By NHI Mgmt Group Editorial TeamBased on DigiCert: “Ransomware: From Rising Threat to Business Crisis” (February 27, 2026)

TL;DR: Ransomware has shifted from simple file encryption to industrialized business disruption, with attackers now stealing data, escalating privileges, and timing impact to operational choke points, according to DigiCert. That makes identity, PKI, and resilience planning part of the core defense model, not adjacent controls.


At a glance

What this is: This is DigiCert’s analysis of how ransomware has evolved from file encryption into an identity- and trust-driven business disruption model.

Why it matters: It matters because IAM, PKI, and continuity teams now have to treat identity assurance, certificate trust, and recovery readiness as part of the same ransomware defence model.


Context

Ransomware is no longer just a file-encryption event. In this article, DigiCert argues that modern campaigns combine identity compromise, stealthy dwell time, data theft, and operational timing to turn security incidents into continuity failures.

For identity programmes, the shift is important because the attack path now runs through authentication gaps, privileged access, trust infrastructure, and recovery dependencies. That makes IAM, PAM, PKI, and resilience planning part of the same control surface rather than separate workstreams.


Key questions

Q: What breaks when ransomware targets identity and trust systems?

A: Business continuity breaks first. Once attackers can abuse identities or compromise trust anchors, they can move from access into claims, payments, software updates, or certificate-driven services. That turns a security incident into an operational outage, which is why identity and PKI recovery must be part of the response plan.

Q: Why do compliant organisations still get hit hard by ransomware?

A: Compliance sets a baseline, but ransomware operators only need one repeatable weakness to create major damage. Gaps in MFA, remote access, third-party trust, or privilege control can remain even in audited environments. The result is a system that passes review but still fails when attackers pursue operational disruption.

Q: What are the signs that ransomware is already moving through an environment?

A: Common warning signs include unusual file renaming or bulk rewriting, privilege escalation, suspicious lateral movement, sudden system slowdown or crashes, and outbound connections to known malicious infrastructure. Teams should also watch for processes that rapidly read and rewrite many files at once. These indicators matter because they often appear before full encryption completes and containment becomes harder.

Q: Should teams prioritise identity hardening or recovery planning for ransomware?

A: They need both, but identity hardening reduces the chance of initial leverage while recovery planning limits business damage after compromise. The article’s core lesson is that continuity failures happen when organisations treat prevention and recovery as separate programmes instead of one resilience model.


Technical breakdown

How ransomware uses identity as the first leverage point

Modern ransomware operators increasingly start with valid access rather than noisy exploitation. Stolen credentials, weak MFA coverage, and compromised third-party paths let attackers enter quietly, then stay invisible while they map internal relationships and business-critical dependencies. That changes the technical problem from pure malware containment to identity assurance and session trust. Once an attacker can authenticate as a legitimate user or service, detection becomes much harder because their activity can resemble normal administration until the final stage of the attack.

Practical implication: reduce the lifetime and reach of authentication paths that can be reused for ransomware entry.

Why encryption is now only the final step

The article describes a pattern in which attackers establish persistence, escalate privileges, and exfiltrate data before they trigger encryption. That sequencing matters because it means the visible ransomware event is often the end of a longer compromise, not the start of one. The real operational damage is frequently created earlier, when attackers identify critical systems, monitor business cycles, and position themselves to choose the moment of maximum disruption. In that model, the encryption event is a pressure tactic layered on top of prior control failure.

Practical implication: build monitoring and containment around dwell time, privilege abuse, and data movement, not only the encryption payload.

Why digital trust and crypto-agility belong in ransomware planning

Ransomware is increasingly targeting the systems that underpin trust itself, including certificates, code signing, and secure software updates. If those trust anchors are disrupted, the blast radius extends beyond data availability into software integrity and communication assurance. The article also highlights the long-term risk from quantum computing, which raises the value of crypto-agility now rather than later. For practitioners, the technical lesson is that identity and cryptography are not adjacent to ransomware defence. They are part of the trust fabric attackers are already trying to break.

Practical implication: treat certificate lifecycle, signing trust, and migration flexibility as ransomware-resilience controls.


Threat narrative

Attacker objective: The attacker’s objective is to turn legitimate access into maximum business leverage by disrupting operations, stealing data, and forcing recovery decisions under pressure.

  1. Entry occurs through compromised credentials or phishing-enabled access, giving attackers a legitimate foothold rather than forcing a loud intrusion path.
  2. Escalation follows as attackers probe identity systems, establish persistence, and map internal dependencies before showing their hand.
  3. Impact is delivered when encryption, data theft, and operational disruption are timed to business choke points and recovery pressure is highest.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Ransomware has crossed the line from malware event to identity-governed business disruption. The article shows that attackers now rely on credentials, privilege, and operational timing rather than only on payload delivery. That means identity controls are not upstream hygiene. They are the conditions that determine whether ransomware becomes contained noise or a continuity crisis. Practitioners should treat identity assurance as a core ransomware boundary, not a supporting control.

