A-Lab briefing · 5 minute read · For boards, executives and counsel
The change
Early ransomware simply encrypted files and sold the key back. A good backup defeated it. In late 2019 the Maze group began copying data out of victim networks before encrypting, and threatening to publish it. Within two years nearly every major group had followed. Today about three quarters of ransomware attacks include exfiltration. The encryption creates urgency; the stolen data creates leverage that survives even a perfect restore.
The three layers
- Encryption. Systems and data are unavailable. Operations stop. This layer is addressed by recovery: backups where they survived, laboratory reconstruction where they did not.
- Publication threat. Samples of stolen data are posted on a leak site with a countdown. Customers, regulators and the press may be contacted. This layer is addressed by legal, regulatory and communications handling, not by technical recovery and not, in practice, by payment.
- Pressure on third parties. Some groups add denial-of-service attacks, call executives directly, or extort the victim's customers using the stolen data. This is "triple extortion".
What it means for decisions
- Backups are necessary but not sufficient. They restore availability. They do nothing about the copy the attacker holds.
- Payment does not solve the confidentiality layer. There is no way to verify deletion, and published cases show paid-for data resurfacing. Payment buys a promise from a criminal group.
- Disclosure obligations are triggered by the theft, not by the encryption. Personal data leaving the organisation can require notification under the UAE Personal Data Protection Law, DIFC and ADGM regimes, and sector regulators, regardless of what happens next.
- Knowing what was taken is a forensic task. Logs, archiving tool traces and outbound-transfer records establish the scope. This is where preserved evidence matters.
Where A-Lab fits
A-Lab addresses the first layer: getting your databases, backups, virtual machines and files back without the attackers' cooperation. Our entry-point analysis also contributes to the second layer by establishing how the intrusion happened and what the attacker could reach. For legal and communications handling we work alongside your counsel and incident-response advisers.
Board summary. Treat a ransomware incident as two problems. Recover availability through backups and laboratory reconstruction. Handle confidentiality through counsel, regulators and communications. Neither problem is solved by contacting the attackers.