TopheadlinesTopheadlines
    What's Hot

    Najee Harris run on first drive ends Steelers’ TD drought

    November 3, 2023

    Forced to Change: Tech Giants Bow to Global Onslaught of Rules

    March 4, 2024

    Spare a thought for the man in the middle as Old Firm prepare to go head-to-head at Ibrox…and pray that he’s not all we’re talking about once the dust has settled

    February 28, 2026
    Facebook Twitter Instagram
    Trending
    • WNBA’s furious trans debate deepens as Seattle star takes bitter swipe at Sophie Cunningham… and protestors gather to support Indiana Fever icon
    • Cookies sold at major grocery store recalled over fears of life-threatening reaction
    • UNLV basketball program ‘not for sale’: Runnin’ Rebels coach Josh Pastner walks back wild claim
    • When Suzie hit her 40s, she put her thinning hair, irritability, wired brain and palpitations down to the perimenopause. Then she started to mysteriously lose weight…
    • Oil tumbles below $90 after pause in fighting between the US and Iran but experts still fear rates hike
    • Tour de France 2026: Pogacar makes history, cycling steps up anti-doping, and popularity grows
    • Trendy meat diet sparks explosion of crippling medieval disease in young people
    • Scientists find potential cause of embarrassing condition that causes excessive sweating in 15 million people… paving way for new treatments
    Facebook Twitter Instagram
    TopheadlinesTopheadlines
    • Latest News

      Inside Epstein’s Zorro Ranch ‘where paedophile looked to carry out human experiments and create super-race breeding facility’ and ‘buried girls who were strangled during sex’

      February 24, 2026

      Cheating Utah ‘grief author’ heard sobbing down phone to 911 operator after allegedly murdering husband with poisoned Moscow mule

      February 23, 2026

      Victim reveals how she was left with flesh-eating disease after GP did not see her face-to-face then fled to India

      February 23, 2026

      ‘Andrew, the prince of darkness’: Global media mark ‘the end of privilege’ for Mountbatten-Windsor and gloat that the royal is ‘at rock bottom’

      February 22, 2026

      Melania Trump stuns in silver pants as she arrives at controversial Governor’s Dinner with husband Donald as dozens threaten boycott after president’s turbulent week

      February 22, 2026
    • Politics

      Law enforcement says eight killed by avalanche in California mountains | Weather News

      February 18, 2026

      Bangladesh PM-to-be and lawmakers sworn into parliament | Sheikh Hasina

      February 17, 2026

      Hillary Clinton gets in testy exchange with European leader over Trump

      February 16, 2026

      At least 11 Palestinians killed in Israeli attacks across Gaza | Gaza News

      February 15, 2026

      DOJ sends letter to Congress with list of people named in Epstein files, including Trump: Report

      February 15, 2026
    • Tech

      Apple’s AI Wearables Expected to Lean Heavily on Visual Intelligence

      February 23, 2026

      What to Know About At-Home STI Tests: Pros, Cons, and Recommendations (2026)

      February 23, 2026

      10 Clever Home Appliance Innovations You’ll See in 2026

      February 22, 2026

      Runlayer is now offering secure OpenClaw agentic capabilities for large enterprises

      February 22, 2026

      Tesla's "cheaper" Cybertruck arrives at $59,990, still far from the $40K promise

      February 21, 2026
    • Business

      Oil tumbles below $90 after pause in fighting between the US and Iran but experts still fear rates hike

      July 27, 2026

      Chancellor urged to rule out pensions raid to stop repeat of damaging speculation under Reeves and back ‘people who do the right thing’

      July 24, 2026

      Does the risk of ruinous care bills deter YOU from spending or gifting money to beat inheritance tax?

      July 23, 2026

      This is the one step Andy Burnham could take now to make us all richer and happier – and it wouldn’t cost him a penny: RACHEL RICKARD STRAUS

      July 21, 2026

      Why will it take half a year to register our property purchase on the Land Registry and should we be concerned?

