Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Ransomware encryption in under 30 minutes: are SOC controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Ransomware can now complete the full attack chain, from initial access to encryption, in under 30 minutes, with median encryption time at 42 minutes and some strains finishing in under 4 minutes, according to Torq and IDC. Manual SOC response is no longer fast enough, and containment speed now matters more than detection alone.

NHIMG editorial — based on content published by torq: ransomware protection and autonomous response workflows

By the numbers:

Questions worth separating out

Q: What breaks when ransomware response still depends on manual triage?

A: Manual triage breaks when the attack completes faster than analysts can validate signals, decide containment, and execute actions.

Q: Why do identity-centric controls matter for ransomware and insider risk?

A: They matter because ransomware and insider abuse often succeed after an identity is already trusted.

Q: How do teams know if layered ransomware defence is actually working?

A: Layered defence is working when suspicious identity activity is detected early, privileged access is revoked quickly, and lateral movement attempts are blocked before critical systems are reached.

Practitioner guidance

  • Implement machine-speed containment workflows Pre-authorise response paths that can isolate endpoints, disable accounts, and segment network access once alerts are validated, so the SOC does not depend on manual handoffs.
  • Tie ransomware containment to identity state Make privileged users, service accounts, and active sessions part of the first triage step so account revocation can happen alongside endpoint isolation when the blast radius is still small.
  • Test backup readiness inside the response workflow Verify backup status automatically during incident handling, not after containment is complete, so recovery options are known before encryption has time to spread.

What's in the full article

Torq's full article covers the operational detail this post intentionally leaves for the source:

  • Detailed workflow examples for connecting EDR, SIEM, IAM, and backup tools into one response chain
  • Specific containment steps used for phishing, behavioural detection, and ransomware remediation
  • Implementation guidance for measuring automation rate, analyst time saved, and mean time to contain
  • Examples of how autonomous remediation is applied across Tier-1 security cases

👉 Read Torq's analysis of ransomware response automation and SOC containment speed →

Ransomware encryption in under 30 minutes: are SOC controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Ransomware response time has become a governance issue, not just a SOC metric. If encryption can happen in minutes, then the old assumption that analysts will inspect, deliberate, and respond in sequence no longer holds. Security leaders have to treat containment automation as a control requirement for modern operations, especially where identity and endpoint actions must be coordinated. The practical conclusion is that mean time to contain matters more than alert volume alone.

A question worth separating out:

Q: What should teams do immediately after discovering ransomware access?

A: Contain the identity path before focusing on payload cleanup. Disable exposed credentials, revoke active sessions, isolate privileged accounts, and protect backup and security-tool access so the attacker cannot continue moving or block recovery. The urgent goal is to stop further use of legitimate access.

👉 Read our full editorial: Ransomware response speed is now the decisive SOC control



   
ReplyQuote
Share: