Behind the Breach: How Ransomware Gets In
In the second of our of State of Ransomware series with Sophos, Brian Sibley, VCTO at Espria and Jon Hope, Cyber Security Evangelist at Sophos talk about what goes on behind the breach and how ransomware gets in.
In this episode the team explore the major technical and operational root causes that lead to ransomware incidents in the UK, why exploited vulnerabilities are the leading technical cause and what preventative strategies you can put in place. Don’t let your business become a statistic in the next State of Ransomware report.
This podcast episode delves into ransomware, exploring how it infiltrates organisations, its root causes, and the defence strategies for prevention. The discussion highlights the complexity of ransomware attacks, emphasising both technological vulnerabilities and human factors.
Ransomware attacks stem from multiple factors, with the most common cause being exploited vulnerabilities in software, accounting for approximately 32% of successful attacks. These vulnerabilities arise from known software flaws that cybercriminals exploit, often due to inadequate or delayed patching by organisations, influenced by limitations in resources and skills.
Human factors also play a significant role. Compromised credentials, often a result of social engineering tactics like fake help desk calls or fraudulent websites, represent another major vector. These attacks are difficult to detect because stolen credentials enable cybercriminals to log in legitimately, making the intrusion hard to distinguish from genuine user activity.
Phishing and malicious emails further contribute to ransomware entry points. These require user interaction and are becoming increasingly sophisticated due to the use of artificial intelligence (AI) by attackers. AI enables cybercriminals to craft convincing emails that mimic trusted brands, using appropriate language and branding to deceive recipients.
Despite awareness, organisations often struggle with vulnerability management due to operational challenges such as a lack of skilled personnel, insufficient time, and security gaps. Ransomware attacks can also expose previously unrecognised weaknesses within an organisation’s security posture.
Detection technologies face difficulties, particularly with attacks involving stolen credentials and sophisticated phishing. Logs generated by network devices contain valuable information about attack chains, including unauthorised access, lateral movement, data exfiltration, and file encryption. However, interpreting these logs requires skilled threat hunters and continuous monitoring, which many organisations lack due to resource constraints.
Platforms like Extended Detection and Response (XDR) and Security Information and Event Management (SIEM) systems help consolidate logs for analysis, but human expertise remains crucial to identify and respond to threats effectively. Managed Detection and Response (MDR) services offer a practical solution by providing round-the-clock monitoring and expert analysis without requiring organisations to hire full-time specialists.
The discussion underscores the value of human-led threat hunting combined with integrated security tools that provide a holistic view of an organisation’s security posture. Effective protection relies not only on endpoint security but also on data from various sources, including email systems and backup solutions.
Recovery planning, visibility into the IT estate, and early warning systems are critical components of a resilient cybersecurity strategy. Organisations should strive to detect and stop attacks before damage occurs, as recovery, while improving, is a last resort.
This podcast episode offers a comprehensive overview of ransomware infiltration methods, highlighting the interplay of technological vulnerabilities and human factors. It stresses the need for timely patching, user education, advanced detection technologies and human expertise in threat hunting.
You may be interested in
Why the Sophos–Microsoft Partnership Matters – Especially for Education, Financial Services and Legal Organisations
For most organisations today, Microsoft is the foundation of how you operate and on top of this there is also a requirement for regulatory compliance and operational resilience. Whether it’s Microsoft 365 for collaboration, Teams for communication, or Azure for infrastructure, these platforms sit at the heart of day-to-day business. But for sectors like Education, Financial Services, and Legal, that reliance comes with heightened risk, and responsibility. These organisations are not only prime targets for cyber attackers, they are also subject to strict regulatory, data protection and governance obligations. That’s why the partnership between Sophos…
Microsoft 365 E7: The Frontier Suite – What’s Changing, Why It Matters and How to Prepare
Microsoft has officially announced Microsoft 365 E7: The Frontier Suite, marking a major leap forward in enterprise productivity, automation and AI. With general availability for both Microsoft 365 E7 and Microsoft Agent 365 set for May 1, 2026, business leaders now have the clarity needed to plan their next move. What’s what: Microsoft 365 E7 is the new top-tier enterprise suite and Microsoft Agent 365 is a key AI-powered component within the E7 offering – not a rebrand, but a major capability addition. What’s Now Official Confirmed features Why This Matters Microsoft 365 E7: The Frontier Suite isn’t just a new…
Cyber Insurance is the New Compliance
Cyber Insurance Is Now Compliance; But UK Businesses Aren’t Ready As cyber threats surge and insurance requirements harden, cyber insurance has shifted from a safety net to a core component of business compliance. Yet many UK SMEs remain dangerously unprepared for the rising expectations of modern underwriters, risking denied claims, unaffordable premiums and serious operational fallout. Cyber Insurance is the New Compliance | RSS.com Cyber Insurers Are Becoming De Facto Regulators The traditional view of cyber insurance as paperwork is now obsolete. Insurers are no longer accepting self‑declared cybersecurity maturity, they require verifiable proof of…
Why Cyber Resilience Can’t Be Audited Once a Year: Lessons from the UK Cyber Action Plan
Moving from box‑ticking compliance to real‑world cyber readiness Written by Richard Puckey Cyber security has a confidence problem For years, many organisations have taken comfort in annual cyber audits, certifications and compliance checklists. Pass the audit, tick the box and move on. On paper, everything looks secure. The problem? Cyber threats don’t operate on an annual cycle. The UK’s Cyber Action Plan is a clear signal that this approach is no longer enough. It challenges businesses to rethink cyber security not as a periodic compliance exercise, but as a living, breathing capability and culture that must stand up…
Unchecked Microsoft 365 Accounts could Become the Next Business Security Crisis, says Espria
Ensuring licenses are regularly reviewed, right sized and aligned with actual usage will keep costs under control even as prices rise. The UK’s new Cyber Security & Resilience Bill is set to bring businesses, not just MSPs, under stricter regulatory control, including tighter rules around resilience planning, faster reporting of cyber incidents, and stricter expectations for maintaining secure systems. The Cyber Security & Resilience Bill increases pressure on organisations to tighten identity governance and reduce avoidable attack surfaces. This directly impacts Microsoft 365 environments, where dormant or “zombie” accounts become a material compliance and security…
Why Enablement, Speed and Hybrid Visibility Will Separate the Best MSPs From the Rest
Espria CEO Angelo Di Ventura outlines what will define success in managed security over the next 18 months. Fresh from his recent appointment as CEO of Espria, Angelo Di Ventura has shared his perspective on how the Managed Service Provider landscape is set to evolve over the next 18 months, with enablement, speed and hybrid visibility emerging as the defining characteristics of the most successful providers. According to Di Ventura, the providers that will stand out will not be those that simply add more tools or services, but those that deliver consistency, clarity and confidence…





