Microsoft's deputy chief information security officer argues that briefings starting at the moment files are locked miss weeks of earlier activity.
What happened
Ransomware briefings delivered to boards typically begin at the point where files get encrypted, by which stage the attack is already in its final phase, according to Terrell Cox, deputy chief information security officer in Microsoft's Customer Security Management Office. The attacker likely bought access to the network weeks earlier, harvested credentials, and moved between systems quietly. Cox argues that boards hearing only about the encryption event will fund recovery, since that is the part they were shown, and that recovery spending leaves the attacker's costs untouched. Organizations getting ahead of the problem, in his account, spend on interrupting the sequence before damage occurs.
Going deeper
Sophisticated attacks no longer require sophisticated attackers, which is the argument Cox puts at the center of the board conversation. Access to a compromised network can be purchased outright. Phishing kits are sold by subscription in the same way streaming services are. Services exist to make malicious software appear legitimate, and AI has reduced the cost of reconnaissance and impersonation at every stage. Cox proposes three points for security leaders to make. Ransomware is operational, financial, reputational, and continuity risk occurring together, which is a category boards already handle for supply chain and market exposure. Attacker economics have changed and defensive economics have to follow. Recovery capability is a strategic investment rather than a compliance exercise, and the measure that matters is the interval between the initial compromise and containment rather than how quickly systems come back.
What was said
"Boards already understand supply-chain and market risk. Ransomware is no different," Cox wrote, arguing that once boards see it that way the question changes from recovering faster to reducing exposure before disruption occurs. He put the accountability gap directly: "CISOs are being held personally accountable for risks their boards do not yet have the data to evaluate. Closing that gap is one of the most important things a security leader can do."
In the know
Microsoft's Digital Crimes Unit disrupted an operation in May that shows what shared criminal infrastructure looks like. Fox Tempest sold a malware-signing service, taking customers' malicious files and returning them carrying code-signing certificates, the digital credentials Windows checks to confirm software comes from a known publisher and has not been altered. Operators used stolen US and Canadian identities to pass identity verification, then generated certificates valid for only 72 hours so that revocation would not catch up before the files had spread. Signed files impersonated Microsoft Teams, AnyDesk, PuTTY, and Webex installers, and reached victims mainly through advertisements and manipulated search rankings. Microsoft removed more than 1,000 certificates and seized the service's website, according to its own account. Customers included the Rhysida, Akira, INC, Qilin, and BlackByte ransomware operations, several of which have attacked hospitals.
The big picture
Boards asking what to fund have a published list to work from. The Healthcare and Public Health Cybersecurity Performance Goals, published by HHS, separate goals covering baseline practices from enhanced goals covering more advanced ones, and were built to address the attack methods identified in a federal analysis of hospital cyber resilience. They also map onto what Cox describes, since the list covers training, email security, and removing credentials when staff leave, all of which sit at the entry stage rather than the recovery stage. A hospital board reviewing its position could reasonably ask which goals the organization has met, how long the last intrusion went undetected, and whether recovery procedures have been tested rather than written.
FAQs
What is an initial access broker?
A criminal who breaks into networks and sells that access to others rather than attacking the organization directly. Ransomware operators buy access instead of finding it, which is why the intrusion often predates the encryption by weeks.
Why does a code-signing certificate matter to Windows?
Windows and security software treat a valid signature as evidence that a file comes from a known publisher and has not been tampered with. Malware carrying a fraudulent but technically valid certificate passes checks that would otherwise flag it, and users see a familiar publisher name.
What does measuring time to containment involve?
Establishing when an attacker first gained access, which usually emerges only during forensic review, and when they were removed. It differs from recovery time, which measures how long systems were unavailable, and it reflects how long an intruder had to move through the network.
What are immutable backups?
Copies of data that cannot be altered or deleted for a set period, even by an administrator account. Attackers routinely target backups before encrypting, and immutability prevents a compromised administrator credential from destroying the recovery option.
How should a board judge whether recovery planning is adequate?
By asking whether a full restoration has been performed as an exercise, how long it took, and what failed during it. Plans that have never been executed under time pressure regularly fail at the point they are needed.
