Intelligent CISO Issue 101 | Page 37

f

e

a

t

u

r

e

Factor one: Ransomware is now a business risk, not just an IT issue
Ransomware no longer affects only IT systems. Successful attacks can halt operations, disrupt customer services, impact supply chains and damage an organisation’ s reputation. In sectors such as healthcare, education and local government, outages can have significant consequences for the people who rely on those services.
Technology leaders should ensure ransomware preparedness is discussed at board level, with clear ownership across IT, security, operations and executive leadership.
EXPERT REACTION
Frank Vukovits, Chief Security Scientist at Delinea, says:“ Visibility starts with knowing what you actually have. Most organisations struggle to produce an accurate inventory of the business applications running across the enterprise, yet without that view it’ s impossible to assess where ransomware risk truly sits.
“ That inventory has to extend beyond applications to the identities that access them – and today that means human users, service accounts and, increasingly, AI agents acting on employees’ behalf. Each of those is a potential entry point.
“ Alongside knowing your applications and identities, employee education is a factor leaders consistently underestimate. Ask yourself how often your people are actually trained to recognise the early signs of an attack. As threat actors use AI to make their ransomware campaigns more convincing and harder to spot, infrequent, tick-box training no longer cuts it. Frequent, practical education remains one of the most costeffective ways to shrink your attack surface.”
Factor two: Identity has become the preferred route for attackers
Attackers are increasingly gaining access using legitimate credentials rather than exploiting software vulnerabilities. Stolen passwords, compromised privileged accounts and phishing attacks often provide an easier route into an organisation than breaking through technical defences.
Strengthening identity security through Multi-Factor Authentication, privileged access controls and continuous monitoring is now a critical component of ransomware defence.
EXPERT REACTION
Frank Vukovits, Chief Security Scientist at Delinea, says:“ The most important question a leader can ask is whether least privilege is genuinely enforced across every identity – human, machine and AI agent – for the access they hold to applications and infrastructure.
“ Attackers rarely need to break down the door when they can walk in with valid credentials. When they do, the amount of damage they can cause depends entirely on how much access that compromised identity carried. Limiting access to only what’ s needed for the task at hand contains the blast radius when, not if, an identity is compromised.
“ Just-in-time access with runtime authorisation is central to this, ensuring high-value accounts are tightly controlled, monitored and time-limited rather than standing open. Zero Trust extends the principle further: access should be continually challenged and verified rather than granted once and left static. Layered controls that repeatedly test whether an identity should still have access are what stop an intruder from moving laterally undetected.”
WWW. INTELLIGENTCISO. COM 37