Principle Security Principle Security.

Resilience

Could you recover from ransomware?

Six questions on the controls that actually decide whether ransomware is an incident or a catastrophe — backups, recovery testing, segmentation, identity, a tested plan, and detection.

6 questions ~2 minutes No signup Runs in your browser

Answer honestly — the point is to find the gap before an attacker does. Your result breaks down question by question and puts the most dangerous gaps first.

1
Backups: do you have offline or immutable copies attackers can't reach?
2
Restore testing: when did you last do a full restore from backup?
3
Segmentation: could an infection on one machine spread flat across the network?
4
Identity: is MFA enforced on email, VPN, and admin access?
5
Do you have an incident response plan you've actually rehearsed?
6
Detection: do you have EDR/MDR that would catch and contain an active intrusion?

Why this matters

Ransomware doesn't beat you at the door — it beats you at recovery

Most organizations survive the intrusion. What decides the outcome is what happens next: whether backups are reachable by the same credentials the attacker just stole, whether a restore has ever actually been tested, and whether the network lets one foothold become every server. Those are the questions that separate a bad week from a business-ending event, and they're all answerable before anything happens.

Days
typical downtime when backups aren't isolated and tested
Recovery, not prevention, is where cost accrues.

How this is scored

Six weighted questions across the controls that govern ransomware outcomes: backup isolation, restore testing, network segmentation, identity/MFA, a rehearsed incident-response plan, and monitored detection. Each answer scores 0–3; your total maps to a band. Anything scoring low surfaces as a prioritized fix, worst first. It's a directional self-assessment, not a formal audit.

Questions

Why does backup isolation matter so much?

Modern ransomware specifically hunts and encrypts backups reachable with production credentials. An offline or immutable copy the attacker can't touch is the single control most correlated with fast recovery.

We have backups — isn't that enough?

Only if they've been restored. An untested backup is a hope, not a control; teams routinely discover at the worst moment that a backup is incomplete, corrupt, or takes days to restore.

What's a realistic first step if we score low?

In order: get one immutable/offline backup copy, run a full restore test, and enforce MFA on email, VPN and admin access. Those three moves cut the most risk for the least effort.

Not sure your recovery would hold?

We pressure-test backups, segmentation, identity and the incident-response plan, then fix what breaks first. No obligation, straight conversation.