      July 17, 2026
    • Sports

      WNBA’s furious trans debate deepens as Seattle star takes bitter swipe at Sophie Cunningham… and protestors gather to support Indiana Fever icon

      July 29, 2026

      UNLV basketball program ‘not for sale’: Runnin’ Rebels coach Josh Pastner walks back wild claim

      July 28, 2026

      Tour de France 2026: Pogacar makes history, cycling steps up anti-doping, and popularity grows

      July 27, 2026

      The McCanns cheer on Madeleine’s brother Sean as he swims in Commonwealth Games nearly two decades after sister disappeared

      July 25, 2026

      Rockies vs. Brewers MLB picks: Keep riding same parlay in lone matinee Friday

      July 24, 2026
    • Health

      Cookies sold at major grocery store recalled over fears of life-threatening reaction

      July 28, 2026

      When Suzie hit her 40s, she put her thinning hair, irritability, wired brain and palpitations down to the perimenopause. Then she started to mysteriously lose weight…

      July 27, 2026

      Trendy meat diet sparks explosion of crippling medieval disease in young people

      July 26, 2026

      Scientists find potential cause of embarrassing condition that causes excessive sweating in 15 million people… paving way for new treatments

      July 25, 2026

      Trump threatens LETTUCE tariffs to control ‘explosive’ parasite outbreak as cases soar

      July 24, 2026
    • Science

      Ever wonder where our math symbols came from? Here are their stories

      February 19, 2026

      Some dog breeds carry a higher risk of breathing problems

      February 19, 2026

      New study links early smartphone ownership to health risks

      February 18, 2026

      The Story of Stories traces the arc of storytelling across human history

      February 17, 2026

      Listen to the crackle of ‘mini-lightning’ on Mars

      February 16, 2026
    • Entertainment

      Paul McCartney and Wings Exhibit Set at Rock & Roll Hall of Fame

      February 18, 2026

      Warner Bros Latest Hollywood Studio To Warn Seedance Over AI Infringement

      February 18, 2026

      Cardi B on Stefon Diggs Relationship Status

      February 17, 2026

      Jelly Roll Will Receive Country Radio’s Humanitarian Award

      February 17, 2026

      X Down For Thousands In U.S. And UK

      February 16, 2026
    TopheadlinesTopheadlines
    Home»Tech»Most ransomware playbooks don't address machine credentials. Attackers know it.
    Tech

    Most ransomware playbooks don't address machine credentials. Attackers know it.

    February 16, 20267 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Most ransomware playbooks don't address machine credentials. Attackers know it.
    Share
    Facebook Twitter LinkedIn Pinterest Email



    The gap between ransomware threats and the defenses meant to stop them is getting worse, not better. Ivanti’s 2026 State of Cybersecurity Report found that the preparedness gap widened by an average of 10 points year over year across every threat category the firm tracks. Ransomware hit the widest spread: 63% of security professionals rate it a high or critical threat, but just 30% say they are “very prepared” to defend against it. That’s a 33-point gap, up from 29 points a year ago.

    CyberArk’s 2025 Identity Security Landscape puts numbers to the problem: 82 machine identities for every human in organizations worldwide. Forty-two percent of those machine identities have privileged or sensitive access.

    The most authoritative playbook framework has the same blind spot

    Gartner’s ransomware preparation guidance, the April 2024 research note “How to Prepare for Ransomware Attacks” that enterprise security teams reference when building incident response procedures, specifically calls out the need to reset “impacted user/host credentials” during containment. The accompanying Ransomware Playbook Toolkit walks teams through four phases: containment, analysis, remediation, and recovery. The credential reset step instructs teams to ensure all affected user and device accounts are reset.

    Service accounts are absent. So are API keys, tokens, and certificates. The most widely used playbook framework in enterprise security stops at human and device credentials. The organizations following it inherit that blind spot without realizing it.

    The same research note identifies the problem without connecting it to the solution. Gartner warns that “poor identity and access management (IAM) practices” remain a primary starting point for ransomware attacks, and that previously compromised credentials are being used to gain access through initial access brokers and dark web data dumps. In the recovery section, the guidance is explicit: updating or removing compromised credentials is essential because, without that step, the attacker will regain entry. Machine identities are IAM. Compromised service accounts are credentials. But the playbook’s containment procedures address neither.

