602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Ransomware Readiness Scorecard

Honeybadger Solutions · Cyber & Digital Forensics

Ransomware Readiness Scorecard

Check every control your organization has fully in place. Your score updates instantly.

0/100
High exposure
Answer the questions above to see your readiness and top gaps.
Get a free cyber risk check →

or call 602-725-2818 · incident response & court-ready forensics

Self-assessment for planning only; not an audit or a guarantee of protection. Controls align with widely used guidance from CISA (StopRansomware) and the NIST Cybersecurity Framework. Honeybadger Solutions LLC.

Why these particular controls, and what each one actually stops

The scorecard above is not a generic security checklist. Every item on it maps to a specific step in how ransomware actually reaches a business, and the reason the list is short is that a small number of controls stop the overwhelming majority of real incidents. Understanding which step each control interrupts is what turns a score into a plan.

The attack chain, in the order it happens

Initial access. Almost always one of three things: a phishing email that harvests a credential, an exposed remote-access service with a weak or reused password, or an unpatched internet-facing device. Note what is not on that list — sophisticated zero-day exploitation is rare against organisations of this size. The way in is usually mundane.

Establishing a foothold. The attacker installs persistence so a reboot or a password change does not evict them. This is frequently done with legitimate administrative tools already present on the network, which is why antivirus alone so often sees nothing.

Privilege escalation and reconnaissance. They look for administrative credentials and map what you have. This phase commonly lasts days or weeks. It is the longest window you get, and the one most organisations have no capability to notice.

Data theft. Modern ransomware groups exfiltrate before they encrypt, because stolen data gives them leverage even if your backups are perfect. This is why “we have backups” is no longer a complete answer — backups solve availability, not disclosure.

Backup destruction. Before encrypting anything, they go after the backups. Connected backup servers, cloud backup consoles reachable with the credentials they now hold, and snapshots they can delete. An attacker who finds your backups accessible has removed your only real leverage.

Encryption. Usually triggered out of hours — a Friday evening, a holiday weekend — to maximise the time before anyone notices.

The controls that matter most

Multi-factor authentication on everything reachable from the internet. The single highest-value control on the list. It defeats the most common initial-access route outright, because a stolen password alone stops being sufficient. Email, VPN, remote desktop, administrative consoles, cloud platforms. Partial MFA is how organisations get breached through the one account nobody covered.

Offline or immutable backups. The 3-2-1 rule still holds: three copies, two media types, one off-site — and for ransomware specifically, one copy must be genuinely unreachable from the network. A backup drive that is permanently connected is not a backup, it is another target. Immutable cloud storage, where copies cannot be deleted for a set retention period even with valid credentials, is the modern equivalent of tape in a safe.

Tested restoration. Untested backups fail at the worst possible moment, and the failure rate is not small. If you have never performed a full restore under timed conditions, you do not know your recovery time — you know your aspiration. Test it, write down how long it actually took, and tell the leadership team that number.

Patching what faces the internet. Internal patching matters; internet-facing patching is urgent. VPN appliances, firewalls, remote-access gateways and web applications are scanned continuously by automated tooling within hours of a vulnerability becoming public.

Least privilege, and separate administrative accounts. Day-to-day work should never happen from an account with domain administrative rights. This single practice turns a compromised workstation from a catastrophe into an incident.

Endpoint detection that someone reads. Detection tooling producing alerts nobody reviews is expenditure, not security. The reconnaissance phase is your longest opportunity to intervene, and it is only an opportunity if a human being is looking.

What to do in the first hour

If encryption has started, the decisions you make in the first hour shape everything that follows.

Isolate, do not power down. Disconnect from the network — physically pull cable, disable wireless. Do not switch machines off. Volatile memory holds encryption keys, running processes and attacker artefacts that are lost forever the moment a system powers down, and that evidence is frequently what determines whether recovery is possible and what your notification obligations are.

Call your insurer before your IT provider starts remediating. Most cyber policies require notification before response work begins and may specify which responders are approved. Well-intentioned remediation performed first has voided real claims.

Preserve everything. Logs, the ransom note, affected systems, firewall and VPN records. Set log retention to preserve rather than rotate. This is the material that answers the only question that ultimately matters: what did they take.

Do not communicate on the compromised network. Assume email and chat are being read. Move to phones and out-of-band channels.

Assume data was stolen until forensics says otherwise. Your legal and notification obligations attach to disclosure, not encryption.

Should you pay?

That is a decision for your leadership, your counsel and your insurer, not for us and not for your IT provider. What we can tell you from casework: payment does not reliably produce clean or complete decryption, it does not remove the stolen copy of your data, and it does not end the relationship — previously-paying organisations are disproportionately targeted again. Payment is sometimes the least-bad commercial option. It is never a security outcome.

Where digital forensics fits

Recovery restores operations. Forensics answers what happened, how they got in, what they reached, what left the building, and whether they are still there. Those are different jobs and the second one is frequently skipped, which is how organisations get hit twice through the same unclosed door.

Forensics also produces the record you need for insurers, regulators, counsel and — where notification is required — for the people whose data was involved. “We think it was probably contained” is not a defensible position when that question is asked formally, and it will be.

What cyber insurance underwriters now ask you to prove

Ransomware coverage stopped being a checkbox several renewal cycles ago. The application you fill out today is effectively a technical audit, and the answers are warranties — if you attest to a control you do not actually have, the carrier can and will contest the claim at the worst possible moment. The questions cluster around the same short list every time: multifactor authentication on email, on remote access and on privileged accounts; endpoint detection and response deployed across the estate rather than on a subset of machines; offline or immutable backups with a documented restore test; a written incident response plan; and privileged access that is separated from day-to-day user accounts.

Notice how closely that list tracks the controls this scorecard asks about. That is not a coincidence. Underwriters converged on those items because their own claims data showed them to be the ones that separate a bad week from a business-ending event. If your score here is low, your premium is going to reflect it — or you will be declined outright, which is increasingly common for organisations that cannot demonstrate MFA and tested backups. Improving the score has a dollar value attached to it that shows up on a renewal quote, independent of whether you are ever attacked.

One trap worth naming: sub-limits. A policy may advertise a headline limit and then cap ransomware, extortion payments, or business interruption at a fraction of it. Read the ransomware endorsement specifically, and ask what the waiting period is before business interruption coverage begins. A seventy-two hour waiting period on a four-day outage covers almost nothing.

What this scorecard does not measure

A score is a conversation starter, not an assessment. It cannot see your network, so it cannot tell you whether your flat network lets an infected workstation reach the server that holds everything, whether your backup server is domain-joined and therefore encryptable along with everything else, or whether the vendor with a standing remote connection into your environment has MFA on their side of that tunnel. Those three questions have ended more organisations than any missing control on this list.

It also cannot weigh your specific exposure. A medical practice, a title company holding wire instructions, and a machine shop with three CNC controllers face very different versions of the same attack, with different regulatory consequences and different recovery clocks. A shared score of six out of ten means something quite different in each case.

Treat the result as triage. If it comes back low, the productive next step is a short scoping conversation about what you actually have and what is realistically reachable in a quarter — not a procurement cycle for tooling you have no one to run.

Related reading