Resilience
Could you recover from ransomware?
Six questions on the controls that actually decide whether ransomware is an incident or a catastrophe — backups, recovery testing, segmentation, identity, a tested plan, and detection.
Answer honestly — the point is to find the gap before an attacker does. Your result breaks down question by question and puts the most dangerous gaps first.
Why this matters
Ransomware doesn't beat you at the door — it beats you at recovery
Most organizations survive the intrusion. What decides the outcome is what happens next: whether backups are reachable by the same credentials the attacker just stole, whether a restore has ever actually been tested, and whether the network lets one foothold become every server. Those are the questions that separate a bad week from a business-ending event, and they're all answerable before anything happens.
How this is scored
Six weighted questions across the controls that govern ransomware outcomes: backup isolation, restore testing, network segmentation, identity/MFA, a rehearsed incident-response plan, and monitored detection. Each answer scores 0–3; your total maps to a band. Anything scoring low surfaces as a prioritized fix, worst first. It's a directional self-assessment, not a formal audit.
Questions
Why does backup isolation matter so much?
Modern ransomware specifically hunts and encrypts backups reachable with production credentials. An offline or immutable copy the attacker can't touch is the single control most correlated with fast recovery.
We have backups — isn't that enough?
Only if they've been restored. An untested backup is a hope, not a control; teams routinely discover at the worst moment that a backup is incomplete, corrupt, or takes days to restore.
What's a realistic first step if we score low?
In order: get one immutable/offline backup copy, run a full restore test, and enforce MFA on email, VPN and admin access. Those three moves cut the most risk for the least effort.
Not sure your recovery would hold?
We pressure-test backups, segmentation, identity and the incident-response plan, then fix what breaks first. No obligation, straight conversation.