Ransomware Frontline Report
7. The Future: Not Prophecy, but Changes to Prepare For
It is not possible to speak definitively about the future. The “outlooks” in this chapter indicate the directions defenders should prepare for, assuming that currently observed conditions continue — the division of labor in attacks, dependence on identity, cloud, and outsourcing partners, double extortion, exploitation of vulnerabilities, and the expanding use of generative AI. They do not predict specific future incidents, the targets of specific groups, or the success of an attack.
7.1 Outlook 1: Encryption Will Remain Part of Extortion
The existence of double extortion and no-ware ransom shows that even if encryption alone is prevented, confidentiality risk remains. Organizations need to include both availability recovery through backups, and confidentiality protection through data classification, access auditing, and exfiltration detection, in the same plan.
Preparation: Make clear the location, retention, access rights, external sharing, and audit logs of critical data, and incorporate leak investigation, notification decisions, and customer response into the recovery plan.
7.2 Outlook 2: The Defensive Value of Identity and the Cloud Management Plane Increases
The more business operations move to SaaS, cloud, and hybrid identity, the greater the scope reachable through a single identity or administration console. This does not mean cloud is dangerous. It means that, just as with on-premises systems, privilege inventory, separation of administrators, logging, emergency access, and control of configuration changes are called into question.
Preparation: Manage not only human identities but service principals, API tokens, OAuth consent, emergency accounts, and outsourcing-partner accounts as assets. Properly preserve cloud audit logs in a separate location from which they can be recovered.
7.3 Outlook 3: Third-Party Risk Becomes an Operational Problem After Procurement
The Verizon 2025 DBIR reported an increase in the proportion of breaches involving a third party. [S03] In an environment with growing dependencies, it is necessary to manage the lifecycle of connection, privilege, change, monitoring, notification, and termination — not only a questionnaire at the time of procurement.
Preparation: Starting with the most critical outsourcing partners, confirm the connection ledger, privilege review, contractual notification and cooperation clauses, joint exercises, and emergency alternate routes. Where all outsourcing partners cannot be evaluated to the same depth, prioritize by reachable privilege and the impact of a business stoppage.
7.4 Outlook 4: Generative AI May Accelerate Both Attack and Defense
The 2026 DBIR reports that, in the median case, actors sought AI assistance for around 15 distinct techniques across MITRE ATT&CK. [S04] This count of techniques should not be read as a prevalence rate for AI involvement across breaches, and does not mean AI was involved in 15% of all breaches. Nor is this a claim that “AI autonomously carries out all attacks.” It is a realistic view that AI can change the speed and scale of existing work — drafting text, reconnaissance, translation, classification, the quality of impersonation, log analysis, and the like.
Preparation: While retaining human verification, use AI for summarizing anomalous logs, cross-checking assets and privileges, formatting incident records, and improving phishing training. Do not treat AI output as a source of fact; design so that one can always trace back to the original logs, official information, and approval records.
7.5 Outlook 5: Recovery Capability Becomes Part of Competitiveness and Trust
Ransomware countermeasures are not merely an insurance-like activity to reduce damage. Customers, business partners, regulators, and insurers watch how quickly and accurately an organization can explain the situation during a major disruption, restore priority operations, and demonstrate recurrence prevention. Recovery capability has become part of operational quality and continuity of business relationships.
Preparation: Rather than an annual document update, continuously measure recovery capability through change management, failure exercises, restoration drills, outsourcing-partner reviews, and reporting to management.