A useful ransomware example describes the full path: initial access, privilege, propagation, exfiltration and impact. That view shows exactly where defenders can detect or interrupt the operation.
of breaches involved ransomware
Verizon’s 2026 DBIR found ransomware in 48% of breaches in its dataset. The benchmark supports prioritizing backups, identity, segmentation and response readiness.
Verizon — 2026 Data Breach Investigations ReportScenarios 1 and 2: remote identity and email
A reused VPN password opens the network where MFA is absent. Breakpoints include phishing-resistant MFA, access policy and new-session detection.
In the second path, an attachment launches a loader followed by legitimate administration tools. Attachment controls, endpoint telemetry and least privilege expose the sequence.
Scenarios 3 and 4: vulnerability and administration
An unpatched edge device becomes the entry point. Continuous inventory, exposure-based patching and device telemetry reduce the window.
A domain administrator is then used from a normal workstation. Dedicated admin stations, PAM and tier separation limit the stolen identity.

Scenarios 5 and 6: cloud and suppliers
A malicious OAuth app reads mail and files without stealing a password. Restricting consent and monitoring grants breaks the path.
A compromised supplier uses legitimate maintenance access. Time-bound access, segmentation and session recording reduce implicit trust.
Build an exercise from one path
Choose the most plausible scenario for a critical service, list the expected telemetry and insert three decisions: contain an identity, isolate a segment and stop a service. Add ambiguity to test judgment.
The outcome is an owned gap list with dates and closure tests, not a theatrical scenario.
Operational decision matrix
| Stage | Question to resolve | Expected outcome |
|---|---|---|
| Entry | Identify the verified initial vector. | Fix the exposure |
| Expansion | Reconstruct privileges and movement. | Find interruption points |
| Impact | Separate theft, disruption and encryption. | Prioritize critical operations |
Using examples well
A historical case is useful when it exposes defensive invariants, not when it freezes a checklist around an old brand.
The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.
Frequently asked questions
Which ransomware path is most common?
It varies by exposure. Compromised identity, edge vulnerabilities and suppliers all require modeling.
Why do attackers use legitimate tools?
Approved tools blend into operations, making context and sequence critical to detection.
How should we choose the first exercise?
Start from a critical business asset and map the most plausible access path through controls actually deployed.
Official sources
Achraf Hachimi
CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.
