Blog

Ransomware Attack Statistics

Man on a laptop in a dark blue environment, representing ransomware attack statistics

In 2025, the median time between an initial access event and handoff to a secondary threat group fell to 22 seconds, according to Mandiant’s M-Trends 2026 report. That interval gives defenders little time to identify suspicious activity before another group can act.

For IT and InfoSec leaders, remote access architecture affects how easily attackers can reach sensitive systems. This article reviews ransomware attack statistics, explains the role of remote access in initial access, and describes the controls enterprises should require from remote support vendors.

Current Ransomware Initial Access Data

Coalition’s 2025 Cyber Threat Index analyzed 2024 ransomware claims and reported two remote-access-related entry categories: compromised perimeter security appliances and remote desktop products.

Remote Access Entry Points in Coalition Ransomware Claims

Initial access route

Share of 2024 ransomware claims

Source

Compromised perimeter security appliances, including VPNs and firewalls

58%

Coalition Cyber Threat Index 2025

Remote desktop products

18%

Coalition Cyber Threat Index 2025

These two categories account for most claims in Coalition’s dataset. The report measures insurance claims, so its figures should remain separate from incident percentages reported by other research firms. The distinction matters because this article focuses on remote access infrastructure and ransomware exposure.

How Remote Access Appears in Ransomware Initial Access Data

Remote access connects external users to systems that hold sensitive data and administrative privileges. VPNs, firewalls, and remote desktop products therefore remain attractive targets.

For buyers, the remote support architecture determines how access is opened, limited, and recorded. Session-based controls can reduce exposure from internet-facing entry points and standing credentials.

Remote Access Paths and Security Implications

Access path

Security implication

Internet-facing VPN or firewall

Can expose a route into internal systems if compromised or misconfigured

Remote desktop product

Can provide direct access to an endpoint or administrative environment

Controlled remote support session

Can limit access by user, endpoint, role, and time window

The first two paths expose access before a support session begins. A controlled session places limits around the user, endpoint, and time window. Those limits matter because attackers can move quickly after gaining a foothold.

How Fast Attackers Move After Initial Access

Once attackers gain access, teams may have only minutes to detect activity. The benchmarks below show why remote support controls need to support fast detection and response.

Attacker Speed and Dwell-Time Benchmarks

Speed metric

Measurement

Source

Median handoff from initial access to a secondary threat group in 2025

22 seconds

Mandiant M-Trends 2026

Average eCrime breakout time in 2025

29 minutes

CrowdStrike 2026 Global Threat Report

Fastest observed eCrime breakout in 2025

27 seconds

CrowdStrike 2026 Global Threat Report

Global median attacker dwell time in 2025

14 days

Mandiant M-Trends 2026

The figures span seconds, minutes, and days. Remote support tools should enforce MFA at session start, limit privileges to the task, record activity, and send logs to the systems your security team monitors. These controls become especially important when evaluating older tools with exposed access paths or limited session visibility.

Why Legacy Remote Support Tools Increase Exposure

Legacy remote support tools often combine four weaknesses: exposed network paths, standing credentials, limited session visibility, and weak SIEM integration. These weaknesses can help an attacker move from initial access to broader activity, especially when the tool sits outside the organization’s identity and monitoring controls.

Legacy Remote Access Risk Factors

Risk factor

Why it matters

Exposed RDP ports or persistent VPN connections

Creates internet-facing access that attackers can scan or exploit

Standing administrator credentials

Turns a support account into a reusable target between sessions

Minimal audit trails

Leaves investigators with less context about who accessed an endpoint and what they changed

No SIEM integration

Slows correlation with identity, endpoint, and network alerts

These four weaknesses define the areas buyers should examine during a remote support review. The following architecture controls address each area.

Security Architecture Requirements for Enterprise Remote Support

A secure remote support architecture needs four capabilities.

No exposed network ports. The platform should operate without open RDP ports, inbound firewall rules, or a persistent VPN connection. Sessions should initiate outbound through a secure cloud relay, reducing internet-facing access paths.

Just-in-time access. Access should be granted per session, scoped to a specific task, and revoked when the session ends. This limits the time that administrative access remains available.

Full session recording and real-time monitoring. Every privileged session should be logged, with activity available for review and investigation. Real-time monitoring helps security teams investigate suspicious activity during a support session.

