An Updated Framework of Defenses Against Ransomware

SEI Report
This report, loosely structured around the NIST Cybersecurity Framework, seeks to frame an approach for defending against RaaS as well as direct ransomware attacks.
Publisher

Software Engineering Institute

Topic or Tag

Abstract

The proliferation of tools and techniques to disrupt enterprise systems has evolved from those capable of supporting merely opportunistic attacks to those enabling targeted attacks. Furthermore, attackers continue to develop methods for monetizing their efforts, resulting in ransomware, a very disruptive threat to business as well as governmental departments and agencies. Ransomware developers are now selling their tools as a service, enabling attackers (individual criminals, organized crime, ideological hackers, or nation-state teams, all hereafter referred to as affiliates) to use tools they do not build or maintain to attack vulnerable systems.

In the last few years we have seen a rise of successful ransomware affiliates that purchase the malware that they use and incorporate it into a ransomware tool chain that is targeted to a specific victim. These attackers lock victims out of their own data, usually by encrypting it, and attempt to extort money to restore the victim’s access to the enterprise data under threat of data destruction or disclosure as a response for non-payment. Recent high-profile cases, including attacks attest to the seriousness of the problem. In each case, the victims suffered operational disruptions with monetary losses.

This report, loosely structured around the NIST Cybersecurity Framework, seeks to frame an approach for defending against Ransomware-as-a-Service (RaaS) as well as direct ransomware attacks.

Cite This SEI Report

Snoke, T., & Shimeall, T. (2020, August 18). An Updated Framework of Defenses Against Ransomware. Retrieved September 12, 2026, from https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/.

@techreport{snoke_2020,
author={Snoke, Timur and Shimeall, Timothy},
title={An Updated Framework of Defenses Against Ransomware},
month={Aug},
year={2020},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/},
note={Accessed: 2026-Sep-12}
}

Snoke, Timur, and Timothy Shimeall. "An Updated Framework of Defenses Against Ransomware." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, August 18, 2020. https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/.

T. Snoke, and T. Shimeall, "An Updated Framework of Defenses Against Ransomware," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 18-Aug-2020 [Online]. Available: https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/. [Accessed: 12-Sep-2026].

Snoke, Timur, and Timothy Shimeall. "An Updated Framework of Defenses Against Ransomware." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 18 Aug. 2020. https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/. Accessed 12 Sep. 2026.

Snoke, Timur; & Shimeall, Timothy. An Updated Framework of Defenses Against Ransomware. Software Engineering Institute. 2020. https://www.sei.cmu.edu/library/an-updated-framework-of-defenses-against-ransomware/