    Gartner frames the urgency in terms few other sources match: “Ransomware is unlike any other security incident,” the research note states. “It puts affected organizations on a countdown timer. Any delay in the decision-making process introduces additional risk.” The same guidance emphasizes that recovery costs can amount to 10 times the ransom itself, and that ransomware is being deployed within one day of initial access in more than 50% of engagements. The clock is already running, but the containment procedures don’t match the urgency — not when the fastest-growing class of credentials goes unaddressed.

    The readiness deficit runs deeper than any single survey

    Ivanti’s report tracks the preparedness gap across every major threat category: ransomware, phishing, software vulnerabilities, API-related vulnerabilities, supply chain attacks, and even poor encryption. Every single one widened year over year.

    “Although defenders are optimistic about the promise of AI in cybersecurity, Ivanti’s findings also show companies are falling further behind in terms of how well prepared they are to defend against a variety of threats,” said Daniel Spicer, Ivanti’s Chief Security Officer. “This is what I call the ‘Cybersecurity Readiness Deficit,’ a persistent, year-over-year widening imbalance in an organization’s ability to defend their data, people, and networks against the evolving threat landscape.”

    CrowdStrike’s 2025 State of Ransomware Survey breaks down what that deficit looks like by industry. Among manufacturers who rated themselves “very well prepared,” just 12% recovered within 24 hours, and 40% suffered significant operational disruption. Public sector organizations fared worse: 12% recovery despite 60% confidence. Across all industries, only 38% of organizations that suffered a ransomware attack fixed the specific issue that allowed attackers in. The rest invested in general security improvements without closing the actual entry point.

    Fifty-four percent of organizations said they would or probably would pay if hit by ransomware today, according to the 2026 report, despite FBI guidance against payment. That willingness to pay reflects a fundamental lack of containment alternatives, exactly the kind that machine identity procedures would provide.

    Where machine identity playbooks fall short

    Five containment steps define most ransomware response procedures today. Machine identities are missing from every one of them.

    Credential resets weren’t designed for machines

    Resetting every employee’s password after an incident is standard practice, but it doesn’t stop lateral movement through a compromised service account. Gartner’s own playbook template shows the blind spot clearly.

    The Ransomware Playbook Sample’s containment sheet lists three credential reset steps: force logout of all affected user accounts via Active Directory, force password change on all affected user accounts via Active Directory, and reset the device account via Active Directory. Three steps, all Active Directory, zero non-human credentials. No service accounts, no API keys, no tokens, no certificates. Machine credentials need their own chain of command.

    Nobody inventories machine identities before an incident

    You can’t reset credentials that you don’t know exist. Service accounts, API keys, and tokens need ownership assignments mapped pre-incident. Discovering them mid-breach costs days.

    Just 51% of organizations even have a cybersecurity exposure score, Ivanti's report found, which means nearly half couldn’t tell the board their machine identity exposure if asked tomorrow. Only 27% rate their risk exposure assessment as “excellent,” despite 64% investing in exposure management. The gap between investment and execution is where machine identities disappear.

    Network isolation doesn’t revoke trust chains

    Pulling a machine off the network doesn’t revoke the API keys it issued to downstream systems. Containment that stops at the network perimeter assumes trust is bounded by topology. Machine identities don’t respect that boundary. They authenticate across it.

    Gartner’s own research note warns that adversaries can spend days to months burrowing and gaining lateral movement within networks, harvesting credentials for persistence before deploying ransomware. During that burrowing phase, service accounts and API tokens are the credentials most easily harvested without triggering alerts. Seventy-six percent of organizations are concerned about stopping ransomware from spreading from an unmanaged host over SMB network shares, according to CrowdStrike. Security leaders need to map which systems trusted each machine identity so they can revoke access across the entire chain, not just the compromised endpoint.

    Detection logic wasn’t built for machine behavior

    Anomalous machine identity behavior doesn’t trigger alerts the way a compromised user account does. Unusual API call volumes, tokens used outside automation windows, and service accounts authenticating from new locations require detection rules that most SOCs haven’t written. CrowdStrike’s survey found 85% of security teams acknowledge traditional detection methods can’t keep pace with modern threats. Yet only 53% have implemented AI-powered threat detection. The detection logic that would catch machine identity abuse barely exists in most environments.

