Entry Point 1: Unpatched External Systems

Internet-facing systems with known, unpatched vulnerabilities are the most direct path into a corporate network. VPN appliances have been particularly targeted — Fortinet, Pulse Secure, Citrix, and SonicWall have all had critical vulnerabilities exploited at scale by ransomware groups. Attackers scan the internet constantly for these signatures; a vulnerable system can be exploited within hours of a public disclosure.

How to close it: Maintain a current external asset inventory, implement a rigorous patch management process with defined SLAs for critical patches, and conduct external penetration testing to identify vulnerabilities before attackers do.

Entry Point 2: Exposed RDP

Remote Desktop Protocol (RDP) exposed directly to the internet is a gift to ransomware operators. Brute-force credential attacks, credential stuffing, and exploitation of RDP vulnerabilities are all common initial access methods. Many organizations expose RDP unintentionally or temporarily and then forget about it.

How to close it: Never expose RDP directly to the internet. Require VPN access before RDP is reachable, implement network-level authentication, and enable MFA for all remote access. External penetration testing identifies exposed RDP in your environment.

Entry Point 3: Phishing and Credential Theft

Phishing remains the most common initial access vector for ransomware. Attackers send emails that steal credentials, deliver malware through attachments, or trick users into authorizing access. Business Email Compromise (BEC) attacks are a related threat that can fund or initiate ransomware operations.

How to close it: Implement phishing-resistant MFA (hardware tokens or FIDO2) for all external-facing accounts. Conduct regular phishing simulations and security awareness training. Grid32 offers phishing assessment services that benchmark your employees' susceptibility.

Entry Point 4: Weak or Absent MFA

Even strong passwords are insufficient without MFA. Credential stuffing attacks — using credentials from prior breaches — succeed at scale against accounts without MFA. Microsoft reports that MFA blocks over 99% of automated credential attacks.

How to close it: Implement MFA universally — email, VPN, cloud services, administrative accounts, and critical applications. Require phishing-resistant MFA (FIDO2) for privileged accounts. NYDFS specifically mandates this; other frameworks strongly imply it.

Entry Point 5: Supply Chain Compromise

Attackers increasingly target managed service providers (MSPs), software vendors, and IT tools used by many companies simultaneously. A successful supply chain compromise gives attackers access to every customer of the compromised vendor. The SolarWinds and Kaseya incidents are high-profile examples of this technique at scale.

How to close it: Assess your MSPs and vendors' security posture. Limit the access third parties have to your environment to the minimum necessary. Network segmentation limits the blast radius of a vendor compromise. Internal penetration testing identifies what a compromised vendor account could reach.

Know which entry points exist in your environment.

Grid32 tests all the entry points ransomware uses — external, internal, and human. Use our quote builder to scope an engagement.

Get a Quote →