Back to Field Notes
Threat Intelligence/Field Note

Ransomware in 2026 — The Economics That Drive the Attacks

Ransomware operators want yield per hour. Controls that make you slower to compromise increase their cost — that's deterrence.

Author

Aisha Khan

Director, Threat Intelligence

Published

March 3, 2026

Read

10 min

Share
AI-generated illustration of a power turbine control room
AI-generated illustration of a power turbine control room
Key Takeaways
  • 01Ransomware-as-a-service operations are businesses that optimize for yield per attacker-hour. Their funnel: initial access (purchased or earned), privilege escalation + lateral movement (labor-intensive), data exfiltration (the primary leverage), encryption (secondary), negotiation + payment (back office).
  • 02Controls that move their economics work because they raise attacker-hours per dollar of yield. Hard MFA reduces initial-access yield. Strict admin separation slows lateral movement. Ransomware-resistant backups force reliance on exfiltration leverage. Egress monitoring catches the exfiltration.
  • 03What does not deter them: legal threats, awareness training, and paying ransoms (which actually subsidizes them). The deterrent is making operations unprofitable, not making them unethical — they already know.
  • 04Combine the controls. Each one alone is route-able. Stacked, they price many targets out of the operator's portfolio — which is the only deterrence that holds up over time.

Ransomware-as-a-service operations are businesses. They optimize for yield per attacker-hour. Understanding that model is the fastest way to understand which controls deter them and which they will route around.

The funnel they optimize

  • 01Initial access — purchased or earned, with measurable cost
  • 02Privilege escalation and lateral movement — labor-intensive
  • 03Data exfiltration — increasingly the primary leverage
  • 04Encryption — destructive but secondary to exfiltration
  • 05Negotiation and payment — back-office operation

Controls that move their economics

Anything that increases attacker-hours per dollar of yield works. Hard MFA reduces initial access yield. Strict admin separation slows lateral movement. Ransomware-resistant backups force them to rely entirely on exfiltration leverage. Egress monitoring catches the exfiltration. The combination prices many targets out of the operator's portfolio.

What does not deter them

Threats of legal action, awareness training, paying ransoms (it actually subsidizes them). The deterrent is making the operation unprofitable, not making it unethical — they already know.

#Ransomware#Threat Intel#Economics

/WRITTEN_BY

Aisha Khan

Director, Threat Intelligence · Alexa Cybersecurity