// BRIEFING

Ransomware. Four steps to a standstill. Ransomware. Vier stappen naar stilstand.

How one stolen login becomes weeks of downtime and a public data leak — in plain language: what happens at each step, and the single control that breaks the chain. Hoe één gestolen wachtwoord uitmondt in weken stilstand en een publiek datalek — in gewone taal: wat er bij elke stap gebeurt, en welke maatregel de keten breekt.

// STEP 01STAP 01

Someone walks in through the front door. Iemand loopt door de voordeur binnen.

initial access / a login, not a hack initial access / een inlog, geen hack
THE WAY INDE INGANG
🕵️
AttackerAanvaller
🏢
Our networkOns netwerk
🚪
VPN · NO SECOND FACTORVPN · GEEN TWEEDE FACTOR
🔑

Ransomware almost never starts with a clever exploit. It starts with a login. A password reused from a breached webshop, a phishing mail asking to “re-authenticate”, a VPN or remote-desktop portal that was never given a second factor. The attacker signs in the way an employee would, from an unremarkable location, and nothing flags it. Days or weeks pass before anything visible happens.

Why this step matters most: it is the only point where stopping the attacker is still cheap. Every step after it costs orders of magnitude more. A second factor on every external login, and an internet-facing footprint that is small and patched, removes most entry routes at once.

Ransomware begint bijna nooit met een slimme exploit. Het begint met een inlog. Een wachtwoord dat ook bij een gehackte webshop werd gebruikt, een phishingmail die vraagt om “opnieuw te verifiëren”, een VPN- of remote-desktopportaal dat nooit een tweede factor kreeg. De aanvaller logt in zoals een medewerker dat doet, vanaf een onopvallende locatie, en niets slaat alarm. Er gaan dagen of weken voorbij voordat er iets zichtbaar gebeurt.

Waarom juist deze stap telt: het is het enige moment waarop de aanvaller nog goedkoop te stoppen is. Elke stap daarna kost een veelvoud. Een tweede factor op elke externe inlog, en een kleine, gepatchte buitenkant, sluit de meeste ingangen in één keer.

A LOGIN, NOT A HACK · UNNOTICED FOR WEEKSEEN INLOG, GEEN HACK · WEKEN ONOPGEMERKT FIX: PHISHING-RESISTANT MFA + SMALL, PATCHED EDGEOPLOSSING: PHISHINGBESTENDIGE MFA + KLEINE, GEPATCHTE BUITENKANT
// STEP 02STAP 02

One laptop becomes the whole company. Eén laptop wordt het hele bedrijf.

lateral movement / privilege escalation lateral movement / rechten uitbreiden
DAY 1 → DAY 9DAG 1 → DAG 9
💻
💻
💻
🖥️
💻
💻
🖥️
💻
💻
💻
🖥️
💻
💻
🗄️
💻
💻
🖥️
💻

Once inside, the attacker encrypts nothing yet. They look around. On a flat network every server is reachable from every desk. An IT administrator who logs on to a workstation leaves credentials behind that can be harvested. Within days the attacker holds a domain administrator account — the keys to every system, including the ones that run the backups. From there, encrypting the entire estate is a scheduled task set to run on a Friday night.

Business impact: blast radius is the whole decision. A segmented network with separate admin accounts turns “the company is down” into “one department is down”. Same attacker, same entry point; a fraction of the cost.

Eenmaal binnen versleutelt de aanvaller nog niets. Hij kijkt rond. In een plat netwerk is elke server bereikbaar vanaf elk bureau. Een IT-beheerder die inlogt op een werkplek laat daar inloggegevens achter die geoogst kunnen worden. Binnen enkele dagen heeft de aanvaller een domeinbeheerdersaccount — de sleutel tot elk systeem, inclusief de systemen die de back-ups maken. Vanaf dat moment is het versleutelen van het hele bedrijf een geplande taak voor vrijdagnacht.

Bedrijfsimpact: de omvang van de schade is de hele beslissing. Een gesegmenteerd netwerk met gescheiden beheerdersaccounts maakt van “het bedrijf ligt plat” een “één afdeling ligt plat”. Dezelfde aanvaller, dezelfde ingang; een fractie van de kosten.

