Spotlight: When Ransomware Comes Calling
ID: a035f056-9e6c-52f4-b4a8-a938f38e3ad9
STIX ID: report--a035f056-9e6c-52f4-b4a8-a938f38e3ad9
Feed Name: Security Ledger
This podcast transcript features an incident response manager discussing the evolving ransomware landscape: increasing use of double/triple extortion, living-off-the-land techniques that evade EDR, supply-chain risks (e.g., SolarWinds/Kaseya), and the operational gaps—lack of talent, monitoring, logging, and retention—that let attacks escalate. Practical advice includes isolating affected systems rather than restoring/wiping them, retaining forensic data and logs, preparing playbooks and external IR support in advance, and ensuring 24/7 visibility to detect and contain actors before encryption or data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
