A readiness checklist for the morning you hope never happens.
Ransomware is a recovery problem long before it is a malware problem. Score yourself on the three lists below - the first one decides how bad it gets, the second how fast it ends.
Before - the controls that decide the outcome
Ransomware outcomes are mostly decided before the attack, by five or six unglamorous controls.
- ✓At least one backup copy is offline or immutable - a backup the ransomware can reach is not a backup
- ✓Somebody has watched a full restore succeed, recently, and knows how long it takes
- ✓MFA is on for email and every remote access path - VPN, remote desktop, admin portals
- ✓Updates land within 30 days on every machine, and unsupported systems are isolated or retired
- ✓Admin accounts are separate from daily accounts, so one clicked link cannot take the whole network
- ✓Endpoint protection runs on every computer and somebody would actually see its alerts
The first hour - decided in advance, on paper
When screens lock, nobody thinks clearly. The plan has to exist before, printed, where people can find it.
- ✓The first call is your cyber insurer’s breach line - calling vendors first can jeopardize coverage
- ✓Disconnect affected machines from the network - do not power them off, evidence lives in memory
- ✓One named person speaks for the office; everyone else preserves and does not touch
- ✓The plan exists on paper, off the systems that just locked - with insurer, bank, IT and legal numbers filled in
- ✓Nobody pays, promises or posts anything in hour one - those are decisions for daylight, with your insurer and counsel
The questions to answer this month
Five questions, answered while it is hypothetical, that are brutal to answer live.
- ✓Which three systems does the business actually stop without - and which gets restored first?
- ✓Could the office run a day on paper while systems come back? Has anyone thought it through?
- ✓Where are the backup credentials stored, and can the right person reach them if email is down?
- ✓Who are you legally required to notify, and when - PIPEDA for most businesses, PHIPA for health information in Ontario?
- ✓When did you last rehearse any of this - even as a 60-minute tabletop conversation?
Related tools and next steps
Ready to see where you stand?
Start with a baseline security checkup. We review your environment, score the highest-risk gaps, and hand you a plain-English 30-day plan.