Why do you believe that [data] is of value to us?” And [maybe] they’ll provide a file tree and that file tree can help determine, “OK, well, here’s what information they might have.” A lot of times if encryption is involved, you might not have access to those servers…Once they got in, what did they touch? What did they steal? A lot of times those breadcrumbs aren’t there, but by having them provide us a file tree, that’s something we can then turn over to the forensics workstream and say, “Hey, where were these files located? On which systems?”
How long do these interactions usually last?
It generally happens over the span of days to weeks. It’s not generally in a matter of hours. These kinds of communications occur over an extended period. Again, it’s the level of urgency; how frequently we’re responding is contingent on what we’re trying to get out of the negotiation itself.
And what is being negotiated exactly here?
One of the things that we need to determine is what are the terms of the negotiation: Are we trying to get access to decryptors? Are we trying to ensure that the information won’t be published to their dark-web site? Are they going to give us the method of ingress and how they actually got into the environment?...We try to get agreement with the cybercriminals: “Hey, if we make a payment, here’s what we expect.” We expect access to decryptors, or we expect that this information won’t be published, and we want indications that it’s been deleted. Realistically, can you expect them to fully delete it and not retain that information? No, these are still cybercriminals…Of course, the ransom payment itself is negotiable as well.
Would you say it’s best for organizations to pay or not pay?
We are complete advocates for not making a payment if it’s unnecessary. It is our responsibility as consultants to educate clients on what will potentially occur or what can potentially transpire and the associated risks of paying or not making a payment. But ultimately, it is up to the client…We are not in a position where we think anybody should be funding cybercriminals or these types of organizations if they don’t have to.

Developer tips: How to keep malicious packages out of your codebase
Advice from two software pros includes ignoring scripts…and looking at mirrors.
Open-source components can streamline software building, making them a developer’s best friend—or worst enemy, if a supply-chain attacker decides to poison a package.
Software supply-chain management company Sonatype identified 394,877 new open-source malware packages in Q4 2025, representing a whopping “476% increase compared to the previous three quarters combined.” (The company said the increase was due largely to a self-replicating malware campaign.)
This attack often begins with a threat actor compromising a developer’s account, then publishing a malicious package to a trusted repository. Other developers pull from that source to create their own apps and services, spreading the malware.
Oh, great. More Dune
The latest attack—a “mini Shai-Hulud” (named after a cinematic sandworm)—compromised legitimate software packages and installed malicious credential-stealing updates that spread along connected dependencies.
As of May 19, a single stolen token with publish rights led to compromises across 633 malicious package versions in the npm software-registry ecosystem, according to research from application security platform Endor Labs.
And to make the attack even tougher to detect: The token-taking malware uses valid provenance markers.
We spoke with software pros about how to defend against malicious packages, even when they appear to be trusted.
Ignorance is bliss
Enable the “ignore-scripts” flag where possible, according to Peyton Kennedy, senior security researcher at Endor Labs. (Kennedy wrote a post of mitigation tips in that May post, including rotating credentials on npm publish tokens and cloud-platform account keys.) “When you enable the ‘ignore-scripts,’ these pre- and post- execute steps, where a lot of these credential harvesters hide, don’t end up executing,” Kennedy said.
Use lockfiles
A lockfile is a compiled, approved dependency list. Without one, a fresh install may pull the new version of a piece of software automatically—a process that attackers are taking advantage of, according to Kennedy.
“Attackers are exploiting that desire of wanting to be on the latest version of the software, whether that be for functionality or just maintenance…they’re exploiting that need for speed that developers have within their deployment cycle,” Kennedy said. (App security platform Semgrep recently shared a summary of lockfiles and the languages that support them.)
Watch for install-time anomalies
Is something that usually takes five seconds to install suddenly taking 15 minutes? That kind of behavior likely warrants investigation, Kennedy warned.
Use your mirrors. Provide a local copy—a mirror—of your codebase, that only gets updated after a “cooldown” period of a few days following a new version, according to Guillaume Valadon, staff cybersecurity researcher at secrets-protection company GitGuardian.
IT pros can use open-source tools or enterprise-artifact repositories to create a mirror—a server that sits between developers and, say, a public npm registry. The internal proxy caches the package and applies a company’s policies before serving it, Valadon wrote in a follow-up email to IT Brew, “Two policies do the real work: a 24- to 72-hour cooldown on new versions, so most malicious releases get yanked before a developer sees them, and an allowlist, so new dependencies need one-time approval before anyone can pull them.”
Today’s CISOs are figuring out how to address the growing problem.
“We’ve seen a lot of attacks with malicious npm packages, and it’s something that is hard to balance,” Sandra McLeod, CISO at Zoom, told us in May. “You want to enable your developers to be able to move quickly, to innovate and to have quick development cycles in terms of testing and trialing, but at the same time, you need to know that there’s real diligence being put into: What software are they working with? Are we ensuring that that software is coming from approved sources?”
Asking around: When does ransomware threat intelligence become noise?
Pros share how to rescue yourself from drowning in alerts.
Like your dad’s travel itinerary, threat intel has a lot of extra detail that you probably don’t need. Even ransomware defenders have their own version of TMI.
