Most businesses picture ransomware as a sudden event. Systems go dark, a ransom note appears, everything stops. That picture is incomplete — and the gap between what people think happens and what actually happens is exactly where attackers thrive.

Modern ransomware operations are not opportunistic viruses. They are deliberate campaigns, run by organised groups, that typically spend weeks inside an environment before any encryption takes place. The encryption itself is the final move — a loud, irreversible action designed to maximise pressure. Everything before it is quiet. Understanding what that looks like is the starting point for doing something about it.

How they get in

Initial access rarely looks dramatic from the outside. Attackers most commonly enter through an internet-facing service with a known vulnerability that has not been patched, a phishing email that captures credentials, or credentials purchased from an initial access broker — a criminal market where compromised access to specific organisations is bought and sold. In the last case, someone else has already done the intrusion work, and the ransomware group is simply buying the foothold.

What happens next is not encryption. The goal at this point is to survive long enough to be useful.

The dwell period: what attackers actually do

Once inside, a ransomware affiliate typically works through a predictable sequence. The specifics vary by group and target, but the pattern is consistent across most documented incidents.

Stage What the attacker does Where defenders can act
Persistence Plants backdoors, adds scheduled tasks, creates new admin accounts EDR alerts, privileged account monitoring
Discovery Maps Active Directory, locates backups, identifies domain controllers and file servers SIEM anomaly detection, identity monitoring
Lateral movement Moves between systems using harvested credentials Network segmentation, credential hygiene
Privilege escalation Escalates from user access to domain administrator Tiered administration model, privileged access controls
Exfiltration Copies sensitive data to attacker-controlled infrastructure Outbound traffic monitoring, data loss prevention
Encryption Deploys ransomware across all accessible systems simultaneously

The discovery phase is worth dwelling on. Attackers spend meaningful time identifying where the backups are. They look for whether backups are accessible from the domain they now control. If they are, they destroy them before encrypting anything. This is deliberate — it removes your most obvious recovery path before you know you need it.

Why encryption comes last

Encryption is deliberately the final step. Once ransomware deploys across your systems, your security team knows you have been attacked, law enforcement may be involved, and the clock starts. Attackers want everything in place before that happens.

The exfiltration stage explains the "double extortion" model that most ransomware groups now use. Even if you restore your systems from clean backups, they threaten to publish what they copied — customer data, financial records, contracts, employee information. This creates leverage regardless of whether you can recover operationally.

Where the attack can actually be stopped

The encryption event is not where the attack can be disrupted. By the time files are being encrypted, the attacker already has domain administrator access and has spent days or weeks moving through your environment. Stopping it at that point is not realistic.

The dwell period is where the attack can be caught. Persistence mechanisms, lateral movement, credential harvesting, unusual Active Directory queries, large outbound data transfers — every stage produces signals that detection tooling can identify, if it exists and someone is reviewing it.

This is why organisations with active security monitoring — a SOC, an MDR provider, a SIEM with genuine coverage across endpoints and identity — have materially better outcomes after a ransomware incident. Not because the attack does not reach them, but because it is identified and contained before the encryption stage.

Reducing the attack surface before they arrive

Ransomware groups are selective about targets. They look for environments with exposed and unpatched remote access services, weak or reused credentials, poor patching discipline, and backup infrastructure that is accessible from the same domain they intend to compromise.

A penetration test identifies these conditions before they are exploited — using the same techniques an attacker would use at the initial access and lateral movement stages. It tells you what an attacker finds when they look at your environment from the outside, and how far they can get once inside.

Managed vulnerability scanning provides continuous visibility into the same attack surface. New exposures — a service that becomes internet-facing, a missed patch, a misconfigured cloud resource — are identified before an attacker finds them first. The dwell period never begins if the initial access route does not exist.

Neither removes risk entirely. But they address the conditions that ransomware groups actively screen for, and close the gaps most commonly exploited at the entry points of documented incidents. For more on how the decision between testing approaches works in practice, see Do I Need A Red Team?

Understanding what your environment looks like from the outside — and what an attacker can do with an initial foothold — is what a penetration test is designed to answer.

Penetration Testing