SecurityOctober 2024 · 4 min read

Why unmanaged devices are still the #1 ransomware entry point

Microsoft research puts unmanaged devices behind 80-90% of successful ransomware attacks. Here's why asset visibility, not just antivirus, is the real fix.

By AssetPilot Team

Every ransomware post-mortem reads the same way: an attacker got in through a device nobody was watching. Microsoft's own threat intelligence puts the figure at 80-90% of successful ransomware attacks originating from unmanaged devices and IBM's Cost of a Data Breach report found unmanaged assets involved in roughly 35% of all breaches. The pattern isn't sophisticated malware, it's a laptop, a forgotten test server, or a contractor's device that was never enrolled anywhere.

Why do unmanaged devices keep slipping through?

Endpoint protection and patch management only work on devices they know about. A machine that was never enrolled in Intune, never added to the asset register, or was quietly replaced without a formal check-in simply doesn't exist as far as the security stack is concerned. It still has a network connection and access to whatever the previous user had; it just has none of the controls.

Where do these blind spots usually come from?

  • Devices bought outside the normal procurement process, so IT never had a reason to register them.
  • Old hardware retired from management but never formally decommissioned or wiped.
  • New starters issued a spare laptop from a drawer while the 'proper' one is on order and the spare is never logged.
  • Contractor and third-party devices connecting to shared resources without ever going through onboarding.

None of these are exotic attack techniques, they're gaps in the asset register. Closing them isn't primarily a security-tooling problem; it's an inventory problem. A register that's reconciled against Intune and Autopilot on a schedule, rather than trusted on faith, surfaces exactly these gaps before an attacker finds them first.

Know exactly what you own, who has it and what it costs.