During a recent IT Brew event, “Trend Watch: The Latest in Ransomware and What That Means for IT Teams,” an attendee asked Grant Smith, president of Phantom Security Group: “At what point does threat intelligence become noise? We’re drowning in alerts, and I’m not sure our team knows what to escalate anymore.”
Smith advised companies to learn about the groups targeting companies in their sector, research their tactics, and then ensure defenses cover the areas those groups are targeting.
“You really have to filter out the information based on the market segment that you’re in,” he told the attendees.
After the event, we posed the same question to other security pros, who shared how to turn down the noise and make the most of all that data.
The responses below were from separate interviews and have been edited for length and clarity.
There’s lots of info
Nick Hyatt, principal threat intelligence analyst at cybersecurity consultancy GuidePoint Security: What a lot of organizations will do is they will buy a threat intelligence feed—something to help, maybe, enrich their SOC [security operations center] alerts, and then they’ll have that data coming in and they won’t know what to do with it.
Nick Biasini, head of outreach at threat-intel research org Cisco Talos: When you’re talking about threat intelligence, historically, it would be a feed of IOCs [indicators of compromise]. Now a lot of it is based on curated reports. So, there’s a lot of private reporting that you’re potentially reading.
Do an asset inventory
Hyatt: Understanding the asset inventory in an environment can actually help filter out a lot of the alerts and a lot of the noise that comes in. Because if you don’t run VMware in your environment, and there’s a new VMware exploit out there: Do you need to worry about it? You should acknowledge it, but it’s not something that you need to have an alert on.
If there’s a new Node.js vulnerability out, but none of your developers use Node.js then, yeah, it’s good to be aware of that, and maybe you need to do some supply-chain analysis to see, do any of our vendors use Node.js? Does any of our tooling have that built in? But if you don’t specifically develop with this specific language or have this specific technology, you can acknowledge the alert and then just disregard it because it doesn’t actually apply to you.
Figure out your likely adversaries
Biasini: If you’re a toy manufacturer somewhere in the middle of America, you’re probably not super concerned about what the latest and greatest state-sponsored groups are doing in espionage attacks. But a lot of your threat intelligence could very well be focused on that exact thing.
Hyatt: If you are a law firm, well, what threat actors are attacking law firms? If you’re just a very small, local shop that has a web presence? Are you really concerned about North Korean threat actors? Maybe not. But are you concerned about ransomware? Absolutely. Same thing for healthcare. And so understanding what the potential is for being attacked is a key part of actually making that data work for you.
Biasini: [Referring to the toy manufacturer example] If you’re interested in ransomware, what ransomware groups, like Qilin and some others, have gone specifically after manufacturing? Those are the groups that I would focus on first. Build as much tooling as you can around what’s known about them. What are their TTPs [tactics, techniques, and procedures]? What tooling do they use? How do they get into environments? And then start focusing your threat intelligence around curating and building those defenses.
Prioritize
Hyatt: You can add prioritization to alerts…And so if you say, well, these five technologies are our key technologies that we use, anything that comes across the wire that has [those five technologies] in there, we need to take a deeper look.
Leeann Nicolo, director of Coalition Incident Response for cyber insurance provider Coalition: I think threat intel becomes noise when it’s not tied to your attack surface and financial risk. So, I think providing a list of indicators of compromises is way less valuable than telling somebody your firewall is unpatched, it’s internet facing, policyholders like you are four times more likely to be hit with ransomware that could cost you $1.5 million—giving that data to put the stress on what is happening, why it impacts you, and what you need to do, rather than, “Here’s a list of indicators of compromise,” because they’re never-ending.
Update 04/27/2026: Leeann Nicolo’s title has been changed.
Cybersecurity professionals say high-profile incidents boost execs’ credibility
“Businesses are really cognizant of how much impact an incident can have, and therefore want trusted leaders that have experience in incident management and dealing with such things,” ISC2 CISO Jon France says.
For cybersecurity professionals, nothing builds character like a high-stakes security incident.
Cybersecurity pros are increasingly putting their trust in leaders with security mishaps under their belts. According to a May ISC2 research report, 76% of cybersecurity professionals either somewhat or strongly agree that a leader’s credibility increases when they have previously been through a “real, high-profile security incident.” The findings are based on an April survey that queried close to 800 cybersecurity professionals.
It’s a new dawn. It’s a new day. The recent research hints at a drift away from the stigma surrounding cybersecurity leaders whose organizations are successfully hit by cyberattacks. Just a year ago, a Sophos report found that 25% of leadership teams were replaced following ransomware attacks. IT Brew has reported on some of the challenges security leaders face following a cyber-calamity.
“Businesses are really cognizant of how much impact an incident can have, and therefore want trusted leaders that have experience in incident management and dealing with such things,” ISC2 CISO Jon France told IT Brew in an interview.
Trust and believe
Cybersecurity pros shared other traits that help create trust in their leaders: 95% of surveyed professionals ranked cybersecurity leaders’ ability to communicate risk to senior leadership as very important for fostering trust and confidence.
“Being able to translate technical impact into risk impact into business language is the translation you need to have as a cyber leader because that’s the language of business,” France said.
