One in twenty organisations we onboard is already breached when we arrive. This is what our team finds when we deploy MDR across a new customer environment for the first time.
The findings in this article come from Eye Security's own incident response casework across European mid-market organisations, covering more than 630 incidents over the past three years and 120 so far in 2026. Ransomware accounts for a share of this caseload. But ransomware usually starts with something ordinary, and the road from there to a ransom note is shorter than most organisations expect.
We recently brought two perspectives together to trace this path: our own incident response work, and Nick Bruinsma, Red Team Lead at The S-Unit, who simulates these attacks for a living. His team has a notable record: there has not yet been a client environment they could not get into.
Both views answer different questions. Incident response tells you what happens when the attack succeeds. Red teaming tells you whether it would succeed in your environment, before anyone has to find out the hard way.
Key takeaways
- Ransomware rarely begins with a sophisticated technique. In our incident response casework, it begins with an exposed remote desktop service, a supplier misconfiguration, or a legitimate remote access tool.
- Network access is bought and sold as a product. Initial access brokers sell entry for a few thousand euros.
- The gap between having a defence and knowing it works is where organisations lose. Red teaming closes this gap by walking the same road under controlled conditions.
Video 1. A company got fully ransomwared from just one phone call
What is an initial access broker, and why does access to your network cost so little?
An initial access broker is a criminal who specialises in breaking into organisations and then selling that access to other criminals.
Most organisations still picture a single threat actor who finds a way in and then encrypts everything. This model is out of date. There is a functioning market between these two steps. Brokers compromise an organisation, package the access, and sell it to whoever wants it.
The listings are specific, including VPN credentials, domain administrator accounts, NTDS files containing every user and password hash in an environment. Sometimes a bundle of all of it, with malware already installed. The victims span insurers, hospitals, energy companies, logistics operators, and organisations of every size.
The prices are the part that should focus attention. Access frequently sells for a few thousand euros. Set that against a ransom demand in the hundreds of thousands, and the economics of the ransomware business become clear. A ransomware operator does not need to be skilled at intrusion, they simply need a budget.
This is also why targeting feels arbitrary. Threat actors are not researching your organisation for weeks and selecting you. They are buying available access in volume and working through it.
How do ransomware threat actors get in?
Video 3. How threat actors gain access now
In the cases we investigate, the most common entry points are exposed remote desktop services, valid credentials obtained from earlier leaks or guessed, and legitimate remote access software installed on the attacker's instruction. Malware plays a shrinking role.
Exposed remote desktop
Exposed remote desktop remains one of the most common. Shodan indexes systems connected to the internet in much the way a search engine indexes pages, and in 2026 it still returns remote desktop services sitting openly available. Someone made a configuration change. A system became reachable. A threat actor guessed a password, or used one from a previous leak, or found a device still running the credentials it shipped with.
Legitimate remote access software
Legitimate remote access software is the second pattern. Tools like TeamViewer and AnyDesk are used daily by IT departments everywhere, which is precisely why they work well for attackers. Your endpoint protection has no reason to flag software you already run.
One case followed this route exactly. A threat actor phoned an employee at an organisation that was not yet our customer, presented themselves as IT support, and explained that an urgent update was needed or the computer would stop working. The employee installed TeamViewer. What followed were not updates. The threat actor moved through the network and ransomwared the organisation, using a phone call and software the business already trusted.
This connects to a broader shift in our incident data. Malware appears in fewer and fewer of the cases we investigate. Threat actors increasingly use valid credentials and legitimate tools, because both are effective and neither triggers the controls built to catch malicious code.
What all of this means is that the defences that matter most are unglamorous. Patch management. Attack surface monitoring. Correct authentication. Knowing what you have connected to the internet. None of it is advanced, and all of it is where these incidents begin.
How fast does a ransomware attacker move once threat actors are inside?
In our current observations and own telemetry, roughly 45 minutes passes between initial access and lateral movement inside a network. That is the window your detection and response has to work with.
The pace has changed. AI is helping attackers find vulnerabilities faster, scan more broadly, and produce credible pretexts at scale. The techniques are not new. The speed and the volume are.
Video 4. Root cause analysis: their backup server was the entry point
What happens in the first hours of a ransomware incident?
The following case shows how the pieces fit together. A financial services organisation, ransom note on their systems, and a call to our incident response team.
Containment
The first hours went to containment. We could not see the environment clearly because most systems were down, and this was not a customer whose infrastructure we already knew. We cut inbound and outbound internet connectivity to limit the attacker's ability to move, then stood up a crisis team with their IT staff, executives and legal function. In parallel we deployed endpoint detection across the estate, which gives visibility even on encrypted machines because ransomware operators generally leave the operating system running. This visibility let us begin root cause analysis and protect systems that were not yet affected.
