The Containment Era is here. →Explore

Executive Summary

In August 2025, the State of Nevada experienced a significant ransomware attack that disrupted the operations of over 60 state agencies, including those responsible for health and public safety. Attackers gained unauthorized access to internal systems, likely through a compromised credential or exposed remote access service. They rapidly deployed ransomware across the network, encrypting critical data and rendering multiple state services inaccessible while officials initiated emergency response protocols. The impact included delayed or suspended services for residents and a comprehensive recovery process lasting several weeks.

This incident underscores a persistent trend: ransomware threat actors are increasingly targeting government entities, leveraging lateral movement and broad access to cripple essential public services. As attacks escalate and recovery costs rise, organizations face greater pressure to modernize segmentation, detection, and incident response strategies.

Why This Matters Now

Ransomware groups are intensifying their focus on government infrastructure, where disruptions cause outsized societal impact and prompt fast ransom negotiations. As attackers increasingly exploit lateral movement and unsegmented networks, urgent investment in zero trust architecture and proactive anomaly detection is required to protect critical functions.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack highlighted gaps in network segmentation, east-west traffic monitoring, and real-time threat detection, all critical for NIST 800-53 and HIPAA compliance.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, east-west traffic controls, and egress policy enforcement would have detected or limited attacker movement, command & control, and ransomware propagation. CNSF controls, especially workload segmentation and inline policy enforcement, could have significantly reduced the blast radius and prevented data loss or widespread encryption.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline access policy and real-time inspection could have blocked risky connections or untrusted entry attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Role- and identity-based microsegmentation would have restricted movement between workloads and sensitive resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west policy controls stop unauthorized workload-to-workload and inter-region communication.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Outbound filtering and application-aware controls block suspicious C2 traffic.

Exfiltration

Control: Multicloud Visibility & Control

Mitigation: Centralized monitoring and policy enforcement alert on and block unauthorized data exfiltration.

Impact (Mitigations)

Real-time threat and anomaly detection may have alerted on ransomware tactics and initiated response before widespread encryption.

Impact at a Glance

Affected Business Functions

  • Health Services
  • Public Safety
  • Licensing
  • Background Checks
Operational Disruption

Estimated downtime: 28 days

Financial Impact

Estimated loss: $1,500,000

Data Exposure

Evidence indicates that data was moved outside of Nevada’s state networks by malicious actors during the ransomware attack. The specific nature of the data has not been identified, but there is no current evidence that personal information was compromised.

Recommended Actions

  • Enforce Zero Trust segmentation and least privilege principles to prevent attacker lateral movement.
  • Implement east-west traffic security with fine-grained policies for workload-to-workload flows.
  • Apply inline IPS and egress filtering to detect and block command & control and exfiltration activity.
  • Increase centralized visibility and automated enforcement across multi-cloud and hybrid environments.
  • Continuously baseline network traffic patterns and employ real-time anomaly detection for rapid incident response.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image