Ransomware Frontline Report
Foundational Terminology
| Term | Meaning in this report | Common points of confusion |
|---|---|---|
| Ransomware | A general term for malicious activity/malicious programs that demand money or other consideration through rendering systems unusable or threatening disclosure | Not limited to encryption alone. |
| Data extortion | Using the threat of publishing, selling, or reporting stolen data as leverage | Can occur even without encryption. |
| Double extortion | A technique that uses both encryption and data theft as pressure | Does not mean a “two-stage intrusion.” |
| RaaS | A division-of-labor model in which developers provide the infrastructure and encryption functionality while operators (affiliates) handle intrusion and the infliction of harm | Not every attacker is RaaS. |
| Initial access | The first phase in which an attacker gains a foothold in an organization’s environment | Do not fix the cause of an entire compromise to a single word. |
| Lateral movement | Expanding reach from one foothold to other endpoints, servers, or identities | Not limited to network movement alone. |
| Management plane | The privilege layer that manages identity, virtualization, backup, EDR, cloud, and similar systems | Its impact can be broader than the business-data plane. This term consolidates control domains that NIST and others address individually, and is used in this report for analytical purposes; it is not a single official standard term. |