Interactive Ransomware Resilience Assessment

Score your ransomware recovery readiness across backup, RTO/RPO, testing and SaaS. Get a 0-100 resilience score, critical alerts and a remediation list.

Advertisement

Ransomware Resilience Assessment: Backup, Recovery and RTO Testing

This ransomware resilience assessment scores your ability to survive and recover from a ransomware event, on the assumption that prevention will eventually fail. It examines four areas — backup architecture, recovery objectives, recovery validation, and SaaS coverage — produces a 0–100 resilience score with a maturity level, raises critical alerts on specific dangerous answers, and returns a prioritised remediation list.

It is built for IT managers, backup and infrastructure engineers, vCISOs, and anyone who has been asked how long recovery would actually take and does not have a tested answer. Sixteen questions take roughly ten minutes and everything runs in your browser.

What the Assessment Covers

  • Data Protection Principles — immutable or air-gapped copies, media diversity under the 3-2-1 rule, isolation of the backup security boundary from production, and backup cadence.
  • Mission Criticality and Performance — whether RTO and RPO targets came from a business impact analysis, whether applications are mapped to tiered recovery groups, and what your current RPO and RTO actually are.
  • Recovery Validation and IR Readiness — testing cadence, whether tested recovery time matches the target, and incident response playbook maturity.
  • SaaS and Cloud Resilience — the shared responsibility gap across Microsoft 365, Google Workspace, and other SaaS, where the provider guarantees service availability but not recovery of your data from your own mistakes or an attacker’s.

How the Score Is Calculated

Each answer scores between 0 and 1. Questions carry a risk class — critical, high, or medium — with class weights of 0.5, 0.3, and 0.2. Weight is distributed within each class rather than assigned per question:

Question weight = (class weight ÷ number of answered questions in that class) ÷ sum of active class weights

Resilience score = Σ (answer score × question weight) × 100

The assessment holds four critical, six high, and six medium questions. With all sixteen answered, all three classes are active and their weights sum to 1.0, so each critical question is worth 12.5 points, each high question 5 points, and each medium question 3.33 points. Four critical questions therefore account for half the total score between them.

Two consequences are worth understanding. First, if conditional logic hides an entire risk class — for example because you indicated no SaaS estate — the remaining classes renormalise so the score still runs to 100. Second, one bad answer on a critical question costs 12.5 points, which is more than three medium questions combined. That is intentional: immutability and tested recovery are not incremental improvements over a weak backup posture, they are the difference between recovering and not.

Maturity bands

0–20 is Level 1 Unstructured, where backups are ad-hoc and recovery objectives are undefined. 21–40 is Level 2 Repeatable, with basic redundancy but rarely validated objectives. 41–60 is Level 3 Standardized, an automated 3-2-1 strategy with defined RTO and RPO but no immutability. 61–80 is Level 4 Managed, 3-2-1-1 enforced with quarterly tests and leadership oversight. 81–100 is Level 5 Optimized, continuous recovery assurance with near-zero objectives for critical data.

The RTO delta

The most valuable output is the smallest. The assessment asks separately for your target RTO for the most critical system, and the actual recovery time measured in your last test. It then reports:

RTO delta = tested recovery hours − target recovery hours

If you target four hours and your last test took eleven, the delta is seven hours and a critical alert fires. That gap is a real, measured commitment failure — not an opinion about maturity — and it is the single most persuasive number this tool produces, because it is the one a business continuity plan already promised. If you cannot supply a tested figure at all, that is the finding.

Critical alerts and remediation

Certain questions carry a critical message that fires when the answer scores below 0.5 — no immutable backup tier, an undefined RTO benchmark, an RPO beyond tolerance, a tested recovery time exceeding target. The remediation list collects every question scoring below 0.8, sorts by risk class and then by score, and returns the top five actions, each with a specific next step.

How to Use It

  1. Answer for production reality. Not the documented policy, and not the intended state. The question is whether the immutable copy exists today, not whether it is on the roadmap.
  2. Enter measured recovery times, not estimates. A number from a real restore test is worth more than a confident guess, and the gap between the two is usually the point.
  3. Do not skip the SaaS module. The assumption that Microsoft 365 or Google Workspace is inherently backed up is one of the most common recovery gaps, and it surfaces only after data is already gone.
  4. Read the module scores separately. Strong backup architecture with weak validation is a common and dangerous profile: backups exist, nobody has proven they restore.
  5. Work the remediation list in order. It is sorted so the highest-risk, lowest-scoring items come first.

