How one stolen login becomes weeks of downtime and a public data leak — in plain language: what happens at each step, and the single control that breaks the chain. Hoe één gestolen wachtwoord uitmondt in weken stilstand en een publiek datalek — in gewone taal: wat er bij elke stap gebeurt, en welke maatregel de keten breekt.
Ransomware almost never starts with a clever exploit. It starts with a login. A password reused from a breached webshop, a phishing mail asking to “re-authenticate”, a VPN or remote-desktop portal that was never given a second factor. The attacker signs in the way an employee would, from an unremarkable location, and nothing flags it. Days or weeks pass before anything visible happens.
Why this step matters most: it is the only point where stopping the attacker is still cheap. Every step after it costs orders of magnitude more. A second factor on every external login, and an internet-facing footprint that is small and patched, removes most entry routes at once.
Ransomware begint bijna nooit met een slimme exploit. Het begint met een inlog. Een wachtwoord dat ook bij een gehackte webshop werd gebruikt, een phishingmail die vraagt om “opnieuw te verifiëren”, een VPN- of remote-desktopportaal dat nooit een tweede factor kreeg. De aanvaller logt in zoals een medewerker dat doet, vanaf een onopvallende locatie, en niets slaat alarm. Er gaan dagen of weken voorbij voordat er iets zichtbaar gebeurt.
Waarom juist deze stap telt: het is het enige moment waarop de aanvaller nog goedkoop te stoppen is. Elke stap daarna kost een veelvoud. Een tweede factor op elke externe inlog, en een kleine, gepatchte buitenkant, sluit de meeste ingangen in één keer.
Once inside, the attacker encrypts nothing yet. They look around. On a flat network every server is reachable from every desk. An IT administrator who logs on to a workstation leaves credentials behind that can be harvested. Within days the attacker holds a domain administrator account — the keys to every system, including the ones that run the backups. From there, encrypting the entire estate is a scheduled task set to run on a Friday night.
Business impact: blast radius is the whole decision. A segmented network with separate admin accounts turns “the company is down” into “one department is down”. Same attacker, same entry point; a fraction of the cost.
Eenmaal binnen versleutelt de aanvaller nog niets. Hij kijkt rond. In een plat netwerk is elke server bereikbaar vanaf elk bureau. Een IT-beheerder die inlogt op een werkplek laat daar inloggegevens achter die geoogst kunnen worden. Binnen enkele dagen heeft de aanvaller een domeinbeheerdersaccount — de sleutel tot elk systeem, inclusief de systemen die de back-ups maken. Vanaf dat moment is het versleutelen van het hele bedrijf een geplande taak voor vrijdagnacht.
Bedrijfsimpact: de omvang van de schade is de hele beslissing. Een gesegmenteerd netwerk met gescheiden beheerdersaccounts maakt van “het bedrijf ligt plat” een “één afdeling ligt plat”. Dezelfde aanvaller, dezelfde ingang; een fractie van de kosten.
Encryption is the loud part, and it comes last. Before it, the attacker quietly copies out what hurts most: contracts, personnel files, customer data, board minutes, the M&A data room. Then they encrypt, and the ransom note has two halves — pay to get your systems back, and pay so we do not publish. Restoring from backup fixes the first half only.
Business impact: this turns an outage into a data breach. GDPR's 72-hour notification, a regulator, customers and staff to inform, and a leak site with our name on it — whether or not we pay. Gigabytes leaving for an address we have never talked to is detectable. But only if someone is watching.
Versleutelen is het luidruchtige deel, en het komt als laatste. Daarvóór kopieert de aanvaller in stilte wat het meeste pijn doet: contracten, personeelsdossiers, klantgegevens, bestuursnotulen, de dataroom van de overname. Daarna versleutelt hij, en het losgeldbriefje heeft twee helften — betaal om je systemen terug te krijgen, en betaal zodat wij niet publiceren. Herstellen vanaf back-up lost alleen de eerste helft op.
Bedrijfsimpact: dit maakt van een storing een datalek. De 72-uursmelding onder de AVG, een toezichthouder, klanten en medewerkers die geïnformeerd moeten worden, en een leksite met onze naam erop — of we nu betalen of niet. Gigabytes die vertrekken naar een adres waar we nooit mee gesproken hebben, is detecteerbaar. Maar alleen als iemand kijkt.
Attackers read the same playbooks we do. Before the encryption runs, they find the backup server — reachable with the same domain administrator account — and delete the backups, or encrypt them too. Cloud backup tied to a connected account? Deleted. A retention period an administrator can shorten? Shortened. What survives is only what the attacker could not touch: a copy that is offline, immutable, or in an account no stolen credential can reach.
