Ransomware Response Reframed as Epidemiology, Using R0 and Re as Near-Real-Time Containment Triggers
Arguing that the most disruptive ransomware incidents behave like outbreaks rather than detection problems, this framework adapts the SEIR model to incident management, where Exposed captures latent compromise and staging including pre-confirmation dwell time and Infectious captures active lateral propagation. It deliberately separates propagation state from observation status so responders stop conflating spread dynamics with detection capability, and uses basic and effective reproduction numbers as directional decision aids for SOCs, with protection-threshold heuristics aimed at driving Re below 1. Grounded in ISO 5477:2023 and the 2025 UNDRR-ISC Hazard Information Profiles, it is illustrated against WannaCry, NotPetya, SolarWinds, and the MGM and Caesars incidents.
↳ Follow the thread