Why Recovery, Not Prevention

Ransomware defence has two halves, and the second is chronically under-measured. Verizon’s 2025 Data Breach Investigations Report, drawn from more than 22,000 incidents and 12,195 confirmed breaches, found ransomware present in 44% of breaches overall — and in 88% of breaches at small and medium businesses. It also found 64% of victims did not pay the ransom, up from 50% two years earlier, with a median payment of $115,000 among those who did. IBM’s Cost of a Data Breach Report 2026 found 39% of breached organisations had experienced at least one ransomware attack, up from 24% in 2023, and that 41% of ransomware attacks included threats to brand reputation such as data leaks and public shaming.

Those figures point the same way: refusing to pay is increasingly the norm, which means recovery capability is what determines the outcome. An organisation that can restore cleanly has a bad week. One that cannot has an existential problem, and extortion leverage shifts entirely to whether your backups survived the attack.

The score is a self-reported planning indicator, not a guarantee of recovery. It cannot verify that a backup restores. Only a test can do that, which is precisely what the validation module keeps asking about.

Frequently Asked Questions

What is the 3-2-1-1 rule?

Three copies of data, on two different media types, with one copy off-site, and one copy immutable or air-gapped. The final “1” is the ransomware-specific addition: modern attackers deliberately target backup infrastructure first, so a copy that cannot be altered or deleted — even with valid administrator credentials — is what separates recovery from paying.

What is the difference between RTO and RPO?

Recovery time objective is how long you can be down. Recovery point objective is how much data you can afford to lose, measured backwards from the incident. A four-hour RTO with a 24-hour RPO means you are back within four hours, having lost up to a day of work.

Why does the assessment weight critical questions so heavily?

Because a small number of controls decide the outcome. With all sixteen questions answered, four critical questions carry half the score. Immutability, a defined RTO, and a tested recovery time are not marginal improvements — without them the rest of the programme cannot deliver a recovery.

Do I really need to back up Microsoft 365?

Under the shared responsibility model the provider guarantees platform availability, not recovery of your data from deletion, malicious insider action, or ransomware that reaches synchronised files. Native retention windows are limited and are not a backup. This is the gap the SaaS module exists to surface.

What if I have never tested a restore?

Then you do not have a recovery time, you have an aspiration. Answer honestly — the assessment will flag it as a critical gap, which is the correct result. A single documented restore test of one critical system is usually the highest-value action available.

What does the RTO delta tell me?

The gap between what your continuity plan promises and what your last test actually delivered. It is the most defensible number in the report because it is measured rather than judged.

Is this a scan of my backup infrastructure?

No. It is a structured self-assessment that never connects to your systems. It reflects your answers, which is why answering for the real production state rather than the documented policy matters.

What should I do after this?

Quantify the exposure and fund the fix. Size the loss with the data breach cost calculator, and test whether a backup or recovery investment pays for itself in the cybersecurity ROI calculator.

What Is Ransomware Resilience Assessment

A ransomware resilience assessment evaluates an organization's ability to prevent, detect, respond to, and recover from a ransomware attack. Ransomware remains the most financially devastating form of cyberattack — the average recovery cost reached $2.73 million in 2024 according to the Sophos State of Ransomware Report, with average downtime of 22 days.

This assessment evaluates your defenses across the ransomware kill chain: initial access prevention, execution blocking, lateral movement detection, data exfiltration prevention, backup integrity, and recovery capabilities.

Ransomware Kill Chain

StageAttack TechniqueDefense
Initial AccessPhishing email, RDP exploitation, VPN vulnerabilityEmail filtering, MFA, patch management, EDR
ExecutionMalicious attachment, PowerShell, macroApplication allowlisting, script controls, EDR
PersistenceRegistry modification, scheduled tasks, servicesEndpoint monitoring, baseline comparison
Privilege EscalationCredential theft, exploit local vulnerabilitiesLeast privilege, PAM, patch management
Lateral MovementPsExec, WMI, RDP, SMBNetwork segmentation, EDR, NDR
ExfiltrationData theft before encryption (double extortion)DLP, network monitoring, egress filtering
EncryptionFile encryption, shadow copy deletionBackup isolation, canary files, EDR
ExtortionRansom demand, data leak threatIncident response plan, communication plan, cyber insurance

