Episode 114 -- The New Playbook for Ransomware Preparedness
In Episode 114 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Mark Lance, Senior Vice President of Digital Forensics, Incident Response, and Threat Intelligence at GuidePoint Security, to examine what a more organized, better-resourced ransomware adversary means for organizational preparedness. Dr. Chatterjee opens with a striking data point: roughly 69 ransomware groups were active in a given quarter in early 2025, but by the second quarter of 2026 that number had grown to 91 distinct groups, with new groups emerging about five times faster than existing ones disappear. Ransomware, he observes, has become a fluid, professionalized market with its own supply chains and support desks.
Lance, who brings 26 years of cybersecurity experience and 16 years in incident response, traces how ransomware evolved from opportunistic attacks on individual consumers into targeted, persistent campaigns against organizations — progressing from encryption to attacks on backups, then to double extortion through data theft, and in some cases triple extortion through DDoS threats. He explains how ransomware-as-a-service platforms, often more sophisticated than the environments they target, have turned cybercrime into a highly profitable enterprise. The conversation then turns to a real incident in which GuidePoint found not one but two threat actors inside a client's network, and Lance walks through how his team used a carefully planned containment and eradication strategy — including corrupting data an attacker was exfiltrating from the CFO's mailbox — rather than a knee-jerk response that could have tipped off the adversary.
To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-114-the-new-playbook-for-ransomware-preparedness/
In Episode 114 of the Cybersecurity Readiness Podcast Series, Dr. Dave Chatterjee is joined by Mark Lance, Senior Vice President of Digital Forensics, Incident Response, and Threat Intelligence at GuidePoint Security, to examine what a more organized, better-resourced ransomware adversary means for organizational preparedness. Dr. Chatterjee opens with a striking data point: roughly 69 ransomware groups were active in a given quarter in early 2025, but by the second quarter of 2026 that number had grown to 91 distinct groups, with new groups emerging about five times faster than existing ones disappear. Ransomware, he observes, has become a fluid, professionalized market with its own supply chains and support desks.
Lance, who brings 26 years of cybersecurity experience and 16 years in incident response, traces how ransomware evolved from opportunistic attacks on individual consumers into targeted, persistent campaigns against organizations — progressing from encryption to attacks on backups, then to double extortion through data theft, and in some cases triple extortion through DDoS threats. He explains how ransomware-as-a-service platforms, often more sophisticated than the environments they target, have turned cybercrime into a highly profitable enterprise. The conversation then turns to a real incident in which GuidePoint found not one but two threat actors inside a client's network, and Lance walks through how his team used a carefully planned containment and eradication strategy — including corrupting data an attacker was exfiltrating from the CFO's mailbox — rather than a knee-jerk response that could have tipped off the adversary.
Analyzed through Dr. Chatterjee's Commitment–Preparedness–Discipline (CPD) Framework, the discussion frames the incident as a governance failure rather than simply a tools failure: the victim organization had 24x7 managed detection and response, centralized logging, and endpoint solutions, yet was treating them as compliance checkmarks. The episode closes with practical guidance on threat modeling, foundational controls, rehearsed incident response plans, “destroy your business” scenarios to earn leadership commitment, and the value of sharing hard-won lessons across the defender community.
To access and download the entire podcast summary with discussion highlights - https://www.dchatte.com/episode-114-the-new-playbook-for-ransomware-preparedness/
Connect with Host Dr. Dave Chatterjee
LinkedIn: https://www.linkedin.com/in/dchatte/
Website: https://dchatte.com/
Books Published
Cybersecurity Readiness: A Holistic and High-Performance Approach
Articles & Cases Published
Chatterjee, D. (2026). The Cryptographic Reckoning: Why Quantum Readiness Begins with Agility, Not Algorithms, The INFORMS Analytics Magazine, June 26, 2026
Chatterjee, D. (2026). The New Digital Fragility: How AI-Enhanced Cyber Threats Are Reshaping Operational Resilience, The INFORMS Analytics Magazine, March 4, 2026
Chatterjee, D. (2026). Root: Automating the Remediation Gap, Ivey Publishing, Jan 7, 2026.
Chatterjee, D. and Leslie, A. (2024). “Ignorance is not bliss: A human-centered whole-of-enterprise approach to cybersecurity preparedness,” Business Horizons, Accepted on Oct 29, 2024.
Chatterjee, D. (2023). “Mission critical – How American Cancer Society successfully and securely migrated to the cloud amid the pandemic,” I by IMD, March 13, 2023.
Chatterjee, D. (2022). “Preventing security breaches must start at the top,” I by IMD, September 28, 2022, Institute for Management Development, Lausanne, Switzerland
Benz, M. and Chatterjee, D. (2020). “Calculated Risk? A Cybersecurity Evaluation Tool for SMEs,” Business Horizons, available online from May 4, 2020
Chatterjee, D. (2019). “Should Executives Go To Jail Over Cyber Attacks,” Journal of Organizational Computing and Electronic Commerce, Vol 29, Issue 1, pp. 1-3.
Abraham, C., Chatterjee, D., and Sims, R. (2019). “Muddling through cybersecurity: Insights from the U.S. healthcare industry,” Business Horizons, July 2019.