FLAT NETWORK · SHARED ADMIN · TOTAL BLAST RADIUSPLAT NETWERK · GEDEELD BEHEER · TOTALE SCHADE FIX: SEGMENTATION + TIERED ADMIN + EDROPLOSSING: SEGMENTATIE + GESCHEIDEN BEHEER + EDR
// STEP 03STAP 03

They copy everything first. Ze kopiëren eerst alles.

exfiltration / double extortion exfiltratie / dubbele afpersing
THE NIGHT BEFOREDE NACHT ERVOOR
🗄️
Our file serversOnze fileservers
☁️
Attacker's serverServer van aanvaller
📄
📄
📄
🕵️COPY FIRST, ENCRYPT LATEREERST KOPIËREN, DAN VERSLEUTELEN

Encryption is the loud part, and it comes last. Before it, the attacker quietly copies out what hurts most: contracts, personnel files, customer data, board minutes, the M&A data room. Then they encrypt, and the ransom note has two halves — pay to get your systems back, and pay so we do not publish. Restoring from backup fixes the first half only.

Business impact: this turns an outage into a data breach. GDPR's 72-hour notification, a regulator, customers and staff to inform, and a leak site with our name on it — whether or not we pay. Gigabytes leaving for an address we have never talked to is detectable. But only if someone is watching.

Versleutelen is het luidruchtige deel, en het komt als laatste. Daarvóór kopieert de aanvaller in stilte wat het meeste pijn doet: contracten, personeelsdossiers, klantgegevens, bestuursnotulen, de dataroom van de overname. Daarna versleutelt hij, en het losgeldbriefje heeft twee helften — betaal om je systemen terug te krijgen, en betaal zodat wij niet publiceren. Herstellen vanaf back-up lost alleen de eerste helft op.

Bedrijfsimpact: dit maakt van een storing een datalek. De 72-uursmelding onder de AVG, een toezichthouder, klanten en medewerkers die geïnformeerd moeten worden, en een leksite met onze naam erop — of we nu betalen of niet. Gigabytes die vertrekken naar een adres waar we nooit mee gesproken hebben, is detecteerbaar. Maar alleen als iemand kijkt.

DATA BREACH, NOT JUST DOWNTIME · PUBLISHED IF UNPAIDDATALEK, NIET ALLEEN STILSTAND · GEPUBLICEERD BIJ NIET BETALEN FIX: EDR + EGRESS MONITORING + LEAST-PRIVILEGE DATA ACCESSOPLOSSING: EDR + UITGAAND VERKEER BEWAKEN + MINIMALE DATATOEGANG
// STEP 04STAP 04

Your backups were the first thing they deleted. Je back-ups waren het eerste dat ze wisten.

backup destruction / recovery failure back-ups vernietigen / herstel mislukt
FRIDAY 02:00VRIJDAG 02:00
🕵️
Domain adminDomeinbeheerder
🗑
💾
Online backupOnline back-up
🔐OFFLINEOFFLINE
Immutable copyOnveranderbare kopie

Attackers read the same playbooks we do. Before the encryption runs, they find the backup server — reachable with the same domain administrator account — and delete the backups, or encrypt them too. Cloud backup tied to a connected account? Deleted. A retention period an administrator can shorten? Shortened. What survives is only what the attacker could not touch: a copy that is offline, immutable, or in an account no stolen credential can reach.

Business impact: this is the difference between a bad week and an existential event. Companies with tested, untouchable backups restore and refuse to pay. The rest negotiate. “We have backups” is not the question. “When did we last restore everything, and how many days did it take?” is.

Aanvallers lezen dezelfde handboeken als wij. Voordat de versleuteling draait, zoeken ze de back-upserver — bereikbaar met datzelfde domeinbeheerdersaccount — en wissen ze de back-ups, of versleutelen ze die ook. Cloudback-up gekoppeld aan een verbonden account? Gewist. Een bewaartermijn die een beheerder kan verkorten? Verkort. Wat overblijft is alleen wat de aanvaller niet kon aanraken: een kopie die offline staat, onveranderbaar is, of in een account zit waar geen gestolen inlog bij kan.

Bedrijfsimpact: dit is het verschil tussen een slechte week en een existentiële crisis. Bedrijven met geteste, onaantastbare back-ups herstellen en weigeren te betalen. De rest onderhandelt. “We hebben back-ups” is niet de vraag. “Wanneer hebben we voor het laatst álles teruggezet, en hoeveel dagen kostte dat?” wel.

