Pandemic conditions give attackers more leverage because people receive more legitimate crisis-related email, making phishing easier to hide. Remote work also increases use of remote desktop protocol, which remains a common ransomware entry path. In healthcare, the pressure to keep patient care running raises the perceived cost of downtime, so victims may feel pushed toward faster, riskier decisions.
How pandemic pressure changes the attacker’s advantage
Pandemic conditions create a heavier stream of legitimate crisis communication, which gives phishing and social engineering more cover. When staff are busy, anxious, and making rapid decisions, it becomes harder to distinguish malicious messages from real operational updates. That is why the same lure can work better during a crisis than in calmer periods.
The pressure is not only psychological. Attackers benefit when organisations are flooded with policy changes, HR notices, health guidance, supplier updates, and emergency process exceptions, because those messages normalise urgency and reduce the chance that a suspicious email stands out.
Why remote access makes ransomware entry paths easier to exploit
Remote work expands the attack surface by pushing more business activity through externally reachable services, especially remote desktop protocol and other remote access tooling. Those paths are valuable to ransomware operators because they offer a direct route into interactive sessions, often with fewer layers of inspection than a well-segmented internal path.
The problem is usually not remote access itself, but weak exposure management around it: internet-facing endpoints, reused credentials, stale accounts, and insufficient authentication hardening all make compromise more likely. Once an initial foothold exists, ransomware crews can move quickly to deployment and encryption.
Why healthcare pressure changes the defender’s decision-making
In healthcare, the cost of interruption is felt immediately in patient care, so the attacker does not need to win every technical exchange to gain leverage. If leaders believe downtime will endanger treatment or overload already strained teams, they may accept faster containment decisions, delayed recovery work, or negotiated responses that would be less likely in other sectors.
That pressure affects defence because ransomware is designed to convert operational urgency into strategic weakness. Even when backups, segmentation, and response plans exist, the defender’s tolerance for disruption may be much lower, which raises the attacker’s expected payoff.
Risk and Threat Considerations
Ransomware becomes harder to resist when crisis conditions increase both the chance of initial compromise and the cost of taking systems offline. The threat is amplified by urgency, because attackers can use familiar crisis themes to hide malicious messages and then exploit the defender’s need to restore service quickly.
Failure mechanism: Phishing, exposed remote access, and time pressure combine to reduce verification, speed up access, and increase the likelihood that a ransomware operator can obtain a foothold before defenders detect and contain the intrusion.
Impact: Organisations face faster compromise, shorter decision windows, and more leverage for extortion, especially where service continuity is mission-critical and leadership is under pressure to restore operations before full validation is complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Crisis-themed lures increase phishing success during pandemic pressure. |
| T1021.001 — Remote Desktop Protocol | Remote desktop is a common ransomware entry path in remote-work conditions. | |
| T1486 — Data Encrypted for Impact | Ransomware pressure aims to force restoration or payment through encryption. | |
| Recommendation — Hunt for urgent-message phishing and tighten mail filtering, user reporting, and response workflows. Reduce exposed RDP, require strong authentication, and monitor for suspicious remote sessions. Prioritise rapid containment and tested recovery before negotiating under operational pressure. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Remote-access abuse and weak credential controls drive ransomware entry paths. |
| Recommendation — Restrict remote access, remove stale accounts, and enforce least privilege on externally reachable services. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Stronger authentication reduces compromise of remote access during crisis pressure. |
| Recommendation — Require phishing-resistant authentication for high-risk remote access and privileged sessions. | ||
Practitioner Guidance
What to prioritise: Treat crisis-period communications and remote access controls as a single attack surface. If the organisation is issuing urgent operational updates, security teams should assume phishing realism will rise and increase scrutiny on message provenance, login anomalies, and remote access exposure at the same time.
Decision rule: If remote access is required for continuity, harden it before the crisis peaks rather than during incident response. The important judgement is whether the access path can be abused for interactive compromise, not whether it is “needed” in principle.
What to verify: Confirm that remote access is limited to named users, strongly authenticated, and monitored for abnormal sign-in patterns, because weak control at this layer is what turns pressure into ransomware reach.
Practitioner takeaway: Pandemic pressure does not create ransomware from nothing, it makes existing weaknesses more profitable by compressing attention, increasing trust in urgent messages, and reducing the defender’s freedom to delay risky decisions.
Related resources from NHI Mgmt Group
- Why does IGA transformation become harder when organisations are under regulatory pressure and shifting to a services model?
- How should organisations defend biometric authentication against spoofing attacks?
- How should organisations defend against AI-powered vishing attacks?
- How should organisations defend biometric onboarding against injection attacks in mobile and web flows?