Ransomware crews, state-linked advanced persistent threat (APT) groups and supply-chain intruders differ in motive, but they behave in similar ways once inside: they gain a foothold, steal credentials, move laterally, and act on their objective. Organisations that understand this sequence can defend against all three with the same core capabilities, rather than chasing each new headline.
Think in stages, not in tools
The cyber kill chain and the MITRE ATT&CK knowledge base describe attacker behaviour as a series of tactics: initial access, execution, persistence, privilege escalation, credential access, lateral movement, collection, exfiltration and impact. The defender's advantage is that an attacker must succeed at every stage, while you only need to detect or block one. Design controls so that each stage has at least one preventive and one detective layer.
Initial access: close the common doors
- Enforce multi-factor authentication on email, VPN, remote administration and cloud consoles.
- Patch internet-facing systems first, and remove services that do not need to be exposed.
- Filter email and web traffic, and train staff to report suspicious messages quickly.
- For supply-chain risk, keep an inventory of third-party software and vendors with access to your environment, limit their privileges, and require them to meet defined security obligations. Verify software updates through signatures or hashes where vendors provide them.
Detect behaviour with EDR, XDR and ATT&CK
Antivirus alone cannot stop attackers who use legitimate tools. Endpoint detection and response (EDR) records process, network and file activity, and extended detection and response (XDR) correlates that with email, identity and network data. Use MITRE ATT&CK as a coverage map: list the techniques most relevant to your sector, check which ones your current logs and rules can actually detect, and close the gaps in priority order. Typical high-value signals include unusual use of administrative tools, credential dumping attempts, new scheduled tasks or services, disabled security software, and mass file access or deletion of backups. Centralise logs in a SIEM and have a monitored process, in-house or managed, to act on alerts around the clock.
Limit the blast radius
- Segmentation. Separate user networks, servers, management interfaces and critical systems such as payment or citizen-records platforms, and allow only required flows. NIST SP 800-207 describes this as a Zero Trust principle.
- Least privilege. Remove local administrator rights, use separate administrative accounts, and protect domain-level credentials with a privileged access management solution.
- Immutable, offline backups. Ransomware operators commonly target backups before encrypting data. Keep at least one copy that cannot be altered or reached from the production network, and test restoration regularly.
Practise before it matters
Controls decay if they are not exercised. Run tabletop exercises with executives and technical teams around a ransomware scenario and a supplier-compromise scenario. Use periodic penetration tests and purple-team exercises, where attackers and defenders work together, to confirm that detections fire and that responders know what to do. Align the outcomes with NIST CSF 2.0, and for banks with PCI DSS v4.0.1 and the SWIFT Customer Security Programme where applicable. Record lessons learned and assign owners to every finding.
How Wethaq ICT helps
Wethaq ICT provides 24x7 monitoring and threat detection, EDR and SIEM deployment, network segmentation design, backup resilience reviews, and adversary-emulation exercises mapped to ATT&CK. Our incident response specialists can also be engaged before an incident, so that procedures and contacts are ready. The aim is simple: to help government bodies, companies and banks interrupt an attack early, contain it quickly and recover with confidence.
Let’s build a secure foundation for your digital future
It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.

