Cyber Epidemiology for Ransomware

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Ransomware is often treated as a detection problem. Yet the incidents with the greatest operational impact unfold like outbreaks: a single foothold propagates through identities, administrative tools, and shared services while responders make time-critical decisions with limited visibility. This paper proposes an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In the cyber SEIR ontology, Exposed represents latent compromise and staging, often overlapping the operational notion of dwell time, in which a foothold exists but has not yet produced confirmed secondary compromise, whereas Infectious denotes active lateral propagation. Grounded in ISO 5477:2023 public health emergency preparedness and response (PH-EPR) information management guidance and the United Nations Office for Disaster Risk Reduction and International Science Council (UNDRR-ISC) 2025 Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information (EEIs) to support cross-incident comparison. We treat the basic and effective reproduction numbers (R0, Re) as directional, near-real-time decision aids for security operations centers (SOCs) and explicitly separate propagation state (SEIR) from observation status (detected/undetected) to avoid conflating detection capability with spread dynamics. Using publicly reported incidents (WannaCry, NotPetya, SolarWinds, and MGM/Caesars) for illustration, we show how outbreak-style measurements translate telemetry into earlier decisions about isolation, credential containment, and restoration sequencing. We also derive simple protection threshold heuristics (targeting Re < 1) and provide a tool agnostic playbook card that links EEIs to explicit action triggers. The frameworks primary contribution is a shared operational language that connects technical telemetry to containment decisions under resource constraints.

Loading executive summary...

LINK COPIED TO CLIPBOARD