Score your ransomware recovery readiness across backup, RTO/RPO, testing and SaaS. Get a 0-100 resilience score, critical alerts and a remediation list.
This ransomware resilience assessment scores your ability to survive and recover from a ransomware event, on the assumption that prevention will eventually fail. It examines four areas — backup architecture, recovery objectives, recovery validation, and SaaS coverage — produces a 0–100 resilience score with a maturity level, raises critical alerts on specific dangerous answers, and returns a prioritised remediation list.
It is built for IT managers, backup and infrastructure engineers, vCISOs, and anyone who has been asked how long recovery would actually take and does not have a tested answer. Sixteen questions take roughly ten minutes and everything runs in your browser.
Each answer scores between 0 and 1. Questions carry a risk class — critical, high, or medium — with class weights of 0.5, 0.3, and 0.2. Weight is distributed within each class rather than assigned per question:
Question weight = (class weight ÷ number of answered questions in that class) ÷ sum of active class weights
Resilience score = Σ (answer score × question weight) × 100
The assessment holds four critical, six high, and six medium questions. With all sixteen answered, all three classes are active and their weights sum to 1.0, so each critical question is worth 12.5 points, each high question 5 points, and each medium question 3.33 points. Four critical questions therefore account for half the total score between them.
Two consequences are worth understanding. First, if conditional logic hides an entire risk class — for example because you indicated no SaaS estate — the remaining classes renormalise so the score still runs to 100. Second, one bad answer on a critical question costs 12.5 points, which is more than three medium questions combined. That is intentional: immutability and tested recovery are not incremental improvements over a weak backup posture, they are the difference between recovering and not.
0–20 is Level 1 Unstructured, where backups are ad-hoc and recovery objectives are undefined. 21–40 is Level 2 Repeatable, with basic redundancy but rarely validated objectives. 41–60 is Level 3 Standardized, an automated 3-2-1 strategy with defined RTO and RPO but no immutability. 61–80 is Level 4 Managed, 3-2-1-1 enforced with quarterly tests and leadership oversight. 81–100 is Level 5 Optimized, continuous recovery assurance with near-zero objectives for critical data.
The most valuable output is the smallest. The assessment asks separately for your target RTO for the most critical system, and the actual recovery time measured in your last test. It then reports:
RTO delta = tested recovery hours − target recovery hours
If you target four hours and your last test took eleven, the delta is seven hours and a critical alert fires. That gap is a real, measured commitment failure — not an opinion about maturity — and it is the single most persuasive number this tool produces, because it is the one a business continuity plan already promised. If you cannot supply a tested figure at all, that is the finding.
Certain questions carry a critical message that fires when the answer scores below 0.5 — no immutable backup tier, an undefined RTO benchmark, an RPO beyond tolerance, a tested recovery time exceeding target. The remediation list collects every question scoring below 0.8, sorts by risk class and then by score, and returns the top five actions, each with a specific next step.
Ransomware defence has two halves, and the second is chronically under-measured. Verizon’s 2025 Data Breach Investigations Report, drawn from more than 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 44% of breaches overall — and in 88% of breaches at small and medium businesses. It also found 64% of victims did not pay the ransom, up from 50% two years earlier, with a median payment of $115,000 among those who did. IBM’s Cost of a Data Breach Report 2026 found 39% of breached organisations had experienced at least one ransomware attack, up from 24% in 2023, and that 41% of ransomware attacks included threats to brand reputation such as data leaks and public shaming.
Those figures point the same way: refusing to pay is increasingly the norm, which means recovery capability is what determines the outcome. An organisation that can restore cleanly has a bad week. One that cannot has an existential problem, and extortion leverage shifts entirely to whether your backups survived the attack.
The score is a self-reported planning indicator, not a guarantee of recovery. It cannot verify that a backup restores. Only a test can do that, which is precisely what the validation module keeps asking about.
Three copies of data, on two different media types, with one copy off-site, and one copy immutable or air-gapped. The final “1” is the ransomware-specific addition: modern attackers deliberately target backup infrastructure first, so a copy that cannot be altered or deleted — even with valid administrator credentials — is what separates recovery from paying.
Recovery time objective is how long you can be down. Recovery point objective is how much data you can afford to lose, measured backwards from the incident. A four-hour RTO with a 24-hour RPO means you are back within four hours, having lost up to a day of work.
Because a small number of controls decide the outcome. With all sixteen questions answered, four critical questions carry half the score. Immutability, a defined RTO, and a tested recovery time are not marginal improvements — without them the rest of the programme cannot deliver a recovery.
Under the shared responsibility model the provider guarantees platform availability, not recovery of your data from deletion, malicious insider action, or ransomware that reaches synchronised files. Native retention windows are limited and are not a backup. This is the gap the SaaS module exists to surface.