    Stale service accounts remain the easiest entry point

    Accounts that haven’t been rotated in years, some created by employees who left long ago, are the single weakest surface for machine-based attacks.

    Gartner’s guidance calls for strong authentication for “privileged users, such as database and infrastructure administrators and service accounts,” but that recommendation sits in the prevention section, not in the containment playbook where teams need it during an active incident. Orphan account audits and rotation schedules belong in pre-incident preparation, not post-breach scrambles.

    The economics make this urgent now

    Agentic AI will multiply the problem. Eighty-seven percent of security professionals say integrating agentic AI is a priority, and 77% report comfort with allowing autonomous AI to act without human oversight, according to the Ivanti report. But just 55% use formal guardrails. Each autonomous agent creates new machine identities, identities that authenticate, make decisions, and act independently. If organizations can’t govern the machine identities they have today, they’re about to add an order of magnitude more.

    Gartner estimates total recovery costs at 10 times the ransom itself. CrowdStrike puts the average ransomware downtime cost at $1.7 million per incident, with public sector organizations averaging $2.5 million. Paying doesn’t help. Ninety-three percent of organizations that paid had data stolen anyway, and 83% were attacked again. Nearly 40% could not fully restore data from backups after ransomware incidents. The ransomware economy has professionalized to the point where adversary groups now encrypt files remotely over SMB network shares from unmanaged systems, never transferring the ransomware binary to a managed endpoint.

    Security leaders who build machine identity inventory, detection rules, and containment procedures into their playbooks now won’t just close the gap that attackers are exploiting today — they’ll be positioned to govern the autonomous identities arriving next. The test is whether those additions survive the next tabletop exercise. If they don’t hold up there, they won’t hold up in a real incident.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

    Related Posts

    Apple’s AI Wearables Expected to Lean Heavily on Visual Intelligence

    February 23, 2026

    What to Know About At-Home STI Tests: Pros, Cons, and Recommendations (2026)

    February 23, 2026

    10 Clever Home Appliance Innovations You’ll See in 2026

    February 22, 2026
    Top Posts

    WNBA’s furious trans debate deepens as Seattle star takes bitter swipe at Sophie Cunningham… and protestors gather to support Indiana Fever icon

    July 29, 2026

    Francis Ngannou claims he is Man United’s ‘favourite heavyweight boxer’ as he teases Tyson Fury

    July 31, 2023

    Turn Your Favorite Pet Photos Into a Pawfect Portrait for Just $20

    July 31, 2023

    Mauricio Diazgranados Is a Botanist in a Hurry

    July 31, 2023
    Don't Miss
    Politics

    The surprising reason Bill Shorten desperately NEEDS a new job after a lifetime in Labor politics – as he lands a bumper $1m-plus pay packet

    Politics 5 Mins Read

    Former Labor leader Bill Shorten will not receive a pension when he leaves politics for…

    Why Geelong Cats have been kicked out of their home ground for Superman star this weekend

    May 2, 2025

    Teal candidate Erchana Murray-Bartlett in McPherson caught ‘showing her true colours’ by encouraging people to vote Green

    November 15, 2025

    Adam Neumann Wants to Take Over WeWork

    February 7, 2024
    Stay In Touch
    • Facebook
    • Twitter
    • Instagram
    About Us
    About Us

    Delivering timely and accurate news updates, our website keeps you informed on the latest events, politics, entertainment, and more. Dive into captivating articles crafted by our team of expert writers, providing a comprehensive view of the world. Stay ahead with our trusted news source.

    Facebook Twitter Instagram
    Our Picks

    Ludwig the psychic sausage dog backs GERMANY to beat Scotland in Euro 2024 opener and predicts Portugal will be overall winner as he follows in the footsteps of Paul the octopus

    June 16, 2024

    Qwen3-Coder-Next offers vibe coders a powerful open source, ultra-sparse model with 10x higher throughput for repo tasks

    February 4, 2026

    From pixels to pop culture

    December 10, 2023
    © 2026 Designed by TopHeadlineSpot.
    • Business
    • Latest News
    • Politics
    • Health
    • Entertainment
    • Sports
    • Science
    • Tech

    Type above and press Enter to search. Press Esc to cancel.