All Articles
Technology5 min read

Stop Ransomware Like a Disease Outbreak: A Practical Guide

Greg (Zvi) Uretzky

Founder & Full-Stack Developer

Share
Illustration for: Stop Ransomware Like a Disease Outbreak: A Practical Guide

Stop Ransomware Like a Disease Outbreak: A Practical Guide

The Problem You Recognize

Your network is under a ransomware attack. Alerts are flooding in. Your team is scrambling. You have to answer one urgent question: Is this attack spreading or are we containing it? Right now, you're making guesses based on fragmented technical data. That leads to overreaction in some areas and dangerous underreaction in others. The result is more damage, longer downtime, and higher costs.

What Researchers Discovered

A team of cybersecurity and public health researchers found a better way. They proved you can manage a ransomware attack exactly like doctors manage a disease outbreak. The key is tracking how it spreads and using one simple number to guide your response.

Their paper, Bending the Curve: Operational Cyber Epidemiology for Ransomware, shows that ransomware follows predictable stages. Just like a flu outbreak moves from exposure to infection to recovery, ransomware moves from initial compromise to active encryption to system removal. By classifying every infected system into these stages, you get a real-time picture of the outbreak's trajectory.

The most critical insight is the effective reproduction number (Re). This is the same "R number" used during COVID-19. If Re is above 1, one infected system is infecting more than one other. The attack is growing exponentially. If Re is below 1, your containment is working and the outbreak is shrinking. This single metric cuts through the technical chaos. It tells you clearly if you're winning or losing.

Finally, the research shows that different ransomware attacks spread through different "dominant pathways." Some spread through unpatched software. Others spread through stolen passwords. Knowing which pathway is dominant tells you which containment action to prioritize. Wasting time on the wrong tactic lets the attack spread further.

How to Apply This Today

You don't need to wait for new tools. You can adapt your existing incident response playbook starting now. Here are four concrete steps to implement this week.

Step 1: Define Your Outbreak Stages

Create a simple, standardized classification system for every compromised asset. Every person on the response team—from tech staff to executives—must use the same terms. The researchers recommend a model inspired by public health:

  • Suspected: A system showing initial signs of compromise (unusual network connections, suspicious processes).
  • Confirmed: A system with verified ransomware activity (encryption in progress, ransom note).
  • Removed: A system that has been isolated, wiped, and removed from the network.

Action: Update your incident response playbook today. Add a one-page appendix with these definitions. Train your team on them in your next tabletop exercise.

Step 2: Build Your Outbreak Dashboard (The 1-Hour Version)

You need a single view to track your stages. You can build this manually at first.

  1. During an incident, dedicate one team member to be the "tracker."
  2. Their job is to maintain a shared spreadsheet (Google Sheets or Excel).
  3. Create three columns: Suspected, Confirmed, Removed.
  4. Every 15 minutes, the tracker updates the counts based on team reports.

For example: At 10:00 AM, you have 12 Suspected, 5 Confirmed, and tap 2 Removed systems. By 10:15 AM, Suspected jumps to 18, Confirmed to 8, and Removed stays at 2. This visual trend immediately shows the attack is spreading faster than you're containing it.

Step 3: Calculate Your 'R Number' (Re)

You don't need complex math. Use this rough formula to get a directional guide:

  1. Look at your tracker from the last hour.
  2. Count how many new "Confirmed" systems appeared in the last 60 minutes.
  3. Count how many "Removed" systems you completed in the last 60 minutes.
  4. If new Confirmations are greater than Removals, your Re is likely above 1. The attack is growing.

Action Trigger: If your rough Re is above 1 for two consecutive check-ins (e.g., 30 minutes), it's a trigger to escalate containment measures—like network-wide isolation of vulnerable segments.

Step 4: Diagnose the Dominant Pathway in the First 30 Minutes

When the attack starts, don't just react. Diagnose. In the initial investigation, answer one question: Is this spreading primarily via unpatched software or stolen credentials?

  • Software Pathway: Are most early infections on systems missing the same critical patch?
  • Credential Pathway: Are attackers moving using stolen admin passwords found in your logs?

Your containment priority flows from this answer.

  • If it's a software pathway, immediately deploy the missing patch to all similar systems and isolate any that can't be patched.
  • If it's a credential pathway, immediately reset the compromised passwords and enforce multi-factor authentication on all privileged accounts.

What to Watch Out For

This framework is a powerful management tool, but it has limits. Be aware of these three points.

  1. It Requires Basic Visibility. You can only track an outbreak you can see. This approach doesn't create visibility; it uses the visibility you already have more effectively. If you lack basic network monitoring, fix that first.
  2. It Manages the Crisis, Not the Root Cause. Driving Re below 1 stops the bleeding. It doesn't heal the wound. After containment, you must still address the root cause—whether it's poor patch management, weak passwords, or insufficient backups.
  3. The Numbers Are Guides, Not Perfect Predictions. Your manually calculated Re is a rough, real-time indicator. It's not a precise epidemiological forecast. Use it to guide decisions, not to replace expert judgment.

Your Next Move

Start by running your next tabletop exercise using the outbreak stages.

This week, simulate a ransomware scenario. Use the Suspected/Confirmed/Removed classifications on a shared sheet. Practice calculating a simple Re number every 15 minutes. Debrief on how this clarity changed your team's decisions compared to past exercises.

This approach turns panic into a process. It gives you the dashboard you need to answer the only question that matters: Are we containing this?

Question for your team: In our last security incident, could we have answered whether our 'R number' was above or below 1? If not, what's the first step we take this month to change that?

ransomware containmentincident response frameworkcybersecurity dashboardreduce attack downtimeCTO security guide

Comments

Loading...

Turn Research Into Results

At Klevox Studio, we help businesses translate cutting-edge research into real-world solutions. Whether you need AI strategy, automation, or custom software — we turn complexity into competitive advantage.

Ready to get started?