LKQ Corporation’s Security Chief on the New Rules of Cyber Resilience

Ransomware has evolved from a niche cybercrime into one of the most consequential threats to global digital infrastructure. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of all breaches, a 37% increase over its 2024 findings, with small and midsize businesses bearing the brunt, accounting for 88% of ransomware-related breaches. According to the US Cyber Threat Intelligence Integration Center, the largest known cyber ransom in history, $75 million, was paid to the Dark Angels group in 2024, extracted from a Fortune 50 company. The threat is also accelerating: US ransomware attacks surged 50% in the first ten months of 2025, with over 5,000 reported incidents. Cybersecurity Ventures projects ransomware will cost victims over $20 billion per month by 2031 — a staggering escalation from under $1 billion annually a decade ago.

Gargi Chakraborty of CXO Chapter, spoke with Abhik Basak, Global Security Director at LKQ Corporation, on ransomware’s evolution, AI-driven threats, and why identity-centric resilience is now critical for enterprise security.

Excerpts:

Q. How have ransomware tactics evolved and what new defensive priorities should CISO’s adopt?Ransomware has evolved from opportunistic, high-volume attacks into highly coordinated, enterprise-scale extortion operations. Early campaigns, such as those inspired by CryptoLocker and the global outbreaks of WannaCry, relied on mass phishing emails or automated worm-like propagation to encrypt endpoints and demand relatively modest payments.

Today, ransomware has become a professionalized criminal ecosystem characterized by targeted intrusions, data theft, and multi-layered extortion strategies. As tactics mature, Chief Information Security Officers (CISOs) must recalibrate their defensive priorities from prevention-centric models to resilience-driven security programs.

Q. How can CISOs recalibrate their defensive priorities? What should be the “new” focus for resilient-driven security programs?

As security leaders we must look at six key areas:

1. Assume breach and prioritize resilience: Prevention alone is insufficient. CISOs must design for continuity under compromise. This includes immutable, offline, and regularly tested backups; segmented networks; and well-rehearsed incident response playbooks. Recovery time objectives (RTOs) should be board-level metrics.

2. Strengthen identity and access governance: This is because modern ransomware exploits privileged access, identity security is paramount. Enforce multi-factor authentication everywhere, adopt least-privilege access models, monitor for anomalous credential use, and implement privileged access management (PAM) with session recording and just-in-time elevation.

3. Enhance detection through behavioral analytics: Deploy endpoint detection and response (EDR) and extended detection and response (XDR) platforms that focus on anomalous behavior rather than signatures. Integrate telemetry across endpoints, networks, and cloud environments to detect lateral movement and data exfiltration early.

4. Secure the supply chain: Conduct rigorous third-party risk assessments, require security attestations, monitor vendor access continuously, and implement zero-trust principles that limit implicit trust in partner connections.

5. Elevate executive and board engagement: Ransomware is now a strategic business risk. CISOs must align cybersecurity strategy with enterprise risk management, legal, communications, and compliance functions. Tabletop exercises should simulate data-leak scenarios, regulatory notification timelines, and extortion negotiations.

6. Invest in threat intelligence and proactive disruption: Proactive monitoring of dark web leak sites, credential dumps, and ransomware affiliate chatter enables earlier intervention. Collaboration with Information Sharing and Analysis Center (ISAC) and law enforcement enhances collective defense.

Q. Are AI-driven attacks and cloud misconfigurations creating conditions for next gen ransomware?

AI-driven attack capabilities combined with widespread cloud misconfigurations are creating highly favorable conditions for next-generation ransomware. The convergence of automation, scale, and systemic complexity is reshaping both the speed and impact of attacks.

Hyper-personalized phishing and social engineering: Generative AI enables threat actors to craft highly convincing spear-phishing emails, business email compromise (BEC) lures, and even synthetic voice or video impersonations of executives. What once required manual reconnaissance can now be automated at scale, improving initial access success rates.

Automated reconnaissance and vulnerability discovery: AI tools can scan internet-facing infrastructure, analyze code repositories, and identify misconfigurations or exposed credentials faster than human operators. This accelerates the “time to compromise,” particularly in complex hybrid-cloud environments.

Adaptive malware: Emerging ransomware variants are experimenting with runtime decision-making, adjusting encryption behavior based on endpoint defenses, privilege level, or data sensitivity. While still early-stage, AI-enhanced tooling could enable ransomware to evade behavioral detection by dynamically modifying tactics.

Overprivileged identities: Cloud environments frequently suffer from excessive permissions. If attackers obtain a single compromised token or API key, they may inherit broad access across storage, compute, and backup systems—creating ideal conditions for ransomware deployment or data exfiltration.

The dangerous synergy lies in three dynamics:

  1. Speed – AI accelerates reconnaissance and initial access.
  2. Scale – Cloud environments centralize high-value assets.
  3. Privilege – Misconfigured identity systems enable lateral expansion across environments.

To counter this convergence, security leaders should prioritize:

Identity-centric security.
Implement least privilege, continuous access evaluation, just-in-time privilege elevation, and mandatory multi-factor authentication for all cloud and SaaS environments.

Cloud security posture management (CSPM).
Automate detection and remediation of misconfigurations. Continuous compliance scanning must replace periodic audits.

Immutable, cross-boundary backups.
Ensure backups are isolated in separate accounts or tenants, with object lock or immutability controls enabled.

AI-powered defense.
Leverage behavioral analytics and anomaly detection to identify abnormal API usage, unusual data transfer patterns, or privilege escalation attempts.

Zero Trust architecture.
Assume breach. Segment workloads and enforce strict identity verification across users, devices, and services.

Q. What single capability would most improve resilience against large scale cyber extortion events?

If forced to choose a single capability that most improves resilience against large-scale cyber extortion events, it would be:

Enterprise-wide, identity-centric Zero Trust with enforced least privilege

Identity control is the single most powerful lever against modern ransomware and cyber extortion. This includes:-

  • Strict Least Privilege by Default
  • Just-in-Time (JIT) Privilege Elevation
  • Universal, Phishing-Resistant MFA
  • Continuous Session and Behavior Monitoring
  • Separation of Backup and Identity Control Planes

Leave a Reply

Your email address will not be published. Required fields are marked *