Ransomware · Detection, containment & readiness

The encryption is the last step. There are hours before it.

Ransomware is not a moment, it is a sequence — access, persistence, reconnaissance, exfiltration, and only then encryption. Huntress reports the average time from initial access to ransom rose to roughly 20 hours during 2025. That interval is the whole opportunity, and using it requires somebody watching while it elapses.

The window

Why the delay is the defence.

Time to ransom rose

Huntress reports the average moved from about 17 hours to about 20 across 2025 — not because attackers got slower, but because they prioritised staying hidden and stealing data before encrypting. Longer dwell is more opportunity to detect, and more data already gone if you do not.

The fastest group is much faster

Huntress puts Akira — linked to 22% of ransomware incidents it observed — at a time to ransom of 6.58 hours. An average is not a planning assumption. Overnight and weekend coverage is where this is decided.

Extortion without encryption

Because exfiltration now precedes encryption, a clean restore no longer ends the incident. Backups answer the availability problem and do nothing about the disclosure one, which is why detection during the sequence matters more than it used to.

What the service covers

Cover the entry points, then watch the sequence.

Endpoint detection and response

Continuous endpoint monitoring with managed investigation and response, including host isolation where containment is warranted — the action that stops lateral movement while the rest is worked out.

Managed endpoint security →

Identity monitoring

Most access now arrives through a valid credential rather than an exploit. Detecting the sign-in that should not have happened is upstream of everything else in the chain.

Identity security →

Log visibility

Reconstructing what an attacker did, and proving what they did not reach, depends on logs that were centralized before the incident. Afterwards is too late to start collecting them.

Managed SIEM →

Exposure reduction

Cyberneza reviews internet-exposed services, remote access paths, administrative accounts, RMM tooling and patch posture — the entry points the sequence starts from — and develops a prioritized remediation plan.

Vulnerability management →

Response readiness

Who decides to isolate, who contacts the insurer, who talks to customers, and where the plan is stored when the network is unavailable. Decided in advance, or improvised badly.

Incident response →

Recovery assumptions, tested

An untested backup is an assumption. We review whether backups are isolated from the credentials an attacker would hold, and whether a restore has actually been performed rather than scheduled.

What the 2025 data showed

Concentration, and a shift away from exploits.

Huntress reports that over 51% of ransomware incidents it observed were linked to four groups — Akira, Medusa, Qilin and RansomHub — and that tradecraft shifted away from exploit-based attacks toward abuse of remote monitoring and management tooling and commodity malware loaders. Abuse of RMM tooling rose 277%.

The practical consequence is that the current ransomware playbook mostly consists of authorized-looking actions. Patching remains necessary and is no longer where the detection happens.

Source: Huntress 2026 Cyber Threat Report. Figures are Huntress’s measurements. Cyberneza is an authorized Huntress reseller. Our read on the report →

If you are already in one

This page is not the right resource for an active incident.

If you believe an attack is under way, contact your cyber-insurance carrier’s incident hotline first — most policies require it, and using an unapproved responder can affect coverage. Preserve systems rather than rebuilding them, and do not power off machines you may need evidence from. If you have no carrier or no plan, get in touch and we will help you work out the immediate sequence.

Want to know where your exposure actually is?

We can review internet-exposed access, identity controls, logging and recovery assumptions, and scope monitoring around the gaps that review finds.

Supported platforms, features, response actions, integrations and licensing depend on the selected Huntress service and current product availability.