Business impact: this is the difference between a bad week and an existential event. Companies with tested, untouchable backups restore and refuse to pay. The rest negotiate. “We have backups” is not the question. “When did we last restore everything, and how many days did it take?” is.
Aanvallers lezen dezelfde handboeken als wij. Voordat de versleuteling draait, zoeken ze de back-upserver — bereikbaar met datzelfde domeinbeheerdersaccount — en wissen ze de back-ups, of versleutelen ze die ook. Cloudback-up gekoppeld aan een verbonden account? Gewist. Een bewaartermijn die een beheerder kan verkorten? Verkort. Wat overblijft is alleen wat de aanvaller niet kon aanraken: een kopie die offline staat, onveranderbaar is, of in een account zit waar geen gestolen inlog bij kan.
Bedrijfsimpact: dit is het verschil tussen een slechte week en een existentiële crisis. Bedrijven met geteste, onaantastbare back-ups herstellen en weigeren te betalen. De rest onderhandelt. “We hebben back-ups” is niet de vraag. “Wanneer hebben we voor het laatst álles teruggezet, en hoeveel dagen kostte dat?” wel.
| Control | Breaks | In one line |
|---|---|---|
| MFA | Entry (01) | A second factor on every login that reaches us from outside. Hardware keys or passkeys for administrators. |
| Attack surface | Entry (01) | Nothing on the internet that does not need to be there. What remains is patched within days, not quarters. |
| Segmentation | Spread (02) | Networks divided so a desk cannot reach the server room, and workstations cannot talk to each other. |
| Tiered admin | Spread (02) | Domain administrator accounts never touch a workstation or read mail. Separate account, separate device. |
| EDR | Spread (02), Steal (03) | Software on every endpoint that spots attacker behaviour and isolates a machine in seconds — with someone watching around the clock. |
| Egress monitoring | Steal (03) | An alert when gigabytes leave for an address we have never talked to. |
| Immutable backups | Backups (04) | A copy nobody can delete or change for a fixed period, not even an administrator. Offline or in a separate account. |
| Restore test | Backups (04) | Rebuild the critical systems from backup, for real, at least yearly. Measure the hours. That number is our true downtime. |
| Response plan | All four | Who decides, who calls whom, who speaks to press and regulator, at 03:00 on a Saturday. Written in advance, rehearsed yearly. |
| Maatregel | Breekt | In één zin |
|---|---|---|
| MFA | Binnenkomen (01) | Een tweede factor op elke inlog die van buiten komt. Hardwaresleutels of passkeys voor beheerders. |
| Buitenkant | Binnenkomen (01) | Niets aan het internet dat er niet hoeft te staan. Wat overblijft wordt binnen dagen gepatcht, niet binnen kwartalen. |
| Segmentatie | Verspreiden (02) | Netwerken zo verdeeld dat een bureau niet bij de serverruimte kan, en werkplekken niet met elkaar praten. |
| Gescheiden beheer | Verspreiden (02) | Domeinbeheerdersaccounts raken nooit een werkplek aan en lezen geen mail. Apart account, apart apparaat. |
| EDR | Verspreiden (02), Stelen (03) | Software op elk apparaat die aanvallersgedrag herkent en een machine in seconden isoleert — met iemand die dag en nacht meekijkt. |
| Uitgaand verkeer | Stelen (03) | Een alarm zodra gigabytes vertrekken naar een adres waar we nooit mee gesproken hebben. |
| Onveranderbare back-ups | Back-ups (04) | Een kopie die niemand een vaste periode kan wissen of wijzigen, ook geen beheerder. Offline of in een apart account. |
| Hersteltest | Back-ups (04) | De kritieke systemen echt terugzetten vanaf back-up, minstens jaarlijks. Meet de uren. Dat getal is onze werkelijke stilstand. |
| Responsplan | Alle vier | Wie beslist, wie belt wie, wie praat met pers en toezichthouder, om 03:00 op een zaterdag. Vooraf geschreven, jaarlijks geoefend. |
Every organisation with email and remote access is a target. Entry needs a password, not an exploit.Elke organisatie met e-mail en externe toegang is doelwit. Binnenkomen vraagt een wachtwoord, geen exploit.
Weeks of downtime, a data breach with notification duties, a ransom demand and months of recovery cost.Weken stilstand, een datalek met meldplicht, een losgeldeis en maanden herstelkosten.
Entry stays possible. Segmentation, EDR and immutable backups bound the blast radius and cut downtime to days.Binnenkomen blijft mogelijk. Segmentatie, EDR en onveranderbare back-ups beperken de schade en brengen de stilstand terug tot dagen.
