Ransomware activity has significantly increased in 2026, with 61 new ransomware groups entering the market between April 2025 and March 2026, resulting in a
{
"title": "Ransomware in 2026: With More Groups, Are Defenses Failing?",
"slug": "ransomware-2026-defenses-failing",
"seo_title": "Ransomware in 2026: With More Groups, Are Defenses Failing?",
"seo_description": "Ransomware in 2026: As active groups grow, experts debate whether industry defenses are keeping pace or if they pose growing vulnerabilities.",
"markdown": "# Ransomware in 2026: With More Groups, Are Defenses Failing?\n\nThe rise of ransomware in 2026 is creating a dichotomy in expert opinion regarding the effectiveness of current cyber defenses. With 61 new ransomware groups emerging within the year and a total of 146 active groups identified, the urgency for improved containment methods and incident response strategies has never been clearer. Experts Darren Cho, Ivan Sorrell, Leah Sterling, Mara Bell, and Noa Keller weigh in on the implications of this growing trend.\n\n## **Darren Cho: Ransomware Defenses Are Lagging, Urgent Action Needed**\nDarren Cho emphasizes the urgency of enhancing containment measures and incident response protocols as ransomware attacks become increasingly prevalent. He expresses concern over the staggering 7,551 reported ransomware victims this year, highlighting that with such a sharp increase of 60% in disclosures, businesses must prioritize triage and response workflows. The evidence points to an unsettling trend; with nearly half of all victims located in the United States, the implications of poor security measures could be devastating.\n\nIn Cho's view, organizations continue to overlook critical vulnerabilities, particularly regarding security misconfigurations and Internet-facing remote access. He argues that the surge of new ransomware groups indicates an influx of unprepared adversaries, meaning that businesses cannot afford to be complacent. "It’s not just an increase in attacks; it’s a significant breakdown in our defenses. Organizations need urgent prioritization of incident response infrastructure," he asserts. Cho insists that without tactical improvements in these areas, companies risk catastrophic breaches.\n\n## **Ivan Sorrell: The Adversaries Are Adapting, But So Must We**\nIvan Sorrell takes an assertive stance on understanding adversary behavior in the evolving ransomware landscape. He notes that as new groups enter the market, there's a measurable shift in exploit development and tradecraft. The increase in fragmentation among the criminal ecosystem has led to more sophisticated attack methods, which require organizations to adopt a multifaceted approach to threat assessment and mitigation.\n\n“The attackers are not just growing in number; they’re becoming more creative and efficient,” Sorrell explains. He insists that cybersecurity teams must leverage intelligence about adversary tactics, techniques, and procedures to stay ahead of these trends. Sorrell is critical of organizations that fail to adapt their security protocols in favor of outdated practices. “If we want to disrupt these attacks, we need to improve our understanding of how adversaries innovate and adapt to our defenses,” he argues. For him, that means investing in threat intelligence and staying on the cutting edge of security technology.\n\n## **Leah Sterling: Privacy Laws and Surveillance Risks Compound Ransomware Threats**\nLeah Sterling brings attention to the intersection of ransomware threats and the current landscape of privacy laws and surveillance risks. Her perspective acknowledges the increased ransomware activity but introduces a layer of complexity regarding the policy frameworks that govern cybersecurity practices. She highlights that as more companies face pressure to disclose breaches due to legal obligations, they inadvertently open themselves up to further vulnerability and scrutiny.\n\nSterling argues that while combating ransomware should be a priority, it cannot come at the expense of citizens' privacy rights. "The rush to implement sweeping surveillance measures or overly invasive security practices can create new vulnerabilities rather than mitigate existing risks," she states. Sterling believes that clear, progressive privacy regulations need to be considered in the context of curtailing ransomware. This includes advocating for a balanced approach that protects personal data while robustly addressing the threats posed by these nefarious actors.\n\n## **Mara Bell: Governance Gaps Need Focus on Risk Management**\nMara Bell approaches the current ransomware situation from a governance and risk management perspective, stressing that the fragmentation of ransomware groups reflects deeper governance gaps within organizations. As more groups emerge, she insists that organizations must focus on outlining clear risk management strategies that inform board reporting and breach disclosures.\n\nBell argues that the presence of so many active groups complicates the already challenging landscape of accountability and decision-making. “Organizations need to be transparent about their vulnerabilities and engage in comprehensive risk assessments,” she advises. She suggests that a culture of open communication and preparedness needs to be paramount in mitigating risks associated with ransomware. “Without the necessary visibility into risk management processes, businesses will continue to falter under the pressure of increasing attacks,” she asserts.\n\n## **Noa Keller: Validating Threat Intel is Paramount Amidst Rising Incidents**\nNoa Keller focuses on the essential need for credible threat intelligence and the importance of thorough validation within the context of rising ransomware activity. She expresses skepticism about the quality of reporting related to ransomware, especially given the surge of new groups and the heightened volume of attacks. “Many organizations are making claims based on unverified intelligence, which can lead to irrelevant or even detrimental responses to threats,” she warns.\n\nKeller emphasizes that proper threat intel validation is crucial before undertaking significant operational changes or strategic investments. "Organizations need not only to recognize the threats they face but to ascertain the validity of the information driving their decisions," she states. By prioritizing accuracy in reporting and validating claims, Keller believes that companies can better protect themselves against misguided responses that fail to address the core issues presented by the ransomware threat.\n\nIn summary, the roundtable presents a range of perspectives on the rising trend of ransomware in 2026. Cho and Sorrell emphasize the urgency of strengthening technical defenses and adapting to adversary behaviors, while Sterling and Bell caution against compromising privacy rights and stress the importance of governance and risk management. Keller, meanwhile, highlights the critical need for validated threat intelligence. Although these experts agree on the concerning escalation of ransomware incidents, their views diverge significantly on how best to address the growing threats and whether existing strategies adequately account for the complexities of modern cyberattacks."
}