Compliance-grade certifications. SOC 2 Type II and ISO 27001 certifications, along with documented privacy and security controls, provide records for procurement, audits, and renewals.

Security Architecture Controls

Security architecture feature

Risk it helps reduce

Cloud-relay architecture with no exposed ports

Reduces internet-facing access paths

Just-in-time, per-session access

Removes standing credentials between support events

Full session recording and monitoring

Improves investigation and response visibility

Compliance certifications and audit documentation

Supports security reviews and compliance checks

Use these controls to compare products. The vendor questions test how each control works in production and how its records reach the security team.

Questions IT and InfoSec Leaders Should Ask Remote Support Vendors

Use these questions during the next audit cycle or contract renewal.

Architecture and Network Exposure

  • Does this tool require open RDP ports, inbound firewall rules, or a persistent VPN connection to function?
  • Are sessions initiated outbound through a secure cloud relay, or inbound to an agent running on the endpoint?

Credential and Access Model

  • Does the tool support just-in-time access, or does it maintain standing administrator credentials between sessions?
  • Does MFA apply at every session initiation and during platform login?
  • Can access be scoped to specific endpoints, roles, and defined time windows?

Audit and Monitoring

  • Does the platform record full sessions, including keystrokes and screen activity?
  • Can audit logs be exported for SIEM integration and compliance reporting?

Compliance and Certifications

  • Does the vendor hold SOC 2 Type II and ISO 27001 certifications with current third-party audit documentation?
  • Can the vendor document its breach history and explain how it handles security incidents?

Vendor Evaluation Criteria: Remote Support Security Minimum Standards

Use these thresholds during procurement, audits, and contract renewals. The criteria cover network exposure, session access, monitoring, and accountability.

Vendor Evaluation Thresholds

Evaluation category

Minimum threshold

Network exposure

No exposed RDP, VPN, or inbound ports required

Session initiation

Outbound cloud relay only; no peer-to-peer requirement

Credential model

Just-in-time access, without persistent administrator credentials

MFA enforcement

Per session and platform login

Session logging

Full recording and exportable audit activity

Access scope

Defined endpoints, roles, and time windows

Compliance certifications

SOC 2 Type II and ISO 27001, with audit documentation

Breach history

Clear, documented incident history

Use these thresholds during vendor review. The conclusion applies them to ScreenMeet’s stated architecture and certifications.

What These Ransomware Attack Statistics Mean for Remote Support

For remote support buyers, the central requirements are exposed access, privilege limits, and session verification. ScreenMeet is a cloud-native, Zero Trust remote support platform with session recording, role-based access controls, and SOC 2 Type II and ISO 27001 certifications. It also supports ServiceNow, Salesforce, and Tanium integrations.

Before your next audit or vendor renewal, compare your current tool with the architecture and vendor questions above. Focus on reducing access paths and preserving evidence for every remote support session.

Book a Demo to See How ScreenMeet Reduces Remote Access Exposure

Sources

  1. Mandiant / Google Cloud, “M-Trends 2026 Report: Executive Edition”: https://cloud.google.com/security/resources/m-trends-executive-edition
  2. Coalition, “Coalition’s Cyber Threat Index 2025 Finds Most Ransomware Incidents Start with Compromised VPN Devices”: https://www.coalitioninc.com/announcements/cyber-threat-index-2025
  3. CrowdStrike, “2026 Global Threat Report”: https://www.crowdstrike.com/en-us/global-threat-report/
  4. ScreenMeet, “Secure Your Remote Support: Why Legacy Tools Like Bomgar Put Your Organization at Risk”: https://www.screenmeet.com/blog/secure-your-remote-support-why-legacy-tools-like-bomgar-put-your-organization-at-risk

Ready to Replace Your Legacy Solutions?
Start Your Journey Here

Try The Guided Tour

See It In Action: Experience our comprehensive in-browser demo showcasing all core remote support capabilities and platform integrations.

Product Overview

Watch A 4-Minute Product Overview: Quick overview covering key benefits, security features, and integration capabilities for busy IT leaders. 

Talk To A Specialist

Ready To Get Started? Speak with our platform experts about your specific ServiceNow, Salesforce, or Tanium integration requirements.

Book A Demo