Skip to content
Security & Trust

Ransomware first days fail on decisions, not tools, responder says

A field guide on Huntress's blog says the first 24 hours test who has authority to act, not how fast engineers type.

W
WebPulse Newsroom
AI-assisted · 5 min read
Share on X LinkedIn
Ransomware first days fail on decisions, not tools, responder says

AI-generated image for WebPulse. About our images

In brief
  • A Huntress-published guide by UnderDefense's CEO argues ransomware first days fail mainly on decisions no one was authorised to make, not on missing technical steps.
  • Mandiant reports a 14-day median dwell time, and CISA records Akira data theft in just over two hours, so the attack predates the ransom note.
  • Test a real restore, name decision-makers and deputies in writing, and confirm multi-factor authentication on every remote access path.

By the time a ransom note appears, the attack is usually old. The first day of response is less a race than an audit. It shows which decisions your organisation settled before it needed them.

That is the argument in a field guide published on Huntress's blog on October 2. Its author, Nazar Tymoshyk, is CEO of UnderDefense. He writes from ransomware engagements in food production, business services and retail. Several of his examples are UnderDefense's own cases. He says the hour markers are approximate and the order is not.

The attack began long before the note

Mandiant's M-Trends 2026, published in March 2026, measured how long intruders stay hidden. The global median is now 14 days, up from 11. This is called dwell time. Encryption comes at the end of that stay.

14 days
Global median dwell time
Source: Mandiant M-Trends 2026, as cited by Huntress (March 2026)

Mandiant also tracked how quickly one criminal group passes its access to another. In 2022 that took a median of more than eight hours. In 2025 it took 22 seconds.

22 seconds
Median hand-off to a second threat group, 2025
Source: Mandiant M-Trends 2026, as cited by Huntress (March 2026)

So the people who lock your files may be strangers to the people who got in first. Investigators face two intrusions with different tools and goals. The earlier one was the quieter.

Hour one: every containment step has a price

Tymoshyk pairs each action with what it buys and what it destroys. Isolating a host from the EDR console stops spread and keeps memory. EDR is the security agent installed on each machine. Memory often holds the injected process and the operator's tooling. Powering the host off loses all of that, so he advises it only when nothing else stops the encryption.

Isolation has its own cost. Cutting a host off can also sever your staff's own way in, unless an allowlist keeps that path open. Disabling compromised accounts and resetting the domain's ticket-signing account, krbtgt, twice triggers a wave of authentication failures. In his view, few companies write these trade-offs where a night-shift engineer can find them at 03:00.

One row he would act on first is the VPN. CISA's Akira advisory lists VPN services without multi-factor authentication among the main ways in. The advisory was refreshed in November 2025 with the FBI, Europol's EC3 and agencies from France, Germany and the Netherlands. A VPN lacking that second check is the quickest thing to shut. It is also a cause to remove.

Data leaves with ordinary software

Tymoshyk says to assume data was stolen until you can show otherwise. CISA's advisory describes Akira cases where the data was gone a little over two hours after entry.

Just over 2 hours
Fastest exfiltration recorded in some Akira incidents
Source: CISA Akira advisory, as cited by Huntress (updated November 2025)

The tools look like an IT department's toolbox. The advisory lists FileZilla and WinRAR to gather files, WinSCP and RClone to move them, Mega as storage and Ngrok to tunnel out. Your administrators may have good reasons to run all of them. That is why a malware signature will not catch it.

The advice is to hunt on volume and destination. Look for a single machine sending tens of gigabytes to a consumer cloud service across a weekend. Legal counsel should join at this point, because what left the building decides who must be told and by when.

A backup is a claim until someone restores it

Mandiant's authors say attackers deliberately went after backups, identity systems and the software that manages virtual machines. CISA describes a cruder method too. Operators delete volume shadow copies, snapshots kept on the machine itself, with a short PowerShell command.

Tymoshyk's checks are blunt. Restore one real file and open it. Find out whether the backup server logs in through the domain you are about to rebuild. Confirm that immutability is switched on today. Find the date of the last full restore test. Know who holds backup credentials that are not domain accounts. His warning to executives is that an untested backup claim does the most damage on day one.

The runbook names no one

After the technical picture settles, the decisions left are ones no engineer can make. Someone must approve taking a production line offline. Your insurer, your regulator and your largest customer each have a notification clock. They start on different events and none pauses during an investigation.

The ransom question is really three questions: whether to engage at all, who may communicate, and who signs off. Tymoshyk says most first days go wrong here. The runbook describes isolation in detail and names nobody. His fix is to put names in the plan, with a deputy for each, because the person listed will eventually be on a plane.

This is the lesson for the people who fund security. Tools can be bought. Authority has to be granted, in writing, by someone senior enough to grant it.

Questions to put to your team

Ask for a timed restore of a file from the newest backup, so your recovery estimate becomes a measurement. Ask to see three named decision-makers and three deputies in the incident plan. Ask whether every remote access path enforces multi-factor authentication today. Ask whether domain controller logs still cover the 30 days before an event.

Then rehearse with the people who would really be on the call. Tymoshyk says responders' calls land on Friday evenings and holiday mornings, so test those hours.

One case shows the payoff. According to UnderDefense's write-up, a poultry producer paid no ransom and then replaced more than 900 noisy detection rules with over 100 written for its own environment. That is one engagement, not a trend. It does show where the effort went afterwards.

Encryption is the last step of the attack, yet it is usually the first moment anyone learns it began. What you settled before that moment decides the rest.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Huntress.

Share this insight