simpl.
Cybersecurity GRC 17 items

Ransomware Readiness Assessment

Assesses organizational readiness to prevent, detect, and recover from ransomware using the CISA #StopRansomware guide and NIST controls, covering prevention, detection, and recovery.

CISA #StopRansomwareNIST 800-53CIS v8

Free PDF · enter your email to download.

Prevention & Hardening

  • Is phishing-resistant or strong MFA enforced on all remote access and email? *
  • Are RDP and remote services restricted, patched, and not exposed to the internet? *
  • Is application allowlisting or macro blocking enforced on endpoints?
  • Is network segmentation implemented to limit lateral movement? *
  • Are internet-facing vulnerabilities prioritized and remediated on a defined SLA? *

Detection & Response

  • Is EDR deployed with detections for ransomware precursor behaviors? *
  • Are common precursor malware families (e.g., loaders, C2 frameworks) alerted on? *
  • Is there a ransomware-specific incident response playbook? *
  • Is the isolation and containment procedure for infected hosts documented? *

Backup & Recovery

  • Are backups maintained following the 3-2-1 rule with at least one offline/immutable copy? *
  • Are backups isolated from production credentials and networks? *
  • Are restoration procedures tested on a defined schedule? *
  • Is a recovery time objective (RTO) defined for critical systems?

Governance & Decision-Making

  • Is there a documented ransom-payment decision process involving legal and leadership? *
  • Are OFAC sanctions considerations documented for any potential payment?
  • Are law-enforcement and CISA reporting contacts documented in advance? *
  • Has a ransomware tabletop exercise been conducted in the past 12 months?

Download the full Ransomware Readiness Assessment checklist

Get it as a clean, printable PDF — free.