Ransomware Frontline Report
Supplement E — Commonly Misunderstood Terms and Their Meanings
E.1 Zero Trust
Zero Trust is not a single product name; it is a way of thinking in which access is judged by identity, device, context, least privilege, and continuous verification, rather than trusting something automatically because it is inside the network. As a ransomware countermeasure, it helps reduce lateral movement and privilege abuse. However, even where an organization claims to have adopted it, its effect is limited if shared identities, permanent privileges, exception traffic, or an unmonitored management plane remain.
E.2 EDR/XDR
EDR is an important means of raising endpoints’ detection and response capability. XDR is used as a concept and family of products that integrate multiple log surfaces to support detection and response. However, if the protective agent is not deployed, is disabled, or loses communication, observation is interrupted. Furthermore, without logs and response authority for identity, cloud, and the backup management plane, the full extent of a compromise cannot be judged from endpoints alone.
E.3 SIEM/SOC
SIEM and a SOC support log collection, correlation, and monitoring, but they are not something that “protects you around the clock just by deploying them.” Asset criticality, log quality, time synchronization, detection rules, staff, escalation, isolation authority, and coordination with business units are all necessary. Alerts that go unused, assets with an unknown owner, and uninterpretable logs reduce the effectiveness of deployment.
E.4 ASM/EASM
Attack Surface Management is the effort to continuously understand assets and services visible from outside, and reduce unowned assets, misconfiguration, and missed updates. Tools are useful, but unless an owner is assigned to a finding, the reason for exposure is confirmed, and it is remediated or turned into a formal exception, the result becomes a pile of notifications. IPA also calls attention to the importance of grasping and managing internet-facing points of contact. [S06]
E.5 Immutable Backup
Immutability refers to a property that makes a backup hard to alter or delete for a set period. It can be a powerful measure, but it does not by itself prove that recovery is possible. Confirm together who can change the retention settings, where the keys are, whether the management plane is separated from production, and whether restoration actually succeeds.
E.6 RTO/RPO
RTO is used as the target for the time needed for recovery, and RPO as the target for the amount (duration) of data loss that is acceptable. Beyond simply setting a number, what matters is who decided it, at what business-operation unit, whether it includes dependencies, and whether it has been measured against actual practice. Even with an RTO of 4 hours, business cannot resume if identity or external integrations do not come back.