Scoping
The threat actor was Snatch. Scoping produced the finding that shapes everything afterwards. The backups had been encrypted and deleted, and no additional copies existed. When backups are only deleted, specialist recovery firms can often restore them and negotiation becomes unnecessary. Encrypted and deleted together left no viable recovery path.
Negotiations
The organisation could not operate. Without systems, it would not survive. On that basis, we opened negotiation with the threat actor, with the executive team fully briefed that they were dealing with criminals and that no outcome was guaranteed. A ransom in the high six figures was paid. A decryption key was obtained. We decrypted copies rather than originals, validated which backups were clean, and rebuilt the rest from scratch.
What was the root cause, and how long was the threat actor present?
The root cause was an exposed remote desktop system on an offsite backup server, running in a data centre managed by a third party of the organisation's own IT supplier. A misconfiguration made it reachable. The antivirus generated detections. The people reviewing those detections did not have the experience to interpret them and marked them as false positives.
The threat actor sat in that network for three months without acting, which suggests an initial access broker rather than the ransomware group. Once Snatch bought the access, they reached their objective within 24 hours.
Three months of opportunity to detect this.
What this case should change in your organisation
- Validate your backup strategy against a compromised environment. The question is not whether backups exist. It is whether an attacker who owns your network can reach them, encrypt them, and delete them.
- Monitor and harden your external exposure continuously. The system that let this attacker in was not supposed to be reachable. Somebody changed a configuration and nobody was watching the result.
- Extend third-party risk management to your suppliers' suppliers. This misconfiguration lived two steps down the chain, in a data centre managed by a third party of the organisation's IT provider.
- Make sure whoever reviews your alerts can interpret them. The tooling worked in this case. The interpretation failed. Detection without experienced analysis is a log file with a licence fee.
What is red teaming, and how is it different from a penetration test?
A red team simulates a complete attack against an organisation over weeks or months, working towards agreed objectives and testing people and processes alongside technology. A penetration test examines a defined system thoroughly and reports the vulnerabilities found in it.
Nick Bruinsma's framing is worth adopting. He calls a red team engagement "the happy road to ransomware", because it follows the same route with the same techniques, under control, with a team that tells you exactly what it did.
As Nick puts it, a penetration test drills every wall of the safe to find each weakness. A red team is trying to get the money out, by whatever route works.
|
Penetration test |
Red team engagement |
|
|---|---|---|
|
Scope |
A defined system or application |
The organisation as a whole |
|
Duration |
Days to weeks |
Weeks to months |
|
Goal |
Find and report vulnerabilities |
Reach an agreed objective by any viable route |
|
Tests |
Technology |
Technology, people and process together |
|
Defender awareness |
Usually informed |
Usually only a small control team knows |
|
Output |
A vulnerability report |
A narrative of the attack, plus joint review with the defenders |
What are flags in a red team engagement?
Flags are the objectives agreed before the engagement starts. Ransomware is a flag in roughly nine out of ten engagements, whatever sector the organisation operates in.
Some clients define this flag as reaching the position from which ransomware could be deployed, meaning domain or global administrator. Others want the full learning experience and ask for fake ransomware to be deployed: identical ransom note, nothing encrypted, and a key that reverses it immediately. This version is worth doing once an organisation has prepared for it.
Formal frameworks exist and are becoming more common by sector, including TIBER. What they share is that engagements are threat intelligence based and scenario based rather than open-ended.
What are the phases of a red team engagement?
|
Phase |
Purpose |
Who is involved |
|---|---|---|
|
Kickoff |
Establish a control team of trusted insiders who know the exercise is running, receive updates and can stop an escalation before it affects production |
Red team and control team |
|
Scoping |
Document the organisation's critical functions and the processes, people and technology supporting each one |
Red team and control team |
|
Threat intelligence |
Identify which threat actors operate against that sector, what motivates them and how they work, then build a profile the simulation will follow |
Red team |
|
Red team operation |
Execute the attack across four stages: reconnaissance, in, through and out |
Red team |
|
Purple teaming |
Replay the whole operation with the defensive team, comparing what was done against what was detected, and improving prevention and detection per technique |
Red team and defenders |
|
Gold teaming |
Take the same material to management, from a presentation through to a tabletop exercise or a live simulation using the access obtained |
Red team and executives |
Scoping is more concrete than it sounds. For a logistics business, a critical function might be global freight and delivery, supported by route optimisation and customs clearance workflows, operated by coordinators and compliance officers, running on control tower and tracking platforms.
