How Does Ransomware Actually Get In? The Six Documented Routes, and What They Mean for a Santa Clarita Practice
Ask anyone in a Valencia office how ransomware gets into a business and you will get one answer: somebody clicked something. It is the answer the training gives, it is the answer the posters give, and it is correct about one of the six routes the federal government actually documents.
The other five do not involve anybody clicking anything. Two of them do not involve a file at all. And the guide that lists them says something about the note on the screen that almost no practice has been told, which is that by the time you are reading it, it is usually the end of the story rather than the beginning.
Overview
The document worth reading here is the #StopRansomware Guide, written jointly by CISA, the FBI, the NSA and the Multi-State Information Sharing and Analysis Center, and maintained through the Joint Ransomware Task Force. It is free, it is public, and it is not written to sell anything, which already distinguishes it from most of what a practice owner reads on this subject.
The structural choice in it is the useful part. Rather than organizing prevention around the ransomware, the guide groups best practices by initial access vector, meaning the route in. There are six, and listing them is most of the value: internet facing vulnerabilities and misconfigurations, compromised credentials, phishing, precursor malware infection, advanced forms of social engineering, and third parties including managed service providers.
Set that against how a small practice usually spends its security attention and the gap is obvious. Nearly all of it goes to the third item. That is not wasted, but it means five routes are being addressed by hope, and the exposed remote desktop service does not care how good your training is.
The Challenge
One: internet facing vulnerabilities and misconfigurations. The guide's instruction is blunt. Do not expose services such as remote desktop protocol on the web, and if they must be exposed, apply compensating controls, with unnecessary applications and protocols disabled on internet facing assets. It also calls for regular vulnerability scanning. This is the route that owes nothing to human behavior: a forgotten remote access port opened years ago for one person's convenience, or a firewall running firmware from two owners ago, is found by automated scanning rather than by anyone choosing your practice.
Two: compromised credentials. The guide asks for phishing resistant multi factor authentication across all services, naming email, VPNs and accounts reaching critical systems, and it says something practices should notice: escalate to senior management when you find systems that do not allow it, systems that do not enforce it, and users not enrolled. A valid login is not an intrusion that anything flags. It looks exactly like work, which is the problem our piece on why MFA alone is no longer enough picks up where this one stops.
Three: phishing. The familiar one, and the guide's recommendations are unglamorous: an awareness program that teaches people how to report rather than only how to spot, external email flagging turned on in the mail client, and filtering at the gateway. Worth remembering that the spotting half has got much harder, which is the subject of our piece on what AI did to the phishing tells, and is exactly why reporting and filtering carry more weight than they used to.
Four: precursor malware infection, and this is the one to read twice. The guide recommends centrally managed antivirus precisely because it can detect precursor malware as well as ransomware, then states the thing nobody tells a small office, and this sentence is worth reading in the original: a ransomware infection may be evidence of a previous, unresolved network compromise, many ransomware infections are the result of existing infections by families such as QakBot, Bumblebee and Emotet, and in some cases ransomware deployment is the last step in a compromise, dropped to obscure earlier activity such as business email compromise. Restore the files, miss the tenant that was quietly being read for the previous two months.
Five: advanced forms of social engineering. Search engine optimization poisoning, where criminals push malicious sites up the results for ordinary searches, and drive by downloads from imposter websites that look like the thing you meant to download. Nobody was tricked by an email here. Somebody searched for a printer driver or a tax form on a Tuesday. The guide's answers are training that includes recognizing illegitimate sites and search results, and protective DNS, which blocks the bad destination at the resolver rather than relying on the person.
Six: third parties and managed service providers. The guide's own words are that MSPs have been an infection vector for ransomware impacting numerous client organizations, that criminals may target an MSP in order to reach its clients, and that they may use the identity or the compromised email of an organization you trust in order to phish you. It also tells you to use contract language to formalize your security requirements, and to confirm that a third party holding your backups follows the same practices. This is the route that is hardest for a practice to inspect, since the provider is the one who would be doing the inspecting, which is where third party vendor risk leaves off and where next week's piece starts. The companion advisory on malicious use of remote monitoring software is where that one begins.
Why It Matters
Five of the six are closed by configuration, not vigilance. Exposed services, missing multi factor authentication, unmanaged endpoint protection, no protective DNS, and unexamined vendor access are all decisions somebody makes once and then lives with. That is good news, because configuration holds on a bad Monday and vigilance does not.
The encryption being the last step changes what a response has to do. A practice that restores from backup and reopens has addressed the symptom while leaving the access that produced it, which is how an organization is hit twice by the same route. The distinction between a backup and a recovery is the substance of our piece on backup versus recovery, and the part that is specific to a regulated office, where one incident becomes several parallel processes on deadlines you do not control, is in our piece on ransomware in a regulated practice.
