Back

Ransomware Guidance Urges Boards To Address Full Attack Chain

At a glance

  • Microsoft Security Insider published new ransomware guidance on June 3, 2026.
  • Ransomware-as-a-service enables attackers to buy access and tools.
  • In 2025, extortion or ransomware drove over half of cyberattacks investigated by Microsoft.

Strategic guidance on ransomware was published by Microsoft Security Insider on June 3, 2026, focusing on board-level discussions and the evolving threat landscape. The article addresses how organizations approach ransomware risks and the importance of understanding the full attack process.

The publication highlights that many board conversations about ransomware concentrate on the moment files are encrypted, rather than considering earlier stages such as how attackers gain entry and move within networks. This approach may overlook critical points where defenses can be strengthened before an attack escalates.

According to the article, the ransomware threat has developed into a complex criminal ecosystem. Attackers can now purchase initial access to networks, subscribe to phishing services, and use malware-signing tools that help their software appear legitimate to security systems.

Microsoft has been monitoring and reporting on the ransomware-as-a-service (RaaS) model since 2020. This model allows malware developers to sell their tools to affiliates, who then carry out attacks, making it easier for a wider range of actors to participate in ransomware campaigns.

What the numbers show

  • Over 50% of cyberattacks with known motives in 2025 investigated by Microsoft were linked to extortion or ransomware.
  • Microsoft Security Insider published ransomware board guidance on June 3, 2026.
  • Microsoft has tracked the ransomware-as-a-service ecosystem since 2020.

Initial access brokers play a key role in the ransomware-as-a-service economy by selling network access to attackers. This service reduces the technical barriers for those seeking to launch ransomware attacks, allowing them to focus on other parts of the attack chain.

The article also notes that phishing-as-a-service is available by subscription, further lowering the entry point for cybercriminals. Malware-signing services are used to make malicious code appear trustworthy, complicating detection efforts for organizations.

Microsoft’s security teams have observed that extortion and ransomware are leading motives behind cyberattacks with known intent. This trend is documented in the Microsoft Digital Defense Report 2025, which states that these types of attacks accounted for the majority of cases investigated during the year.

Ransomware-as-a-service continues to shape the threat landscape, with various actors providing specialized services to facilitate attacks. The guidance published by Microsoft Security Insider encourages organizations to broaden their focus beyond the encryption stage and address vulnerabilities throughout the entire attack lifecycle.

* This article is based on publicly available information at the time of writing.