The threat intelligence phase produces what Nick calls a method acting profile, so the simulation moves the way a specific real adversary moves. Some reach their objective in a day. Others remain quiet for months, exactly as the access broker did in the case above.
The operation itself has an internal logic. Reconnaissance establishes what is deployed and who matters. The in phase achieves initial access, whether by phishing, physical entry or exploiting an exposed application. The through phase escalates privilege and moves laterally, because you almost never land where the objective is. The out phase gathers what the flag requires and takes it.
Engagements can also start from assumed breach, skipping reconnaissance and beginning from the position an access broker would have sold. Given how common that scenario is in our incident data, it is often the more realistic starting point.
What is purple teaming, and why does it matter more than the intrusion?
Purple teaming is a joint session, usually a single day, where the red team and the defensive team replay the entire operation with all cards on the table, comparing every technique used against what was detected and deciding what to improve.
Gold teaming is the equivalent exercise for management, ranging from a briefing to a full decision-making simulation built on the access the red team obtained.
Nick's own view is that purple teaming, not the intrusion, is the most valuable part of an engagement. That matches our experience of what actually changes an organisation's security posture. The intrusion produces findings. The replay produces detection rules, process changes and people who recognise the pattern next time.
How do you get real value from a red team or an incident response plan?
-
Treat a red team as a learning exercise. There is nothing to pass. If the objective is to watch attackers fail, the honest advice is to hire the least capable team available, enjoy the result, and understand that it tells you nothing.
-
Define learning goals before anything starts. The preparation determines the value. A competent control team that understands the business is worth more to the outcome than any technique used later.
-
Test your security provider through the same conversation. Ask whether they operate on an assume breach principle rather than ingesting every log available. If you are receiving volumes of firewall false positives while identity coverage is thin, that is worth examining, because the majority of incidents we handle are identity related. A provider who welcomes a red team and engages properly in purple teaming is demonstrating something useful about how they work.
-
Prepare for the incident as a marathon. Recovery routinely takes weeks. Plan shift rotations and agree in advance who decides what. Bring in legal and communications expertise early rather than late, communicate openly with the stakeholders who need to know, and do not let the internal conversation turn into a blame exercise while the incident is still running.
What both sides, defence and offence, agree on
The road to ransomware runs through the ordinary: an exposed service, a supplier's misconfiguration, an alert that was closed too quickly, a phone call that sounded plausible. It is bought and sold as a product, and it is walked faster every year.
The organisations that come through this well are not the ones with the most tooling. They are the ones who found their own exposures first, tested whether their defences respond as intended, and decided in advance how they would act under pressure.
You can learn where your road runs from a red team, or you can learn it from an attacker. Only one of those gives you the report afterwards.
Talk to us about your environment. We will look at where you are exposed, what your current visibility covers, and what would happen in the first hour of an incident.
Experiencing a cyber incident? Call the Eye Security Incident Response hotline.
Frequently asked questions
How do most ransomware attacks start?
In Eye Security's incident response casework, most ransomware attacks start with an exposed internet-facing service such as remote desktop, valid credentials obtained from a leak or guessed, or legitimate remote access software installed by an employee acting on an attacker's instruction. Sophisticated exploitation is the exception rather than the rule.
What is an initial access broker?
An initial access broker is a criminal who specialises in breaking into organisations and selling that access to other criminals, including ransomware operators. Access frequently sells for a few thousand euros, against ransom demands in the hundreds of thousands.
How long do ransomware attackers stay in a network before deploying?
It varies widely because two different parties are often involved. In one case we handled, the access broker was present for three months without acting, and the ransomware group reached its objective within 24 hours of buying that access. Once an attacker is active, we currently observe roughly 45 minutes between initial access and lateral movement (own telemetry).
Should an organisation pay a ransom?
Payment should only ever be considered when there is no viable recovery path and the organisation cannot continue to operate without its systems. If backups have been deleted but not encrypted, specialist recovery firms can often restore them, which removes the need to negotiate at all. Any decision to negotiate belongs with the executive team, fully briefed, and with legal counsel involved.
What is the difference between a red team and a penetration test?
A penetration test examines a defined system and reports its vulnerabilities. A red team simulates a full attack against the whole organisation over weeks or months, works towards agreed objectives, and tests people and processes alongside technology.
What is purple teaming?
Purple teaming is a joint replay of a red team operation with the defensive team, comparing every technique the red team used against what was actually detected, and improving prevention and detection accordingly. It is generally where the most durable value of an engagement is created.