Ransomware and Breaches into Organizations

People & Organizations
The topic combines practical methods of breaching the corporate environment and related ransomware, including identity abuse, weak access controls, and slow incident response.

Key questions and insights

How do attackers combine phishing, account abuse, and other techniques when breaching an organization?

Before an attack, attackers prepare by reconnaissance of the environment and use publicly available data.

Why do MFA and other protections fail when accounts or processes are poorly configured?

Identity and existing accounts are a common entry point into other parts of the environment.

How quickly must an organization respond so that ransomware does not grow into a larger incident?

Ransomware attacks are significantly worsened by the organization's slow response.

Which systems and access paths are usually most vulnerable during an attack?

MFA alone is not enough if the attacker is working with a real account or the user approves the access.

What increases the impact of an attack on an organization?

Poor configuration, weak permissions, and unmaintained systems increase the impact of an attack.

Explore Blue Events Insights

Explore more themes and insights that connect conference know-how with practical business impact.

View all themes