NO RECOVERY · NO LEVERAGE · WEEKS OF DOWNTIMEGEEN HERSTEL · GEEN ONDERHANDELINGSPOSITIE · WEKEN STILSTAND FIX: IMMUTABLE OFFLINE BACKUPS + TESTED FULL RESTOREOPLOSSING: ONVERANDERBARE OFFLINE BACK-UPS + GETEST VOLLEDIG HERSTEL
// CONTROLSMAATREGELEN

What breaks the chain. Wat de keten breekt.

mostly configuration and discipline — not a new product per step vooral configuratie en discipline — geen nieuw product per stap
DEFENCE STACKVERDEDIGINGSLAGEN
MFA EDR SEGMENTATIONSEGMENTATIE TIERED ADMINGESCHEIDEN BEHEER IMMUTABLE BACKUPSONVERANDERBARE BACK-UPS
ControlBreaksIn one line
MFAEntry (01)A second factor on every login that reaches us from outside. Hardware keys or passkeys for administrators.
Attack surfaceEntry (01)Nothing on the internet that does not need to be there. What remains is patched within days, not quarters.
SegmentationSpread (02)Networks divided so a desk cannot reach the server room, and workstations cannot talk to each other.
Tiered adminSpread (02)Domain administrator accounts never touch a workstation or read mail. Separate account, separate device.
EDRSpread (02), Steal (03)Software on every endpoint that spots attacker behaviour and isolates a machine in seconds — with someone watching around the clock.
Egress monitoringSteal (03)An alert when gigabytes leave for an address we have never talked to.
Immutable backupsBackups (04)A copy nobody can delete or change for a fixed period, not even an administrator. Offline or in a separate account.
Restore testBackups (04)Rebuild the critical systems from backup, for real, at least yearly. Measure the hours. That number is our true downtime.
Response planAll fourWho decides, who calls whom, who speaks to press and regulator, at 03:00 on a Saturday. Written in advance, rehearsed yearly.
MaatregelBreektIn één zin
MFABinnenkomen (01)Een tweede factor op elke inlog die van buiten komt. Hardwaresleutels of passkeys voor beheerders.
BuitenkantBinnenkomen (01)Niets aan het internet dat er niet hoeft te staan. Wat overblijft wordt binnen dagen gepatcht, niet binnen kwartalen.
SegmentatieVerspreiden (02)Netwerken zo verdeeld dat een bureau niet bij de serverruimte kan, en werkplekken niet met elkaar praten.
Gescheiden beheerVerspreiden (02)Domeinbeheerdersaccounts raken nooit een werkplek aan en lezen geen mail. Apart account, apart apparaat.
EDRVerspreiden (02), Stelen (03)Software op elk apparaat die aanvallersgedrag herkent en een machine in seconden isoleert — met iemand die dag en nacht meekijkt.
Uitgaand verkeerStelen (03)Een alarm zodra gigabytes vertrekken naar een adres waar we nooit mee gesproken hebben.
Onveranderbare back-upsBack-ups (04)Een kopie die niemand een vaste periode kan wissen of wijzigen, ook geen beheerder. Offline of in een apart account.
HersteltestBack-ups (04)De kritieke systemen echt terugzetten vanaf back-up, minstens jaarlijks. Meet de uren. Dat getal is onze werkelijke stilstand.
ResponsplanAlle vierWie beslist, wie belt wie, wie praat met pers en toezichthouder, om 03:00 op een zaterdag. Vooraf geschreven, jaarlijks geoefend.
The board-level point: two numbers decide everything — how many days can we be down, and how much data can we afford to lose. Every control above is priced against those two. And decide now, in calm, whether we would ever pay. At 03:00 with the company down is the wrong moment to have that debate. De kern voor de directie: twee getallen bepalen alles — hoeveel dagen kunnen we plat liggen, en hoeveel data kunnen we ons veroorloven te verliezen. Elke maatregel hierboven wordt tegen die twee afgewogen. En beslis nu, in rust, of we ooit zouden betalen. Om 03:00 met een stilstaand bedrijf is het verkeerde moment voor dat debat.
// RISK & COMPLIANCERISICO & COMPLIANCE

On the register, and in the audit. In het risicoregister, en in de audit.

indicative — confirm scope and deadlines with legal and complianceindicatief — bevestig reikwijdte en termijnen met legal en compliance
LikelihoodKansHighHoog

Every organisation with email and remote access is a target. Entry needs a password, not an exploit.Elke organisatie met e-mail en externe toegang is doelwit. Binnenkomen vraagt een wachtwoord, geen exploit.

ImpactImpactCriticalKritiek

Weeks of downtime, a data breach with notification duties, a ransom demand and months of recovery cost.Weken stilstand, een datalek met meldplicht, een losgeldeis en maanden herstelkosten.

Residual after controlsRestrisico na maatregelenMediumMiddel

Entry stays possible. Segmentation, EDR and immutable backups bound the blast radius and cut downtime to days.Binnenkomen blijft mogelijk. Segmentatie, EDR en onveranderbare back-ups beperken de schade en brengen de stilstand terug tot dagen.

Risk ownerRisico-eigenaarCIO / COOCIO / COO

Executes through the CISO and IT. The board owns the two numbers: tolerable downtime and tolerable data loss.Uitvoering via de CISO en IT. De directie is eigenaar van de twee getallen: aanvaardbare stilstand en aanvaardbaar dataverlies.