Another 91% pointed to leaders with a long-term cybersecurity vision as very important for building trust, while 88% named the ability to effectively work with boards to secure budgets.
Trust exercise!
A little over one-fifth (21%) of respondents said they had little to no confidence in their current cybersecurity leadership team. Kayne McGladrey, a senior IEEE member, told IT Brew one-on-one conversations can help cyber leaders get a pulse check for how staffers are feeling about them.
“I believe in 360 reviews. I’m not [just] reviewing them, they’re reviewing me at the same time, so that I can be a better manager or leader for them,” McGladrey said. “ I think that that ability to be introspective and to take feedback when you give feedback is really necessary to build and maintain trust.”
For leaders who want to foster trust and confidence with staff, McGladrey said transparency is key: “That’s absolutely necessary to build trust with your staff.”
How much control does an IT pro really have when a third-party platform gets hit?
We spoke with pros who advised on early preparations.
The school day was “a bit of a logistical nightmare” on May 8, according to Nikita Borisov, a professor of electrical and computer engineering at the University of Illinois Urbana-Champaign’s Grainger College of Engineering.
But it wasn’t your typical chaos: A cyberattack against widely used edtech platform Canvas locked college professors, high school teachers, and students out of assignments, messaging, video content, grades, and other classroom materials.
While the global downtime caused minimal disruption for Borisov (whose final presentations for students did not explicitly rely on Canvas, he said), some teachers had to figure out a plan when campus canceled exams on May 9.
Threat actors exploited a vulnerability related to the company’s “Free for Teacher” environment, according to a statement from Steve Daly, Canvas parent company Instructure’s CEO. The chief exec said the incident involved unauthorized access to information like usernames, email addresses, course names, enrollment information, and messages.
The hacking group ShinyHunters posted on their own site that they had stolen terabytes of data from Canvas linked to nearly 9,000 schools worldwide.
When platforms go down, either by misconfiguration or miscreant, can an IT pro actually soften the impact? We spoke with two security pros about important preparations.
Map your dependencies
According to Brandon Blankenship, CISO at cybersecurity company ProCircular, a team involving IT, legal, operations, and main players (say, professors) need to do an internal audit ahead of any compromise to define:
- Critical business processes (teaching and grading, for example)
- The core systems supporting those business processes (say, Canvas)
- The under-the-hood systems (dependencies) that the core systems need (like databases or identity management)
Next, Blankenship recommends that leaders discuss reasonable expectations for recovery time and how much downtime an organization can tolerate.
“Senior leadership has to understand this too-big-to-fail company can and probably will fail for 48 hours, or 24 to 72 hours, and if that happens, either we tell people, ‘Go home and we’ll do tests three days later,’ or we try to have a completely redundant system, which is almost always too expensive at that scale,” Blankenship said.
Etay Maor, VP of intelligence at network security platform Cato Networks and an adjunct professor at Boston College (who thankfully got his grades in before the incident), said school leaders need to identify high-risk assets, and strategize redundancies where necessary. Maybe grades and lecture videos are considered critical and must therefore be backed up on an external system; maybe messaging is less important and schools can resort to usual email.
“You need to [know]: What happens if Canvas goes dark on me?” Maor said.
A business continuity assessment “should absolutely be done beforehand with the systems that matter the most, and I would usually recommend, the fewer the better,” Blankenship said, adding there’s no need to build up in-depth plans for a dozen systems. Pick the “absolutely most critical” ones and run through what needs to happen when those go down.
Make outages part of your disaster recovery plan, Blankenship and Maor advised.
Be ready to answer the ransom question
Instructure “reached an agreement” with the threat actors, according to the CEO’s statement. Orgs should also prepare to answer ransom-related questions and work with insurance companies (in advance!) to determine set points for payment, Blankenship advised.
“Thinking about paying or not paying is such an emotionally charged conversation that should be guided by people who have been through incidents before,” Blankenship said.
According to calculations from pro-consumer site Comparitech, ransomware actors took credit for 251 attacks in 2025—a steady number compared to 2024’s 247 incidents. However, 2025 saw a jump in compromised records: 3.96 million compared to 3.11 million in 2024.
Wait, wait, backup
Both organizations and individuals need to prepare for an outage. Borisov luckily didn’t rely too heavily on the Campus platform.
“Having copies of your grades, having copies of your course materials in multiple places might make sense to be more agile in responding to these things,” he said.
Blankenship wants to see more backup and planning instead of a blame game.
“The control we put in place is: stop blaming IT, and stop blaming Canvas and having professors and TAs, whoever’s in operations, have a viable workaround if that system is unavailable for 48 hours,” he said. “That’s the real answer, and that’s a conversation that not many people want to have.”
Block the Breach
A high-stakes interactive game built on real-world reporting from IT Brew.
In many ways, ransomware is the great equalizer, potentially impacting organizations both large and small. If you’re an IT professional tasked with defending their tech stack against these and other attacks, you no doubt have questions about the latest dangers and defensive tactics. Fortunately, IT Brew’s comprehensive stories on cybersecurity can offer key insights into key ways to protect your team and organization.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.