It also tells you what to ask after an incident. Not only how do we get the files back, but how did they get in, when did it start, and what else did they touch. A provider who cannot answer those three questions has restored a practice without closing anything, and in Saugus or Canyon Country that distinction will not surface until it happens again.
What Organizations Should Watch For
- Anything reachable from the internet that nobody deliberately published. Remote desktop, a camera system, an old VPN appliance, a server someone opened a port for during the pandemic and nobody closed.
- Accounts without multi factor authentication, especially email. The guide treats the discovery of systems that cannot enforce it as something to escalate, not something to note.
- Antivirus installed machine by machine with no central console. If a warning appears and nobody is notified, the detection did not happen in any sense that matters.
- No filtering at the DNS layer. This is the control that catches the poisoned search result and the imposter download site, and most small practices do not have it.
- Vendors with standing access and no contract language about security. The guide asks for both the assessment and the paper, and most practices have neither for the companies inside their network.
- A past incident that was cleaned up rather than investigated. If a machine was once reimaged because it was acting strangely and nobody established why, that is an unresolved compromise in the guide's language.
Recommended Actions
- Find out what of yours answers from the internet. An external scan of your own address is a short job and it routinely surprises the practice that commissions it.
- Put multi factor authentication on email first, then remote access, then the practice management system. Credentials are a documented route in their own right, and email is where the rest of the damage is coordinated from.
- Centralize endpoint protection so alerts reach a person. The guide pairs this with application allowlisting or endpoint detection and response on all assets so only authorized software runs.
- Turn on protective DNS. It is inexpensive, it covers the staff laptop working from home, and it addresses the one route where the person did nothing wrong at all.
- Ask your vendors the backup question in writing. If a third party maintains or stores your backups, confirm what they do to protect them and put your requirements in the contract rather than in an email thread.
- Treat any strange machine as a question rather than a chore. Reimaging without finding out what happened is how the precursor survives into the following quarter.
The SecureLynx Perspective
Observe:
What we find in medical practices, accounting firms and law offices across the Santa Clarita Valley is a security posture shaped almost entirely around route three. Training is done, the phishing posters are up, and everybody can describe a suspicious email. Meanwhile something is usually listening on the internet that nobody remembers publishing, endpoint protection reports to nobody, and there is no filtering between a staff laptop and whatever a search result offers it. The first pass is a look from outside the building, and it takes an afternoon.
Adapt:
Then the work follows the list rather than the fashion. Close or properly control what faces the internet and keep it patched, which is ordinary systems and network administration. Get multi factor authentication onto email and remote access, centralize endpoint detection so alerts reach somebody, add DNS filtering, and write the vendor requirements down where they are enforceable. Then make sure a restore has actually been performed rather than described, which is the substance of continuity and recovery planning and the difference between an outage and a closure.
Protect:
Two honest things. None of this makes a practice immune, and anybody who tells you otherwise is selling. Five of these six routes can be narrowed considerably by decisions you make once, and the sixth is the subject of next week's piece, because the hardest route for any practice to examine is the standing access its own IT provider holds, and we would rather answer that question about ourselves in public than wait to be asked. The guide behind this piece is free and worth the hour for any owner who wants to read the source rather than our summary of it. Our pricing is published and the agreements are readable before you ever call.
Common questions
How does ransomware get into a small business?
The joint federal guide groups the answer into six initial access vectors, and prevention is organized around them rather than around the ransomware itself. They are internet facing vulnerabilities and misconfigurations, compromised credentials, phishing, a precursor malware infection, advanced forms of social engineering such as search result poisoning and imposter websites, and third parties including managed service providers. Most offices picture only the third one. The practical consequence is that awareness training, which addresses phishing, leaves five other routes open, and several of those have nothing to do with whether a staff member is careful. The exposed remote desktop service and the unpatched firewall do not care how well trained anyone is.
Can antivirus stop ransomware?
It helps, and it is not sufficient on its own. The guide recommends a centrally managed antivirus solution specifically because it can detect precursor malware as well as ransomware, and it recommends application allowlisting or endpoint detection and response on all assets so that only authorized software can execute. The reason central management matters is that scattered individual installations produce no view of the whole, so a warning on one machine is seen by nobody. The larger reason antivirus alone falls short is that several of the six routes do not involve a malicious file at all: stolen credentials used to log in look like a login, and an attacker using legitimate remote access software is using software your antivirus has no reason to object to.
Is a ransomware infection the start of the problem or the end of it?
Usually it is late in the story, and this is the single most useful thing in the federal guide for a small practice. It states that a ransomware infection may be evidence of a previous, unresolved network compromise, that many ransomware infections result from existing malware infections, and that in some cases ransomware deployment is the last step in a compromise and is dropped to obscure earlier post compromise activity such as business email compromise. The practical implication changes how a practice should respond. Restoring from backup and moving on addresses the encryption while leaving whatever preceded it in place, which is how an organization gets hit a second time by the same access that was never closed.