Executes through the CISO and IT. The board owns the two numbers: tolerable downtime and tolerable data loss.Uitvoering via de CISO en IT. De directie is eigenaar van de twee getallen: aanvaardbare stilstand en aanvaardbaar dataverlies.
% of external logins without MFA · days to patch a critical internet-facing flaw · date and duration of the last full restore test · % of endpoints with EDR.% externe inlogs zonder MFA · dagen tot een kritieke kwetsbaarheid aan de buitenkant is gepatcht · datum en duur van de laatste volledige hersteltest · % apparaten met EDR.
“Ransomware through compromised credentials and a flat network causes a multi-week outage, a personal-data breach and extortion.”“Ransomware via gestolen inloggegevens en een plat netwerk veroorzaakt wekenlange stilstand, een datalek en afpersing.”
| Framework | What it requires of you | When a supplier hands you their report | When this incident happens |
|---|---|---|---|
| NIS2 | Risk management measures covering incident handling, backup and continuity, supply chain, MFA and encryption. Management approves them, follows training, and is personally accountable. | There is no NIS2 certificate. Ask how the supplier covers these measures, and put their duty to warn you of incidents in the contract. | A significant incident: early warning to the national authority within 24 hours, full notification within 72, final report within a month. Affected customers must be informed. |
| DORA | For financial entities: an ICT risk framework approved by the board, backup and restore policies that are actually tested, a register of ICT third parties, and resilience testing. | A report is input, not a substitute. Critical ICT providers need the contractual clauses DORA prescribes, including audit rights and an exit strategy. | A major ICT incident: initial notification to the supervisor within hours of classification, intermediate report within 72 hours, final report within a month. |
| SOC 2 | If you issue one: controls for access, change, backup and incident response are tested over a period (Type II). Every exception is printed in the report. | Check the period, the systems in scope and the exceptions. Then read the complementary user entity controls: that is the list of things you must do yourself. | The incident appears in the next report as a deviation, auditors test the response, and customers will ask for a bridge letter and your root-cause analysis. |
| ISAE 3402 | Assurance over outsourced processes relevant to financial reporting. The service organisation sets the scope, so security controls may be thin or absent. | Read the control objectives first. If backup and recovery are not among them, the report says nothing about ransomware resilience. | The service organisation must disclose the incident to the user auditors. If you are the service organisation, expect it in your opinion and in your customers’ audits. |
| Kader | Wat het van u vraagt | Als een leverancier u zijn rapport geeft | Als dit incident u treft |
|---|---|---|---|
| NIS2 | Risicobeheersmaatregelen voor incidentafhandeling, back-up en continuïteit, toeleveringsketen, MFA en versleuteling. Het bestuur keurt ze goed, volgt training en is persoonlijk aansprakelijk. | Er bestaat geen NIS2-certificaat. Vraag hoe de leverancier deze maatregelen invult, en leg zijn plicht om u bij incidenten te waarschuwen vast in het contract. | Een significant incident: vroegtijdige waarschuwing aan de toezichthouder binnen 24 uur, volledige melding binnen 72 uur, eindrapport binnen een maand. Getroffen klanten moeten worden geïnformeerd. |
| DORA | Voor financiële instellingen: een ICT-risicokader dat het bestuur goedkeurt, back-up- en herstelbeleid dat echt wordt getest, een register van ICT-derden, en weerbaarheidstesten. | Een rapport is input, geen vervanging. Kritieke ICT-leveranciers vereisen de contractbepalingen die DORA voorschrijft, inclusief auditrechten en een exitstrategie. | Een ernstig ICT-incident: eerste melding aan de toezichthouder binnen enkele uren na classificatie, tussenrapport binnen 72 uur, eindrapport binnen een maand. |
| SOC 2 | Als u er zelf een afgeeft: maatregelen voor toegang, wijzigingen, back-up en incidentrespons worden over een periode getest (Type II). Elke afwijking staat in het rapport. | Controleer de periode, de systemen binnen scope en de afwijkingen. Lees daarna de complementary user entity controls: dat is de lijst van wat u zelf moet doen. | Het incident verschijnt in het volgende rapport als afwijking, auditors testen de respons, en klanten vragen om een bridge letter en uw oorzaakanalyse. |
| ISAE 3402 | Zekerheid over uitbestede processen die relevant zijn voor de financiële verslaggeving. De serviceorganisatie bepaalt de scope, dus beveiligingsmaatregelen kunnen mager of afwezig zijn. | Lees eerst de beheersdoelstellingen. Staan back-up en herstel er niet bij, dan zegt het rapport niets over weerbaarheid tegen ransomware. | De serviceorganisatie moet het incident melden aan de auditors van haar klanten. Bent u zelf de serviceorganisatie, verwacht het dan in uw oordeel en in de audits van uw klanten. |