Compliance Node Overview
MITRE ATT&CK T1486 covers adversary encryption of victim data and demand for ransom, the canonical ransomware behaviour responsible for the majority of catastrophic enterprise cyber incidents. LockBit, BlackCat/ALPHV, Cl0p, Akira, and Royal remain the dominant ransomware-as-a-service brands as of 2025. Compliance obligations span NIST SP 800-53 CP-9 (backup), CP-10 (recovery), SI-7 (integrity), HIPAA 164.308(a)(7), NIS2 Article 21(2)(c), DORA Articles 12-13, SEC Cybersecurity Risk Management Rule, and US Treasury OFAC ransomware payment advisory.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1486/
SHA-256 integrity: a51e1541e45fb20a41cab4da29a52ae2143679526b2c58c3244e1edb336d9499
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1486: Data Encrypted for Impact (https://attack.mitre.org/techniques/T1486/)
- CISA #StopRansomware Guide: comprehensive ransomware defence and response playbook
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access