Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
If you are after the definition, it is in the ransomware glossary entry and takes a minute to read. This page is the other thing: how it actually gets into a company, who is on the other side, what decides the amount you are asked for, and which controls break the chain before it reaches the end. No storytelling, and nobody else’s numbers.
Everyone’s mental image of ransomware is the screen with the ransom note. That screen is the end. By the time it appears, the attack has been inside for days or weeks and has already done what really matters.
The usual sequence is this: they get in, they look around, they obtain high privileges, they find where the backups are and disable them, they take the data out, and only then do they encrypt. The order is not accidental: encrypting earlier would raise the alarm and stop them doing everything above.
From that comes the consequence that is hardest to accept: a perfect backup no longer solves the problem. It gives you your operations back, not your confidentiality. The negotiation stops being about recovering the files and becomes about not publishing them, and for that a backup is no use at all.
That is why the leak site exists: a website where the victims who do not pay get published. It does two jobs at once, punishing whoever does not pay and acting as a shop window to convince the next one.
And it is worth knowing that the worst case exists: sometimes there is no key. A wiper destroys and disguises itself as ransomware to buy time and confuse the response. Paying there gives nothing back, because there is nothing to give back.
Thinking about ransomware as one particular gang leads to the wrong conclusions, above all to the idea that if that gang is dismantled the problem goes down.
The work is split up:
That is why this page does not publish a list of families with dates. It would be a list of other people’s names that expires within months and that would force us to assert dates we cannot check. What does not expire is the structure: as long as selling access and renting encryptors is profitable, the name of the group is the least of it.
Almost always through one of these four, and none of them is sophisticated:
What almost never happens is what people imagine: a targeted, original attack against your company in particular. The normal thing is that you fit into a sweep.
This page used to carry two contradictory amounts: one of a few hundred and one of millions. Both have been withdrawn, and not out of caution, but because the question "how much does a ransom cost" has no answer that is any use. The amount is not a price list, it is an estimate they make about you.
What moves it:
Any average figure you read out there describes other companies, not yours. If you need a number for a board, the one that works is a different one and it is yours: what a day of downtime costs your company. That one can be calculated, and it is the one that decides how much it is worth investing in not getting there.
The decision is not a technical one and it is not made by whoever runs the systems. What is technical is knowing what you are buying and what you are not.
What has to be decided beforehand, not during: who is in charge in a crisis, who talks to the regulator and to customers, and on what basis the call gets made. That is incident response, and the part about preserving the evidence without destroying it is digital forensics. Improvising those three decisions at three in the morning is how the worst ones get made.
In order of effect, not of price:
All of the above can be bought, switched on and documented, and still not work. The only way to know is for somebody to try.
The general order of priorities, if this is the first thing you are looking at, is in the guide to cybersecurity for companies, and the picture of what is actually getting in is in cyber threats facing companies in Spain. For a specific case, get in touch.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.