Most teams discover their ransomware gaps at 3 a.m. during the actual event. This is the assessment you run before that night: 30 concrete, scored checks across identity, backups, detection, hardening, and governance. Score yourself honestly, total the result, and you will know within an hour whether a restore is a rehearsal or a gamble.
What is a ransomware readiness assessment?
A ransomware readiness assessment is a structured self-audit that measures how well you can prevent, detect, survive, and recover from an encryption-plus-extortion attack. It scores concrete controls, such as MFA coverage, immutable backups, tested restores, and detection speed, rather than intentions, so you can see exactly where a real attack would land.
- ▸Modern ransomware is double extortion: attackers exfiltrate data first, then encrypt, so backups alone no longer protect you from the leak.
- ▸The assessment spans the full kill chain, from initial access to recovery, not just backups.
- ▸Run it quarterly and after any major change, ideally with the IT lead, a security owner, and someone from the business who owns downtime cost, so scores reflect reality rather than optimism.
- ▸For context, see Ransomware Resilience in 2026: Backups That Actually Restore, Faster Detection, and Recovery You Can Prove and Ransomware in 2026: What Small Businesses Keep Getting Wrong.
How do you score this 30-point assessment?
Score each of the 30 checks 0, 1, or 2: 0 means not in place, 1 means partial or untested, 2 means implemented and verified. The maximum is 60. Total your score and read the band in the final section. Be strict, because an untested backup scores 1, never 2, since untested is unknown.
- ▸0 means the control is absent.
- ▸1 means partial, or documented but unverified.
- ▸2 means implemented and evidenced with logs, test results, or screenshots.
- ▸The maximum score is 60 across all five sections below.
- ▸Record the evidence next to each score. The point of the number is not the number itself; it is the shortlist of specific gaps you can hand to whoever owns the fix, ranked by how much they reduce total-loss risk.
Identity and access (points 1 to 6)
Identity is the ransomware front door, because most intrusions start with a phished credential or exposed remote access. These six checks confirm MFA is universal, privileged access is controlled, and legacy entry points are closed. Weak identity here caps your realistic resilience no matter how good your backups are.
1. Phishing-resistant MFA on all users, prioritizing email and VPN, using FIDO2 or passkeys where possible. 2. No internet-exposed RDP or SMB; remote access sits behind VPN or ZTNA. 3. Privileged accounts separated from daily-use accounts, with admin MFA enforced. 4. Least privilege reviewed, with no standing domain-admin sprawl. 5. Service and legacy accounts inventoried, with stale credentials disabled or rotated. 6. Conditional access and lockout on impossible-travel and brute-force attempts.
Backup and recovery (points 7 to 13)
Backups are where ransomware readiness is won or lost, and where most teams overestimate themselves. These seven checks verify the 3-2-1-1 rule, immutability, isolation, and the step everyone skips: a timed, full restore test. An untested backup is a hypothesis, not a recovery plan.
7. 3-2-1-1 rule: three copies, two media types, one offsite, one offline or immutable. 8. Immutable or air-gapped copy using object lock or WORM that attackers cannot reach. 9. Backups isolated from production identity, with separate credentials and network. 10. Full restore tested end to end within the last 90 days. 11. Documented RTO and RPO backed by measured, not assumed, restore times. 12. Backup coverage includes SaaS such as Microsoft 365 and Google Workspace, plus cloud data. 13. Restore runbook exists, and someone other than its author can execute it.
The restore test is the single most predictive line here, as argued in The Restore You Rehearse: Business Continuity and DR for SMEs in 2026.
Detection and response (points 14 to 20)
Ransomware dwell time is often days, so the earlier you catch lateral movement or mass file changes, the smaller the blast radius. These seven checks confirm you have EDR, centralized logging, someone watching after hours, and a written playbook. Detection without a response plan just tells you how fast you are losing.
14. EDR or XDR deployed on all endpoints and servers, running in block mode. 15. Centralized logging or SIEM with retention long enough to investigate. 16. 24/7 monitoring, in-house or via MDR, because attacks land on weekends and holidays. 17. Canaries or honeytokens that trip on mass encryption early. 18. Written IR playbook with roles, contacts, and clear decision authority. 19. Out-of-band communications, since the attacker may control your email or Teams. 20. Fast isolation capability to segment or quarantine hosts on demand.
Build the playbook from Incident Response Playbooks That Teams Actually Use, and weigh coverage economics in Cyber Insurance and Affordable MDR: The New Economics of SME Resilience.
Email, endpoint and network hardening (points 21 to 26)
Most ransomware still arrives by email or through an unpatched internet-facing service. These six checks shrink the initial-access surface: mail filtering, macro controls, a patch cadence on exposed systems, and segmentation that stops one host from becoming the whole estate.
21. Email security with SPF, DKIM, and DMARC enforced, plus attachment sandboxing. 22. Macro and script controls that block macros from the internet and constrain scripting engines. 23. Patch SLA for internet-facing and critical systems, remediating known-exploited (KEV) flaws within days. 24. Network segmentation that limits east-west movement. 25. Application allowlisting or an equivalent control on critical servers. 26. Vulnerability scanning and external attack-surface monitoring.
Governance, testing and insurance (points 27 to 30)
The last four points separate a control set from a program. They confirm you rehearse the scenario, train people, carry insurance that matches your controls, and have worked through the legal and disclosure duties of an extortion event before the clock starts.
27. Tabletop exercise run within the last 12 months. 28. Security awareness and phishing-simulation program active and measured. 29. Cyber insurance reviewed, with your controls meeting the policy's stated requirements. 30. Legal and regulatory plan: a ransom-payment stance, breach-notification duties under GDPR and NIS2, and law-enforcement contacts.
What does your score mean, and what do you fix first?
Total your 60-point score and read the band. 0 to 24 is high risk: a common attack likely succeeds and recovery is uncertain. 25 to 42 is developing: you survive some scenarios but have exploitable gaps. 43 to 54 is solid: fix the specific low-scorers. 55 to 60 is mature: validate with an independent test.
- ▸0 to 24, high risk: start with phishing-resistant MFA, an immutable backup, and a tested restore; those three moves prevent most total-loss outcomes.
- ▸25 to 42, developing: close detection and segmentation gaps and run a tabletop.
- ▸43 to 54, solid: attack your own lowest scores and verify each claim with evidence.
- ▸55 to 60, mature: commission independent validation and adversary emulation.
- ▸Any single 0 in backups or MFA is a red flag regardless of your total.
How TuniCyberLabs helps
We run this assessment as a formal, evidence-based audit: validating backups with a live restore test, checking detection coverage, and pressure-testing your response with a tabletop, then handing you a prioritized remediation plan mapped to your score. We work with SMEs and scale-ups across the EU and North Africa.
Book a ransomware readiness audit: contact our team.
