Ransomware Readiness Assessment: A Practical Checklist for Security Teams
A ransomware readiness assessment measures whether your organisation can prevent, detect, contain and recover from a ransomware attack โ before one tests it for you. The controls that separate a contained incident from a catastrophic one are well understood and largely the same across every real case: offline/immutable backups that are actually restore-tested, network segmentation that limits lateral movement, phishing-resistant MFA on all remote and privileged access, endpoint detection with someone watching it, a written and rehearsed incident-response plan, and least-privilege that stops one compromised account becoming domain-wide. This checklist groups those into six domains you can self-score, with the failure mode each one prevents.
A ransomware readiness assessment answers one question: if an attacker got a foothold in your environment today, would it be a contained incident or a business-ending one? The controls that decide the answer are remarkably consistent across real cases โ which is good news, because it means readiness is measurable. This is a vendor-neutral checklist grouped into six domains you can score yourself against, with the specific failure each control is there to prevent.
1. Backups you have actually restored from
This is the control that most reliably changes the outcome. Modern ransomware operators hunt for backups and delete them before triggering encryption, so an online backup reachable with production credentials offers little protection against this threat. What you need: offline or immutable copies (object-lock, air-gapped, or a separate trust domain), and โ the part most organisations skip โ a documented, recently-executed restore test with a known recovery-time objective. A backup you have never restored from is a hope, not a control.
2. Segmentation that limits lateral movement
Most ransomware damage comes from lateral movement after the initial foothold โ one compromised laptop becoming domain-wide encryption. Flat networks make that trivial. Segment by trust level, restrict east-west traffic, isolate backup infrastructure and domain controllers, and ensure workstations cannot freely reach each other. The test: from a standard user endpoint, how much of the environment is directly reachable?
3. Phishing-resistant identity
Ransomware still overwhelmingly begins with a phished credential or a token relayed through an adversary-in-the-middle kit. MFA on all remote and privileged access is table stakes; phishing-resistant MFA (FIDO2/passkeys) on those accounts removes the most-used entry path entirely. Pair it with least privilege so a single compromised account cannot reach crown-jewel systems.
4. Detection someone is actually watching
Endpoint detection and response (EDR) that alerts to no one is not detection. Readiness means EDR deployed on endpoints and servers, with coverage gaps known, and either an internal SOC or a managed service watching and empowered to act out-of-hours โ because ransomware crews deliberately trigger on weekends and holidays.
5. A response plan you have rehearsed
The worst time to design your response is during the incident. A ransomware-specific plan names who declares the incident, who can authorise isolating production, where the offline restore runbook lives, how you communicate when email and identity are down, and when and how legal, insurer and law enforcement get involved. The test is a tabletop โ walk it before an attacker does.
6. Least privilege and attack-surface hygiene
Exposed RDP, unpatched internet-facing services and over-privileged service accounts are the recurring initial-access and escalation paths. Reducing standing privilege, removing direct internet exposure of remote-access services, and keeping perimeter systems patched shrinks both the ways in and the blast radius once inside.
Score yourself, then close the biggest gap
Rate each of the six domains red/amber/green. The point is not the number โ it is finding the one red domain that would decide your worst day, and fixing it first. For most organisations that is untested backups or flat networks.
Model the financial side with the free Breach Cost calculator โ, pressure-test your response in the ransomware simulation, and read how ransomware crews actually operate in our ransom-economy series.
Frequently asked questions
What is a ransomware readiness assessment? A structured review of your ability to prevent, detect, contain and recover from ransomware โ walking the specific controls (backups, segmentation, identity, detection, response, privilege) and finding which are missing or untested.
What is the single most important control? Restore-tested offline/immutable backups โ attackers destroy reachable backups before encrypting, so an online backup is not protection against this threat.
How often should we assess? At least annually and after any material change; the highest-value exercise is a full tabletop.
Does insurance replace readiness? No โ insurers require these same controls, and weak ones raise premiums or void claims.
Ready to practise the decisions these articles describe?
Run a free War Room โ