Common Use Cases

  • Security gap analysis: Identify weaknesses in your ransomware defenses across prevention, detection, response, and recovery capabilities
  • Board risk reporting: Quantify ransomware readiness for executive leadership with specific capability scores and remediation priorities
  • Insurance qualification: Document ransomware controls for cyber insurance applications, which increasingly require specific protections (MFA, backups, EDR)
  • Compliance alignment: Map ransomware resilience to NIST CSF, CIS Controls, and industry-specific requirements
  • Incident preparation: Verify that your backup, response, and recovery capabilities will actually work when ransomware hits

Best Practices

  1. Implement immutable backups — Ransomware operators specifically target backups. Use immutable storage (WORM), air-gapped backups, or offline backup copies that cannot be encrypted by malware.
  2. Deploy EDR on all endpoints — Endpoint Detection and Response provides the most effective defense against ransomware execution. Ensure 100% coverage, not just servers.
  3. Enforce MFA everywhere — MFA on VPN, email, RDP, and privileged accounts blocks the most common initial access vectors. SMS-based MFA is better than nothing but phishable — use hardware keys or app-based MFA.
  4. Test backup restoration — 60% of organizations that pay ransoms still cannot fully recover. Regular restore testing (monthly for critical systems) is the only way to verify your recovery capability.
  5. Segment networks aggressively — Flat networks allow ransomware to spread from a single compromised endpoint to every system. Segment by function and restrict lateral movement with firewall rules.

Frequently Asked Questions

What is ransomware resilience assessment?+

Ransomware resilience assessment evaluates your ability to prevent, detect, respond to, and recover from ransomware attacks. It examines backup strategies, network segmentation, endpoint protection, email security, access controls, incident response plans, and recovery capabilities. Assessment identifies vulnerabilities and provides prioritized recommendations to reduce ransomware risk and minimize impact if attacked.

What are essential ransomware prevention controls?+

Critical controls include: email security filtering (blocks 90%+ delivery), endpoint detection and response, application whitelisting, regular patching, network segmentation, privileged access management, multi-factor authentication, user training, and secure RDP configuration. Defense-in-depth approach layers controls so attackers must defeat multiple protections. Focus on preventing initial access and lateral movement.

What backup strategy defends against ransomware?+

Follow 3-2-1-1 rule: 3 copies of data, 2 different media types, 1 offsite, 1 offline/immutable. Implement air-gapped or immutable backups that ransomware cannot encrypt. Test restoration regularly (quarterly minimum). Maintain versioned backups to recover pre-encryption data. Backup critical systems first. Document recovery procedures. Consider continuous data protection for critical assets. Backups are last line of defense.

How quickly should you detect ransomware?+

Early detection is crucial—aim for detection within minutes to hours, before widespread encryption. Implement 24/7 monitoring for ransomware indicators: unusual file access patterns, suspicious encryption activity, shadow copy deletion, backup system tampering, and lateral movement. EDR and SIEM tools with ransomware-specific detection rules enable rapid response. Average detection time is improving but still exceeds 24 hours for many organizations.

What should incident response plan include for ransomware?+

Plan should cover: decision tree for containment actions, communication protocols (internal and external), system isolation procedures, backup verification steps, law enforcement notification process, ransom payment decision framework, recovery prioritization, and public relations strategy. Pre-establish relationships with incident response firms, legal counsel, and cyber insurance. Conduct tabletop exercises quarterly to test plan effectiveness.

Should you pay ransomware demands?+

Payment is strongly discouraged—it funds criminal operations, provides no guarantee of decryption, and marks you as willing payer for future attacks. Only 57% who pay receive all data back. Many attackers sell data anyway. FBI and CISA recommend against payment. However, some organizations in crisis situations pay as last resort. Decision requires legal counsel, insurance input, and executive approval.

What is average ransomware recovery time?+

According to Sophos 2024 research, average recovery time is 22 days for organizations that use backups, 28 days overall. Some organizations take months for full restoration. Time depends on backup readiness, attack scope, system complexity, and restoration testing. Organizations with tested recovery plans restore 60-80% faster. Critical systems should be restorable within 24-72 hours to minimize business impact.

How do you test ransomware resilience?+

Conduct quarterly backup restoration tests (verify data integrity and RTO). Run ransomware attack simulations and tabletop exercises biannually. Perform penetration testing focusing on ransomware attack paths. Test incident response procedures under stress. Validate immutable backup isolation. Measure detection capabilities with adversary simulation tools. Document lessons learned and update controls. Testing reveals gaps before real attacks occur.

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.