The Problem: Boards See the Explosion, Not the Fuse
Terrell Cox, Microsoft’s deputy CISO, points out something that should make every hospital IT leader uncomfortable: ransomware briefings delivered to boards typically start at the moment files get encrypted. By that point, the attack is over. The scumbag has already won.
The encryption event — the part that gets the board’s attention — is the final stage of a sequence that started weeks earlier. Someone bought network access from an initial access broker. Credentials got harvested and written to disk. Lateral movement tools were copied to network shares across the environment. Reconnaissance scripts ran and wrote their output to files. The ransomware binary finally landed on systems throughout the network.
Every single one of those stages involves writing files to Windows systems.
The article describes the Fox Tempest operation that Microsoft disrupted — a service that sold fraudulent code-signing certificates to ransomware groups. Customers included Rhysida, Akira, INC, Qilin, and BlackByte, several of which attacked hospitals. The malware came back with valid signatures that made it look legitimate to Windows.
Here’s what matters: a valid code-signing certificate gets the malware past signature checks, but it doesn’t change the fundamental requirement that the malicious file has to be written to disk before it can execute.
How FileSure Stops This at Stage One
FileSure operates at the Windows kernel level via a filter driver that intercepts file system operations before they complete. You define which programs are authorized to write executable files to your systems. Everything else gets blocked.
A specific rule configuration that applies here:
- Operations: File Create, File Write
- File name filter: *.exe, *.dll, *.scr, *.bat, *.ps1, *.vbs
- Authorized programs: Your software deployment tools, Windows Update, approved installers
- Action: Block and alert on any write attempt from unauthorized programs
When the initial payload arrives — whether it’s a phishing attachment opened in Outlook, a file downloaded through a browser, or a binary pushed through compromised RDP — FileSure intercepts the write operation. The program attempting the write (Outlook, Chrome, mstsc.exe, or whatever delivery mechanism the attacker used) is not on the authorized list. The write is blocked. The file never lands on disk.
No payload on disk means no execution. No execution means no credential harvesting, no lateral movement, no encryption. The attack stops before it starts.
This works on ransomware variants nobody has seen before, because FileSure doesn’t try to recognize the threat. It simply enforces the rule: unauthorized programs cannot write executables to this system. Signature-based tools have to wait for the vendor to analyze the new variant and push an update. FileSure blocks it the same way it blocked last year’s ransomware.
The article mentions that sophisticated attacks no longer require sophisticated attackers — access is purchased, phishing kits are sold by subscription, and AI has reduced reconnaissance costs. That’s all true. But every one of those attacks still requires writing files to Windows systems at multiple stages. Control the file operations and you control the attack surface.
Cox argues that boards should fund interruption of the attack sequence rather than just recovery capability. FileSure is exactly that kind of control — it interrupts at the earliest possible stage, before damage occurs, on every Windows system you have including the legacy ones running your medical devices.
Try It On Your Systems
FileSure runs on all Windows versions from XP through Windows 11 and Server 2003 through Server 2022. If you have medical imaging systems, lab equipment, or pharmacy systems locked to older Windows versions — the kind of systems that modern endpoint security tools won’t even install on — FileSure protects those too.
Start a free 21-day trial at bystorm.com. Install it, watch it block our test file that mimics ransomware behavior, then open a Word document and see the access get logged. That’s the product. It works exactly like that every time.
Source: Hospital boards hear about ransomware too late in the attack
Category: Ransomware
Tags: ransomware, healthcare, hospital security, kernel filter driver, file system security, fox tempest, code signing, initial access broker