Microsoft Stops Ransomware in 128 Seconds with New Defender Response Action
The threat of ransomware attacks is far from over, despite what some might think.
According to IBM, reported ransomware incidents have risen year-on-year, with attackers increasingly using AI to automate and scale their operations.
In fact, BlackFog has confirmed that attacks targeting the service sector have increased by 221% from Q1 to Q2 this year.
In response, Microsoft claims its new Defender response action can stop ransomware attacks in just 128 seconds using device isolation.
This involves isolating the compromised device within seconds of detection, blocking external network connectivity while maintaining access to security services.
The goal is to break the lateral movement opportunity and give security teams time to contain the threat.