Ransomware Readiness Deficit Widens as Machine Identities Become Key Target
The gap between ransomware threats and an organization’s ability to defend against them continues to grow, with a significant blind spot emerging around the security of machine identities. A recent report from Ivanti reveals a widening “Cybersecurity Readiness Deficit” across all threat categories, particularly concerning ransomware attacks. While 63% of security professionals view ransomware as a high or critical threat, only 30% feel “very prepared” to defend against it – a 33-point gap that has increased from the previous year.
The Growing Preparedness Gap
Ivanti’s 2026 State of Cybersecurity Report highlights a consistent trend: organizations are falling further behind in their ability to defend against evolving cyber threats. This deficit isn’t limited to ransomware; it spans phishing, software vulnerabilities, API vulnerabilities, supply chain attacks, and even encryption issues. Daniel Spicer, Ivanti’s Chief Security Officer, coined this phenomenon the ‘Cybersecurity Readiness Deficit,’ emphasizing the imbalance between security investments and actual defense capabilities.
The Hidden Risk of Machine Identities
A critical component of this growing vulnerability lies in the lack of attention paid to machine identities – the non-human accounts used by applications and services. CyberArk’s 2025 Identity Security Landscape report reveals that organizations have 82 machine identities for every human user, with 42% of these possessing privileged or sensitive access. These machine identities often operate without the same level of scrutiny as human accounts, creating a significant entry point for attackers.
Playbook Shortcomings and the Ransomware Countdown
Current ransomware preparation guidance, such as Gartner’s April 2024 research note “How to Prepare for Ransomware Attacks,” focuses heavily on resetting user and host credentials during containment. However, these playbooks largely overlook crucial elements like service accounts, API keys, tokens, and certificates. This oversight leaves organizations vulnerable to attacks that exploit these often-unmanaged credentials. Gartner warns that ransomware incidents put organizations on a “countdown timer,” with recovery costs potentially reaching 10 times the ransom amount, and deployment occurring within one day of initial access in over 50% of cases.
Why Machine Identities Are Overlooked
Several factors contribute to the neglect of machine identity security:
- Lack of Inventory: Organizations often lack a comprehensive inventory of their machine identities, making it impossible to effectively manage and secure them.
- Insufficient Detection: Anomalous behavior from machine identities doesn’t typically trigger the same alerts as compromised user accounts.
- Stale Credentials: Service accounts and API keys are often left unrotated for extended periods, becoming easy targets for attackers.
- Network Isolation Fallacy: Simply isolating a compromised machine from the network doesn’t revoke the trust relationships established by its machine identities.
The Economic Imperative for Improved Security
The financial consequences of ransomware attacks are substantial. CrowdStrike data indicates the average ransomware downtime cost is $1.7 million per incident, rising to $2.5 million for public sector organizations. Despite this, approximately 54% of organizations report they would likely pay a ransom if attacked, reflecting a lack of effective containment alternatives. 93% of organizations that pay a ransom still experience data theft, and 83% are subsequently attacked again.
Looking Ahead: Governing Autonomous Identities
The rise of agentic AI will further exacerbate the problem, as each autonomous agent creates modern machine identities that require governance. Organizations that proactively build machine identity inventory, detection rules, and containment procedures into their ransomware playbooks will be better positioned to address both current and future threats.
Addressing the Cybersecurity Readiness Deficit requires a shift in focus towards comprehensive identity security, with a particular emphasis on securing the often-overlooked world of machine identities.
Related reading