Then you do not have a recovery time, you have an aspiration. Answer honestly — the assessment will flag it as a critical gap, which is the correct result. A single documented restore test of one critical system is usually the highest-value action available.
The gap between what your continuity plan promises and what your last test actually delivered. It is the most defensible number in the report because it is measured rather than judged.
No. It is a structured self-assessment that never connects to your systems. It reflects your answers, which is why answering for the real production state rather than the documented policy matters.
Quantify the exposure and fund the fix. Size the loss with the data breach cost calculator, and test whether a backup or recovery investment pays for itself in the cybersecurity ROI calculator.
A ransomware resilience assessment evaluates an organization's ability to prevent, detect, respond to, and recover from a ransomware attack. Ransomware remains the most financially devastating form of cyberattack — the average recovery cost reached $2.73 million in 2024 according to the Sophos State of Ransomware Report, with average downtime of 22 days.
This assessment evaluates your defenses across the ransomware kill chain: initial access prevention, execution blocking, lateral movement detection, data exfiltration prevention, backup integrity, and recovery capabilities.
| Stage | Attack Technique | Defense |
|---|---|---|
| Initial Access | Phishing email, RDP exploitation, VPN vulnerability | Email filtering, MFA, patch management, EDR |
| Execution | Malicious attachment, PowerShell, macro | Application allowlisting, script controls, EDR |
| Persistence | Registry modification, scheduled tasks, services | Endpoint monitoring, baseline comparison |
| Privilege Escalation | Credential theft, exploit local vulnerabilities | Least privilege, PAM, patch management |
| Lateral Movement | PsExec, WMI, RDP, SMB | Network segmentation, EDR, NDR |
| Exfiltration | Data theft before encryption (double extortion) | DLP, network monitoring, egress filtering |
| Encryption | File encryption, shadow copy deletion | Backup isolation, canary files, EDR |
| Extortion | Ransom demand, data leak threat | Incident response plan, communication plan, cyber insurance |
Ransomware resilience assessment evaluates your ability to prevent, detect, respond to, and recover from ransomware attacks. It examines backup strategies, network segmentation, endpoint protection, email security, access controls, incident response plans, and recovery capabilities. Assessment identifies vulnerabilities and provides prioritized recommendations to reduce ransomware risk and minimize impact if attacked.
Critical controls include: email security filtering (blocks 90%+ delivery), endpoint detection and response, application whitelisting, regular patching, network segmentation, privileged access management, multi-factor authentication, user training, and secure RDP configuration. Defense-in-depth approach layers controls so attackers must defeat multiple protections. Focus on preventing initial access and lateral movement.
Follow 3-2-1-1 rule: 3 copies of data, 2 different media types, 1 offsite, 1 offline/immutable. Implement air-gapped or immutable backups that ransomware cannot encrypt. Test restoration regularly (quarterly minimum). Maintain versioned backups to recover pre-encryption data. Backup critical systems first. Document recovery procedures. Consider continuous data protection for critical assets. Backups are last line of defense.
Early detection is crucial—aim for detection within minutes to hours, before widespread encryption. Implement 24/7 monitoring for ransomware indicators: unusual file access patterns, suspicious encryption activity, shadow copy deletion, backup system tampering, and lateral movement. EDR and SIEM tools with ransomware-specific detection rules enable rapid response. Average detection time is improving but still exceeds 24 hours for many organizations.
Plan should cover: decision tree for containment actions, communication protocols (internal and external), system isolation procedures, backup verification steps, law enforcement notification process, ransom payment decision framework, recovery prioritization, and public relations strategy. Pre-establish relationships with incident response firms, legal counsel, and cyber insurance. Conduct tabletop exercises quarterly to test plan effectiveness.
Payment is strongly discouraged—it funds criminal operations, provides no guarantee of decryption, and marks you as willing payer for future attacks. Only 57% who pay receive all data back. Many attackers sell data anyway. FBI and CISA recommend against payment. However, some organizations in crisis situations pay as last resort. Decision requires legal counsel, insurance input, and executive approval.
According to Sophos 2024 research, average recovery time is 22 days for organizations that use backups, 28 days overall. Some organizations take months for full restoration. Time depends on backup readiness, attack scope, system complexity, and restoration testing. Organizations with tested recovery plans restore 60-80% faster. Critical systems should be restorable within 24-72 hours to minimize business impact.
Conduct quarterly backup restoration tests (verify data integrity and RTO). Run ransomware attack simulations and tabletop exercises biannually. Perform penetration testing focusing on ransomware attack paths. Test incident response procedures under stress. Validate immutable backup isolation. Measure detection capabilities with adversary simulation tools. Document lessons learned and update controls. Testing reveals gaps before real attacks occur.