ipfour

Toolkit · Security · about 5 minutes

Ransomware Resilience Check

Weighted towards recovery rather than prevention. Everyone believes they will not be hit; the organisations that survive are the ones whose backups were out of reach when it happened.

18 questions. Nothing is sent anywhere as you answer — the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.

0 of 18 answered0%

Recovery capability

What you can get back, and how quickly.

Is at least one backup copy offline, immutable, or in a separate account that production credentials cannot reach?

Modern ransomware deletes the backups first. A backup reachable from a compromised domain admin account is not a backup.

Has a full restore been tested in the last 12 months, with the time it took recorded?

Do you know your recovery time and recovery point objectives, and has anyone checked they are achievable?

Are backups monitored, with failures alerting to a person?

Is there a documented rebuild order — which systems come back first, and what depends on what?

Initial access

The routes attackers actually use.

Is MFA enforced on all remote access — VPN, RDP, and every cloud and email service?

Is RDP either closed to the internet entirely or reachable only through a gateway with MFA?

Are internet-facing systems patched within 14 days for critical vulnerabilities?

Is email filtering in place for malicious attachments and links, with staff trained to report?

Limiting the blast radius

What one compromised machine can reach.

Are administrative accounts separate from daily-use accounts, with no domain admin used for routine work?

Is the network segmented so that one compromised workstation cannot reach servers and backups directly?

Is endpoint detection and response deployed, with someone actually watching the alerts?

Are local administrator passwords unique per device rather than shared?

Response readiness

What happens in the first hour.

Is there an incident response plan that is available offline, if your systems are encrypted?

A plan stored only on the file server that has just been encrypted is not available.

Do you know who to call — incident response retainer, insurer, legal — before you need them?

Has the plan been exercised with the people who would run it, including non-technical leadership?

Do you have a way to communicate if email and Teams are unavailable?

Does your cyber insurance policy's requirements match what you actually have in place?

More in the toolkit