Standing access and broad trust relationships create the leverage that ransomware operators need. The problem is not only compromise, but the fact that many environments still preserve authentication paths long enough for attackers to study, abuse, and weaponise them. Identity verification gaps, overexposed third-party access, and weak segmentation let adversaries move from foothold to disruption with little friction. The practical conclusion is that leverage often comes from access structure, not from malware sophistication.

Digital trust is now part of ransomware resilience, not a separate PKI discussion. The article’s emphasis on certificates, code signing, and secure updates shows that attackers increasingly target the control plane of trust itself. That elevates certificate lifecycle governance, software integrity, and crypto-agility into the same risk conversation as backup and recovery. Practitioners should stop treating trust infrastructure as back-office plumbing and start treating it as a continuity dependency.

Compliance and resilience are not interchangeable, and ransomware keeps proving it. The article points to sectors that are highly regulated yet still absorb devastating operational impact because audit-readiness does not stop adversaries from exploiting predictable baselines. Regulation can standardise minimums, but ransomware operators profit from uniformity and from controls that exist on paper more than in recovery reality. The implication is that governance must measure operational survivability, not just policy conformity.

Identity, PKI, and recovery planning now share the same blast radius. When attackers can time disruption around claims processing, service delivery, or software trust, the security programme must understand how credentials, certificates, and fallback procedures interact under pressure. This is the identity blast radius problem: the more tightly operations depend on trusted access and cryptographic continuity, the more one compromise can cascade across the business. Practitioners should design for coupled failure, not isolated control events.

What this signals

Identity is now part of ransomware economics. When attackers can enter with valid credentials, they can spend time learning business cycles, privilege relationships, and recovery pressure points before revealing themselves. That shifts the defensive priority from blocking every payload to shrinking the value of every foothold.

Identity blast radius: ransomware campaigns succeed when one compromised account can reach multiple operational dependencies. The programme question is no longer only who can authenticate, but how far that identity can influence continuity before containment begins.

Certificate lifecycle and software trust are now continuity controls. Ransomware operators increasingly target trust anchors because compromising certificates, code signing, or update channels can extend disruption beyond a single endpoint. Teams should place those assets inside resilience planning, not treat them as separate PKI workstreams.


For practitioners

  • Tighten identity entry points Reduce the attack surface for credential-based ransomware entry by enforcing MFA coverage, eliminating stale third-party access, and reviewing privileged authentication paths that can be reused for long dwell-time attacks.
  • Map ransomware to business choke points Identify the systems whose disruption would halt claims, fulfilment, communications, or other critical workflows, then tie those dependencies to response plans and restoration priorities.
  • Add dwell-time detection to incident monitoring Look for identity probing, lateral dependency mapping, quiet data movement, and privilege escalation before encryption appears, because the visible ransomware payload is often the last step.
  • Treat trust infrastructure as continuity infrastructure Place certificates, code signing, and software update trust into resilience planning so cryptographic failure does not become an operational outage during a ransomware event.

Key takeaways

  • Ransomware now succeeds by combining identity abuse, data theft, and timed disruption, which turns access control into a continuity issue.
  • The Change Healthcare incident shows how compromised credentials and hidden dwell time can produce multi-billion-dollar business impact.
  • Identity hardening, trust infrastructure governance, and recovery readiness need to be planned together if organisations want to limit ransomware leverage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centers on compromised credentials and weak MFA as an entry path for ransomware.
NHI-05 — Overprivileged NHIAttackers escalate privileges and map dependencies after initial access, which overprivilege enables.
NHI-07 — Long-Lived SecretsPersistent access and reused credentials give attackers time to dwell before encryption starts.
Recommendation — Harden authentication paths and eliminate weak MFA gaps that let ransomware operators enter with valid access. Reduce privilege scope so a single compromised identity cannot reach business-critical systems. Shorten secret lifetime and revoke reusable access paths that support long dwell-time attacks.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential lifecycle and MFA gaps are central to the article's attack and resilience discussion.
Recommendation — Apply authenticator management to rotate, revoke, and monitor credentials that can support ransomware entry.
MITRE ATT&CKTA0006;TA0004;TA0008 — Credential Access; Privilege Escalation; Lateral MovementThe article describes credential abuse, escalation, and movement before encryption and impact.
Recommendation — Map ransomware dwell-time behaviors to credential access, escalation, and lateral movement in detection content.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article argues that access structure determines how much leverage ransomware can gain.
Recommendation — Review permissions and entitlements so compromised accounts cannot spread disruption across critical workflows.

Key terms

  • Ransomware Dwell Time: The period between initial access and visible disruption, when an attacker remains active inside an environment without triggering the main payload. In modern ransomware, this window is used to map dependencies, escalate privilege, and exfiltrate data before encryption or extortion begins.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Crypto-Agility: Crypto-agility is the ability to change cryptographic algorithms, certificates, and trust dependencies without redesigning production systems. It matters because cryptographic standards evolve, and organisations need accurate inventories and automated lifecycle controls before they can migrate safely.
  • Business Continuity: Business continuity is the capability to keep essential services operating through disruption and recover them afterward. In identity programmes, continuity depends on access control, authentication, and recovery governance remaining dependable when normal workflows are stressed or unavailable.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org