The Question
The popular mental model of a ransomware attack is an opportunistic criminal who fires exploits at internet-facing systems until something breaks. The reality — at least for the ransomware-as-a-service groups responsible for the most significant enterprise incidents — is considerably more deliberate.
Modern RaaS operations separate the functions of initial access from ransomware deployment. Initial access brokers (IABs) are specialists who sell authenticated access to enterprise networks on criminal marketplaces. These brokers perform structured reconnaissance before selecting targets and investing time in achieving access. They assess the external attack surface, check credential exposure in dark web markets, identify which internet-facing systems are running vulnerable software versions, and evaluate whether the target's email security posture suggests susceptibility to phishing. The brokers who sell access at the highest prices are the ones who do the most thorough pre-attack reconnaissance.
This is the threat model that CTEM is positioned to counter — not the opportunistic scanner, but the structured reconnaissance process that identifies specific, exploitable weaknesses in your specific environment before the attack begins.
Ransomware operators assess your exposure before attacking — and the organizations that perform that assessment themselves, in advance, are the ones that close the specific gaps attackers would exploit rather than patching CVEs by CVSS score.
Why This Matters Now
The Change Healthcare ransomware attack of February 2024 is the defining case study for the pre-attack reconnaissance model. The ALPHV/BlackCat ransomware group used compromised credentials to authenticate against a Citrix Netscaler remote access portal. The portal lacked MFA enforcement. The credentials were not stolen from Change Healthcare — they were obtained from a dark web credential marketplace, where they had been available from a prior third-party breach.
The attack sequence required no zero-day exploits, no sophisticated technical capability, and no extensive operational dwell time before deploying ransomware. What it required was a pre-attack assessment that identified: (1) an externally accessible remote access portal, (2) the absence of MFA on that portal, and (3) the availability of valid credentials for that portal in breach data markets. All three components were discoverable through the same OSINT techniques available to defenders.
The consequences were not modest. Change Healthcare's systems processed roughly 15 billion healthcare transactions annually, representing approximately one-third of all U.S. healthcare claims. The outage lasted weeks. Hospitals and physician practices could not process insurance claims. The parent company, UnitedHealth Group, disclosed total losses exceeding $870 million in the first quarter following the attack, with cumulative losses approaching $3 billion. The financial and operational impact was produced by a gap that CTEM would have surfaced.
The pattern extends beyond this single incident. CrowdStrike's 2024 Global Threat Report documented a 75 percent increase in cloud environment intrusions, with IABs driving a significant portion of initial access in enterprise ransomware cases. Mandiant's 2024 M-Trends report found that the median attacker dwell time before ransomware deployment was under 48 hours — implying that initial access was already purchased or staged when the ransomware deployment phase began.
What the CURVE™ Data Shows
The 2026 Stackcurve CTEM CURVE™ Report assessed the ransomware resilience validation category — platforms and methodologies that simulate the pre-attack reconnaissance and initial access techniques used by ransomware operators, with the goal of identifying exploitable gaps before attackers do.
This category overlaps with breach and attack simulation (BAS), external attack surface management, and credential exposure monitoring. No single vendor covers the full pre-attack assessment workflow; the most effective programs combine capabilities from multiple platforms.
Pentera leads on automated credential-based attack simulation, including automated password spray and credential stuffing validation against identified external-facing systems. The platform's ability to take discovered credentials and validate whether they successfully authenticate against enterprise systems is directly relevant to the IAB threat model. Cymulate provides the broadest BAS coverage and the most mature threat intelligence integration, with campaign simulations mapped to specific threat actor TTPs. Picus Security differentiates on purple team automation and remediation guidance quality.
For the reconnaissance phase specifically: Shodan and Censys are the authoritative tools for external exposure assessment from the attacker's perspective — every CTEM program should include regular review of what these platforms see for the organization's IP ranges and domain infrastructure. SpyCloud leads for credential exposure assessment against dark web sources. GreyNoise provides context on which discovered exposures are actively being scanned by threat actors.
CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative reference for internet-facing CVEs that ransomware operators are actively exploiting — it should be the primary cross-reference for any internet-facing system vulnerability assessment.
The full vendor rankings are in the 2026 Stackcurve CTEM CURVE™ Report — free to download.
The Gap Most Buyers Miss
Most organizations have some exposure visibility and some vulnerability management capability. What they rarely have is a structured simulation of the specific pre-attack assessment that ransomware initial access brokers perform.
VPN and remote access vulnerabilities are the highest-priority ransomware initial access vector. The 2024 and 2025 ransomware incidents traced to known CVEs were disproportionately concentrated in VPN and remote access products: Ivanti Connect Secure (CVE-2024-21887, CVE-2024-21888), Fortinet FortiGate, Palo Alto GlobalProtect, and Cisco ASA. These products are internet-facing by design, they authenticate users to the internal network, and they run software that requires patching like any other application. But they are frequently excluded from normal vulnerability management schedules — treated as network infrastructure rather than endpoints — and therefore often run unpatched versions longer than other systems. A CTEM program that does not specifically include VPN and remote access product CVE assessment has a gap that matches the most common ransomware initial access vector.
Credential exposure assessment must cover the systems attackers target, not just general breach monitoring. Dark web monitoring that alerts when employee credentials appear in breach data is useful. It becomes materially more valuable when the credential exposure is cross-referenced against the systems accessible with those credentials. An executive's credentials appearing in breach data is a medium-priority finding. An executive's credentials appearing in breach data, combined with those credentials being valid for the corporate VPN, which lacks MFA enforcement, is a critical finding that requires immediate remediation. The correlation between credential exposure and accessible systems is the step most organizations skip.