Key risk indicatorsKernrisico-indicatorenFour numbers to ask forVier getallen om naar te vragen

% of external logins without MFA · days to patch a critical internet-facing flaw · date and duration of the last full restore test · % of endpoints with EDR.% externe inlogs zonder MFA · dagen tot een kritieke kwetsbaarheid aan de buitenkant is gepatcht · datum en duur van de laatste volledige hersteltest · % apparaten met EDR.

Risk register entryTekst voor het risicoregisterOne sentenceEén zin

“Ransomware through compromised credentials and a flat network causes a multi-week outage, a personal-data breach and extortion.”“Ransomware via gestolen inloggegevens en een plat netwerk veroorzaakt wekenlange stilstand, een datalek en afpersing.”

FrameworkWhat it requires of youWhen a supplier hands you their reportWhen this incident happens
NIS2Risk management measures covering incident handling, backup and continuity, supply chain, MFA and encryption. Management approves them, follows training, and is personally accountable.There is no NIS2 certificate. Ask how the supplier covers these measures, and put their duty to warn you of incidents in the contract.A significant incident: early warning to the national authority within 24 hours, full notification within 72, final report within a month. Affected customers must be informed.
DORAFor financial entities: an ICT risk framework approved by the board, backup and restore policies that are actually tested, a register of ICT third parties, and resilience testing.A report is input, not a substitute. Critical ICT providers need the contractual clauses DORA prescribes, including audit rights and an exit strategy.A major ICT incident: initial notification to the supervisor within hours of classification, intermediate report within 72 hours, final report within a month.
SOC 2If you issue one: controls for access, change, backup and incident response are tested over a period (Type II). Every exception is printed in the report.Check the period, the systems in scope and the exceptions. Then read the complementary user entity controls: that is the list of things you must do yourself.The incident appears in the next report as a deviation, auditors test the response, and customers will ask for a bridge letter and your root-cause analysis.
ISAE 3402Assurance over outsourced processes relevant to financial reporting. The service organisation sets the scope, so security controls may be thin or absent.Read the control objectives first. If backup and recovery are not among them, the report says nothing about ransomware resilience.The service organisation must disclose the incident to the user auditors. If you are the service organisation, expect it in your opinion and in your customers’ audits.
KaderWat het van u vraagtAls een leverancier u zijn rapport geeftAls dit incident u treft
NIS2Risicobeheersmaatregelen voor incidentafhandeling, back-up en continuïteit, toeleveringsketen, MFA en versleuteling. Het bestuur keurt ze goed, volgt training en is persoonlijk aansprakelijk.Er bestaat geen NIS2-certificaat. Vraag hoe de leverancier deze maatregelen invult, en leg zijn plicht om u bij incidenten te waarschuwen vast in het contract.Een significant incident: vroegtijdige waarschuwing aan de toezichthouder binnen 24 uur, volledige melding binnen 72 uur, eindrapport binnen een maand. Getroffen klanten moeten worden geïnformeerd.
DORAVoor financiële instellingen: een ICT-risicokader dat het bestuur goedkeurt, back-up- en herstelbeleid dat echt wordt getest, een register van ICT-derden, en weerbaarheidstesten.Een rapport is input, geen vervanging. Kritieke ICT-leveranciers vereisen de contractbepalingen die DORA voorschrijft, inclusief auditrechten en een exitstrategie.Een ernstig ICT-incident: eerste melding aan de toezichthouder binnen enkele uren na classificatie, tussenrapport binnen 72 uur, eindrapport binnen een maand.
SOC 2Als u er zelf een afgeeft: maatregelen voor toegang, wijzigingen, back-up en incidentrespons worden over een periode getest (Type II). Elke afwijking staat in het rapport.Controleer de periode, de systemen binnen scope en de afwijkingen. Lees daarna de complementary user entity controls: dat is de lijst van wat u zelf moet doen.Het incident verschijnt in het volgende rapport als afwijking, auditors testen de respons, en klanten vragen om een bridge letter en uw oorzaakanalyse.
ISAE 3402Zekerheid over uitbestede processen die relevant zijn voor de financiële verslaggeving. De serviceorganisatie bepaalt de scope, dus beveiligingsmaatregelen kunnen mager of afwezig zijn.Lees eerst de beheersdoelstellingen. Staan back-up en herstel er niet bij, dan zegt het rapport niets over weerbaarheid tegen ransomware.De serviceorganisatie moet het incident melden aan de auditors van haar klanten. Bent u zelf de serviceorganisatie, verwacht het dan in uw oordeel en in de audits van uw klanten.