Skip to content
BreachPathAttack Path LibraryStart

Ransomware in the Professional services sector

How a ransomware attack could realistically chain together in a Professional services organisation, from initial access to business impact — and exactly what you should test to break the chain.

AdvancedOn-premises Active Directory

Exposed VPN to Active Directory ransomware

Weakly protected remote access is used to reach the internal network, escalate to domain-wide control of Active Directory, neutralise backups and stage ransomware across the estate.

Remote accessActive DirectoryDomain-wide controlBackups are
Ransomware
AdvancedOn-premises Active Directory

Supplier account to internal network

A compromised supplier's access is used to enter the organisation through a trusted connection, then to move from the supplier's limited footprint toward internal systems and data.

A supplier'sThe trustedInternal systems
Data theftRansomware
AdvancedCustom web applications

Vulnerable web application to ransomware

A flaw in an internet-facing application provides a server foothold, which is used to move onto the internal network, escalate privilege and deploy ransomware against reachable systems.

The internet-facingThe attackerRansomware is
Ransomware
IntermediateOn-premises Active Directory

Exposed remote desktop to ransomware

An internet-exposed remote desktop service with weak authentication gives direct interactive access to a host, which is used to spread, escalate and deploy ransomware.

Exposed remoteThe attackerRansomware is
Ransomware
AdvancedSaaS (generic)

Supplier software update to ransomware

A trusted software update from a compromised supplier delivers attacker code into the environment, which is used to establish control and deploy ransomware from the inside.

Attacker codeControl isRansomware is
Ransomware

Why chaining matters here

A scanner might flag each weakness in this environment in isolation. What determines whether ransomware is actually achievable is whether those weaknesses — together with identities, trust relationships and gaps in monitoring — can be linked into a working path. That is what a red-team engagement validates, and what these chains are designed to help you scope.