

Ransomware remains a persistent operational threat. BitSight’s live tracker continues to record substantial victim activity on ransomware leak sites, while Huntress describes an environment in which attackers increasingly combine encryption, data theft, disruption and pressure on customers or partners. The precise numbers will continue to change, but the leadership problem is more durable: once something gets through, can the organisation still change the course of the incident?
Organisations should continue to train staff, harden systems and invest in monitoring, segmentation, backup and response. None of those measures has become less important. However, prevention and detection do not remove the need for control once an incident is active.
AI can increase the scale and plausibility of some intrusion techniques, while also adding complexity to security operations. Yet the board-level question does not depend on predicting exactly how much faster attackers will become. Every organisation already has a finite interval between receiving a credible signal and executing a consequential move. If triage, authority or technical execution consumes that interval, visibility becomes a record of attacker progress rather than a means of changing it.
The emergency begins when visibility does not yet create control.
Because once an adversary is already moving, visibility on its own does not reassure anyone. What matters is whether visibility creates a safe move: reduce access, limit spread, interrupt malicious behaviour, and preserve enough operations to stay governable while trust is rebuilt. The Council of Europe’s ransomware risk guidance is clear that the consequences are not only financial, but also operational, legal, safety, and security related.
This is why I think the real distinction is not prevention versus detection.
It is awareness versus control.
Huntress says attackers are standardising double, triple, and even quadruple extortion tactics. BitSight says the volume is still climbing. Gartner says the operating environment is becoming more complex as AI destabilises established routines in security operations. None of that suggests a future where “we saw it” is enough on its own.
The challenge is not only that attackers are becoming more numerous. The challenge is that AI is compressing the time between discovery and exploitation. Human defenders are still coordinating meetings, approvals and investigations while machine-assisted attackers are increasingly automating analysis, targeting and adaptation. That makes the distance between seeing and stopping even more important.
The real failure is often the time-to-action gap. Not the first signal. Not the first suspicious behaviour. Not even the first alert.
The real failure is the distance between seeing attacker activity and stopping attacker progress.
That gap widens when the signal is debated, when the first move is unclear, or when the organisation has visibility but no safe containment step ready to authorise.
None of this remains a purely technical problem for very long.
We have seen this repeatedly. In incidents such as Change Healthcare, the question quickly became larger than initial detection. The real challenge quickly became operational control, continuity and decision-making while trust in systems was being rebuilt.
In a fast-moving incident, nobody remembers that a dashboard lit up. They remember whether the organisation reduced the blast radius, protected critical operations, and stayed in control long enough to make defensible decisions. The Council of Europe notes that ransomware can lead to downtime, missed deadlines, supply-chain disruption, layoffs, and even closures. Those are not alert-quality problems. They are outcome problems.
And they are leadership problems too. Because when the signal is seen but the move is unclear, the burden shifts quickly onto people: who decides, how fast they decide, what they are willing to disrupt, and how much uncertainty they are prepared to act under.
That is where visibility stops being a security discussion and becomes a governability test.
A line I keep coming back to is this:
Detection buys awareness. Only containment buys time.
That is the difference between seeing the incident and changing its outcome. It is also why the first hour matters so much more than many reporting packs suggest. By then, the question is no longer whether the signal was technically accurate. It is whether the organisation can turn that signal into controlled action.
The real question is: “If we detected it, how quickly would that become control?”
These are not technical footnotes. They are the questions that decide whether visibility leads to control or simply to a more informed form of delay.
One practical pressure-test suggestion:
Run a time-to-action validation around a credible early-stage ransomware signal. Do not test whether the tool detects. Assume the alert already exists.
Instead, test whether the organisation can answer, in sequence:
The value is not the discussion.
The value is finding out whether awareness in your environment can actually become action. That is the real question for leadership.
Not whether the alert exists. But whether the organisation can turn that alert into a safe move before the situation becomes harder to govern.
Our platform is designed for the moment when an alert needs to become a controlled response. It complements existing preventive and detective controls by adding an operational containment layer that can help interrupt lateral movement, constrain unsafe paths and reduce the attacker’s room to act, while the organisation preserves as much safe operation as the incident allows.
Our aim is not to suggest that every alert immediately creates certainty. The practical value is that the organisation gains an executable move between observing malicious activity and resorting to broad shutdown or recovery. That is why we believe containment should be demonstrated in the customer’s own environment rather than accepted as a product promise.
The critical question is therefore not simply whether the organisation would detect the incident, but how quickly that detection could become control.
I can share more detail on how S10 Group’s platform helps close the gap between seeing the signal and changing the outcome.
And for teams that want to pressure-test their own setup: I can run a free remote resilience assessment in your own sandbox environment, with your existing security controls enabled, to show how your current environment behaves under pressure and what difference that added control makes in practice.
If any of these would be relevant for your team, feel free to contact me.