The field · 7 min read

Ransomware in 2026: what defenders changed

The attackers got faster and the headlines got louder. The interesting story is quieter: the specific things defenders changed this year, and why they held.

When did your organisation last rehearse the first hour of a ransomware incident, with the right people in the room and the laptops switched off? That single question separates the teams who had a bad week in 2026 from the teams who had a bad year. The technology mattered less than most boards assumed. The preparation mattered more.

The pattern reported across the field this year is consistent. Verizon's Data Breach Investigations Report and ENISA's threat landscape work both describe ransomware that arrives faster, leans harder on stolen credentials, and treats data theft as the real source of pressure. The UK's NCSC says much the same in its guidance. None of that is a surprise to the analysts living it. What changed is how those analysts responded, and the changes were practical rather than dramatic.

The attack got faster, so the first hour got rehearsed

The window between initial access and encryption has been shrinking for several years, and 2026 continued the trend. When intruders can move from a phished credential to domain-wide impact inside a working day, a containment plan that lives in a PDF is worthless. So the teams who fared well stopped treating the runbook as a document and started treating it as a drill.

That meant tabletop exercises that ran on a Tuesday afternoon, not once a year for the auditor. It meant agreeing in advance who can pull a network segment offline without waiting for a director to wake up. A SOC analyst on a night shift should not have to find a phone number before they can act. The change was cultural before it was technical, and it cost very little.

Identity became the thing worth defending first

The reports agree on where the doors are. Stolen and reused credentials, valid accounts, and unmanaged remote access remain the most common ways in. So defenders moved their attention to identity ahead of almost everything else. Phishing-resistant multi-factor authentication went from a roadmap item to a baseline. Standing administrative access got cut back to time-boxed, approved sessions. Service accounts, long the quiet weak point, got inventoried and rotated.

This is unglamorous work. Nobody writes a press release about retiring a legacy VPN or removing a domain admin who left two years ago. The people who did it this year are the reason several incidents stopped at one compromised host instead of spreading to the estate.

The blast radius moved to suppliers, so defenders looked outward

A growing share of the incidents described this year did not start inside the victim at all. They started with a supplier, a managed service provider, or a piece of widely deployed software. ENISA and the NCSC have both flagged this widening blast radius, where one compromise reaches many organisations through a trusted connection. A defender can run a tidy estate and still inherit someone else's bad day.

So the better-prepared teams looked outward. They mapped which third parties hold the keys to their systems, asked harder questions about how those partners segment and monitor their own access, and rehearsed what happens when the call comes from a vendor rather than an internal alert. Treating a supplier breach as a likely scenario, rather than an unlucky one, was the change that made the difference.

Extortion moved past encryption, so recovery changed shape

For years the recovery question was straightforward. Restore from backup and refuse to pay. Attackers adapted. The pressure in 2026 comes from data theft. Files are copied out before anything is locked, and the threat is publication. A clean backup answers the encryption problem, but it does nothing about a leak site.

Defenders responded by changing what recovery means. Backups got pulled out of the production identity boundary, so that an attacker holding domain admin could not also delete the recovery copies. Restore drills got timed, because an untested backup is a hope, not a control. Legal, communications, and data protection colleagues got pulled into the planning early, because the decisions in a data-theft incident are no longer purely technical. The defenders who did this were calm in the room when it mattered, and calm is a skill that is built in advance.

The quiet work is what kept incidents off the front page

The defining feature of a good 2026 was an absence. No leak site listing. No customers reading about it in the news. No board meeting that started with an apology. Those non-events are the product of work nobody sees: the analyst who noticed an odd login at the right moment, the engineer who had already segmented the network, the responder who shortened the time an intruder spent inside before anyone else knew there was a problem.

This is the work that recognition exists to name. A breach that never happens makes no headline, and a team that holds together through a bad night gets no press. Across a decade of the Hall of Fame, the names that have lasted are the ones whose work held under scrutiny, not the ones who shouted loudest. The lesson of ransomware in 2026 is the same lesson the field keeps relearning. The defenders who prepare, quietly and in advance, are the ones still standing when the year is over.

FAQ

Ransomware in 2026

Are ransomware attacks faster in 2026?

Yes. The window between initial access and impact has continued to shrink, and the Verizon DBIR, ENISA, and the NCSC all describe attackers reaching encryption or data theft within hours when they use stolen credentials. This is why defenders moved to rehearsed, fast containment rather than relying on a written plan alone.

Is paying the ransom still the main risk?

The pressure has shifted. Double extortion, where data is stolen and threatened with publication, is now the default. A clean backup solves the encryption problem but not the leak, so recovery planning in 2026 brings in legal, communications, and data protection colleagues from the start.

What single change helps most against ransomware?

Prioritising identity. Phishing-resistant multi-factor authentication, removing standing administrative access, and cleaning up service accounts close the most common routes in. These are not new ideas, but the teams who actually did the work in 2026 contained incidents that would otherwise have spread.

How should backups be protected against ransomware?

Keep recovery copies outside the production identity boundary so an attacker with domain admin cannot delete them, and test restores on a timed drill. An untested backup is a hope rather than a control, and recovery plans should assume credentials are already compromised.