DMARC, DKIM, and SPF configuration signals phishing susceptibility to attackers.
Reconnaissance-focused threat actors check email authentication configuration before investing in phishing campaigns — poorly configured or missing DMARC, DKIM, and SPF records indicate that phishing from spoofed company domains is likely to succeed and is unlikely to be blocked. This is a low-effort check that influences attacker target selection. Organizations with missing or enforcement-mode DMARC records are more attractive phishing targets than those with p=reject DMARC policies in place. Email authentication configuration should be part of CTEM external exposure assessment.
Exposed RDP remains a first-tier initial access vector despite years of guidance. Internet-facing Remote Desktop Protocol (TCP 3389) is simultaneously the most well-known ransomware initial access vector and one of the most consistently present findings in external attack surface assessments. The 2024 CISA and FBI joint advisories on ransomware prevention continue to list RDP exposure in the top three initial access methods. The persistence of this finding is not explained by organizations being unaware of the risk — it is explained by the gap between policy ("RDP should not be internet-facing") and operational reality ("someone opened RDP for a specific reason and it was never closed"). EASM continuous monitoring, not point-in-time assessment, is the only reliable way to catch new RDP exposures before attackers do.
Software inventory from passive sources tells attackers which CVEs to try. Censys, Shodan, and similar passive reconnaissance platforms fingerprint internet-facing software versions. An organization running Ivanti Connect Secure 9.1R14 on its external VPN gateway is, in effect, publicly advertising that it is vulnerable to CVE-2024-21887. Attackers use this information to prioritize targets — organizations running recently announced vulnerable software versions are actively targeted in the days following CVE disclosure before patches are applied. CTEM programs must include rapid assessment of internet-facing software versions against current KEV catalog entries, with SLAs measured in days, not weeks, for internet-facing systems.
Questions Your Buying Team Should Be Asking
1. Can your platform simulate the specific reconnaissance techniques used by ransomware initial access brokers against our external attack surface? This is not a standard BAS question. The IAB reconnaissance workflow is specific: port scanning for known initial access vectors (RDP, VPN ports), software version fingerprinting against current exploit databases, credential validation against identified external-facing portals, and dark web credential availability assessment. Ask the vendor to map their platform's capabilities to each of these steps and identify which require integration with complementary tools (EASM, credential monitoring).
2. How does your platform validate whether discovered credentials are valid for current access to our external systems? The distinction between "this credential appears in breach data" and "this credential successfully authenticates against your VPN portal today" is the operational distinction that matters for ransomware risk. Some platforms perform this validation automatically, some require manual testing, and some do not perform it at all. Understand which capability you are purchasing and whether it is appropriate to the operational environment — automated credential validation may require explicit authorization and scoping.
3. What is the coverage and freshness of your VPN/remote access CVE detection, and how quickly do you flag newly disclosed CVEs against our internet-facing systems? Ransomware operators move fast after CVE disclosure. The Ivanti Connect Secure CVEs in January 2024 were exploited at scale within days of public disclosure. Ask vendors what the latency is between NIST NVD publication of a CVE and detection in your internet-facing systems, and what the alerting mechanism is for critical new disclosures.
4. How do you integrate with CISA KEV to prioritize internet-facing vulnerabilities? The CISA Known Exploited Vulnerabilities catalog is the authoritative list of CVEs with confirmed active exploitation. Every CTEM platform should support KEV cross-referencing natively. Ask specifically how KEV is used in your platform's prioritization logic: is KEV status a hard-priority flag that automatically elevates findings regardless of CVSS score, or is it one input among many? For internet-facing systems, KEV status should be a mandatory escalation factor.
5. Can you model what a specific ransomware group — such as Akira, Play, or RansomHub — would find if they targeted our organization today? Threat actor-specific simulation is the highest maturity level of BAS. The platforms that map their simulations to documented threat actor TTPs (using MITRE ATT&CK threat group profiles and current threat intelligence) allow organizations to answer a more specific question than "are we defensible against generic attack techniques." If a specific ransomware group is relevant to your industry or region, ask the vendor to demonstrate a simulation of that group's known TTPs against a representative environment.
The Stackcurve Take
The ransomware pre-attack assessment is not a novel security practice — it is what penetration testers have always done, applied to the specific threat model that accounts for the largest share of enterprise security incidents. The novelty is in applying it continuously, at the frequency required to match the pace of ransomware operator reconnaissance, rather than as an annual point-in-time exercise.
The CTEM framework operationalizes this as continuous scope, continuous discovery, and continuous validation — which is exactly the cadence that IAB reconnaissance operates at. Initial access brokers do not assess your organization once per year. They assess it when new CVEs are disclosed for your VPN software, when new credential dumps hit dark web markets, and when new attack tooling makes previously protected systems accessible. The defense that matches them operates on the same cadence.
The Change Healthcare incident should have produced a permanent change in how enterprises assess remote access portal security. The combination of no MFA, accessible from the internet, and valid credentials available in breach markets is a compound exposure that is entirely detectable through CTEM workflows before it becomes a $3 billion incident.
The 2026 Stackcurve CTEM CURVE™ Report covers the ransomware resilience validation category, including detailed assessments of BAS platforms, credential exposure monitoring, and the CTEM workflows that simulate IAB reconnaissance. Download it free →
Stackcurve Advisory Briefs are independent research. No vendor pays for placement, tier assignment, or editorial influence. The CURVE™ methodology is disclosed in full at stackcurve.net/research/methodology.