Building a strong defence: A guide to ransomware resilience

Building a strong defence: A guide to ransomware resilience

Ben Lister, Head of Threat Research at NetSPI, explores how organisations can use Breach and Attack Simulation to build robust defences and outsmart ransomware threats.

Ransomware remains one of the most disruptive threats facing UK businesses. Recent breaches at Marks & Spencer, Adidas, and Co-op, underscore just how disruptive and opportunistic these threats can be. In the case of Marks & Spencer, the fallout has been severe: an estimated £300 million loss in operating profit, more than £1 billion wiped from its market value and online trading halted for seven weeks. Beyond financial losses, the exposure of customer data inflicted immeasurable reputational harm.

Ben Lister, Head of Threat Research at NetSPI

What is particularly striking is that these attacks haven’t relied on advanced techniques. Marks & Spencer revealed that its breach was likely the result of human error involving social engineering tactics via a third-party supplier. This is a stark reminder that cybercriminals still often exploit the simplest vulnerabilities. It takes just one weak link for attackers to gain entry.

Faced with this reality, security leaders must shift from reactive response to proactive detection. Breach and Attack Simulation (BAS) is a critical tool for proactive defence because it continuously tests security controls against the same basic tactics that ransomware actors use, identifying weaknesses before attackers can exploit them.

Why ransomware attacks are on the rise

The surge in ransomware attacks is not limited to high-profile incidents. The 2025 Cyber Security Breaches Survey paints a concerning picture: ransomware attacks doubled between 2024 and 2025.

A key driver is the Ransomware-as-a-Service (RaaS) model which allows low-skilled actors to deploy ransomware kits. Groups like DragonForce offer ransomware kits to malicious actors in exchange for a share of the profits. The attack chain is usually simple. Gain initial access through phishing, credential compromise, or unpatched systems; move laterally; encrypt data; and demand a ransom. 

Despite popular belief, AI is not the main driver of this growth. While AI has begun to shape the threat landscape – used to craft more convincing phishing emails or automate attack workflows – its most advanced applications remain on the horizon. For now, most ransomware operators stick to tried-and-tested methods because they are faster and more profitable.

Why BAS outperforms traditional testing

Penetration testing and red teaming remain critical for assessing defences against targeted, complex threats like APTs or insider compromise. However, ransomware actors don’t typically operate with stealth or sophistication – they exploit routine missteps.

These kinds of operational gaps often fall outside the scope of traditional testing, especially when exercises are run only once or twice a year. The risk? A misconfiguration introduced post-assessment could sit undetected for months – long enough for an attacker to exploit it.

BAS addresses this blind spot by running continuously. It safely simulates real-world attack techniques across the kill chain, exposing weak spots as they emerge. For CISOs, this means fewer surprises and faster remediation, with security controls tested against the actual tactics’ ransomware actors are using today.

By integrating BAS into the defensive stack, organisations shift from point-in-time confidence to ongoing assurance that their environment is resilient, responsive, and ready.

Maximising the impact of BAS

While BAS is a powerful addition to the defensive stack, it works best when organisations understand its scope and use it in conjunction with other security measures. BAS is designed to simulate known attack techniques and behaviours at scale, making it ideal for validating existing controls and surfacing misconfigurations. However, like any tool, its effectiveness depends on how it’s implemented and integrated.

BAS isn’t designed to replace human-led exercises such as red teaming; it complements these efforts by running continuously in the background, providing real-time insights between manual assessments and helping teams maintain a high level of readiness.

To get the most out of BAS, tuning and prioritisation are essential. Well-configured BAS platforms help teams focus on what matters most, reducing noise and enabling faster remediation of genuinely impactful findings. 

As BAS technology evolves, its breadth of simulations and ease of integration are expanding rapidly. The value lies not just in what it tests today, but in how it enables teams to build a more agile, responsive approach to continuous control validation.

Resilience requires a mindset shift 

When it comes to ransomware prevention, it is about having the right tools at every level. Most ransomware actors follow well-worn playbooks, enabled by the rise of RaaS, which lowers the barrier to entry and makes attacks more frequent, not necessarily more advanced. This means that the basics are more important than ever – including tested backups, endpoint visibility, staff training, and detection of the common tactics used by ransomware actors, all of which should be foundational.

True resilience comes from shifting the organisational mindset, from reactive fixes to proactive simulation. That means proactively simulating attacker behaviour, routinely testing recovery processes, and understanding how and where ransomware threats are likely to emerge.

Turning the tables on ransomware

The Marks & Spencer’s breach is a stark reminder of how much can be at stake: revenue, reputation, and customer trust. As ransomware continues to evolve, the challenge isn’t just about defending your perimeter, it’s about knowing whether your existing controls will hold up under pressure.

Ransomware isn’t going anywhere. In 2025 and beyond, it’s not a question of if your organisation will be targeted, but when. With the right mindset and the right tools, you can face the threat with confidence.

Browse our latest issue

Intelligent CISO

View Magazine Archive