Cybersecurity

The 30-Point Ransomware Readiness Assessment

TuniCyberLabs Team
6 min read

A scored, 30-point ransomware readiness assessment your team can self-run across identity, backups, detection, hardening and governance, with a scoring band that tells you exactly what to fix first.

Most teams discover their ransomware gaps at 3 a.m. during the actual event. This is the assessment you run before that night: 30 concrete, scored checks across identity, backups, detection, hardening, and governance. Score yourself honestly, total the result, and you will know within an hour whether a restore is a rehearsal or a gamble.

What is a ransomware readiness assessment?

A ransomware readiness assessment is a structured self-audit that measures how well you can prevent, detect, survive, and recover from an encryption-plus-extortion attack. It scores concrete controls, such as MFA coverage, immutable backups, tested restores, and detection speed, rather than intentions, so you can see exactly where a real attack would land.

How do you score this 30-point assessment?

Score each of the 30 checks 0, 1, or 2: 0 means not in place, 1 means partial or untested, 2 means implemented and verified. The maximum is 60. Total your score and read the band in the final section. Be strict, because an untested backup scores 1, never 2, since untested is unknown.

  • 0 means the control is absent.
  • 1 means partial, or documented but unverified.
  • 2 means implemented and evidenced with logs, test results, or screenshots.
  • The maximum score is 60 across all five sections below.
  • Record the evidence next to each score. The point of the number is not the number itself; it is the shortlist of specific gaps you can hand to whoever owns the fix, ranked by how much they reduce total-loss risk.

Identity and access (points 1 to 6)

Identity is the ransomware front door, because most intrusions start with a phished credential or exposed remote access. These six checks confirm MFA is universal, privileged access is controlled, and legacy entry points are closed. Weak identity here caps your realistic resilience no matter how good your backups are.

1. Phishing-resistant MFA on all users, prioritizing email and VPN, using FIDO2 or passkeys where possible. 2. No internet-exposed RDP or SMB; remote access sits behind VPN or ZTNA. 3. Privileged accounts separated from daily-use accounts, with admin MFA enforced. 4. Least privilege reviewed, with no standing domain-admin sprawl. 5. Service and legacy accounts inventoried, with stale credentials disabled or rotated. 6. Conditional access and lockout on impossible-travel and brute-force attempts.

Backup and recovery (points 7 to 13)

Backups are where ransomware readiness is won or lost, and where most teams overestimate themselves. These seven checks verify the 3-2-1-1 rule, immutability, isolation, and the step everyone skips: a timed, full restore test. An untested backup is a hypothesis, not a recovery plan.

7. 3-2-1-1 rule: three copies, two media types, one offsite, one offline or immutable. 8. Immutable or air-gapped copy using object lock or WORM that attackers cannot reach. 9. Backups isolated from production identity, with separate credentials and network. 10. Full restore tested end to end within the last 90 days. 11. Documented RTO and RPO backed by measured, not assumed, restore times. 12. Backup coverage includes SaaS such as Microsoft 365 and Google Workspace, plus cloud data. 13. Restore runbook exists, and someone other than its author can execute it.

The restore test is the single most predictive line here, as argued in The Restore You Rehearse: Business Continuity and DR for SMEs in 2026.

Detection and response (points 14 to 20)

Ransomware dwell time is often days, so the earlier you catch lateral movement or mass file changes, the smaller the blast radius. These seven checks confirm you have EDR, centralized logging, someone watching after hours, and a written playbook. Detection without a response plan just tells you how fast you are losing.

14. EDR or XDR deployed on all endpoints and servers, running in block mode. 15. Centralized logging or SIEM with retention long enough to investigate. 16. 24/7 monitoring, in-house or via MDR, because attacks land on weekends and holidays. 17. Canaries or honeytokens that trip on mass encryption early. 18. Written IR playbook with roles, contacts, and clear decision authority. 19. Out-of-band communications, since the attacker may control your email or Teams. 20. Fast isolation capability to segment or quarantine hosts on demand.

Build the playbook from Incident Response Playbooks That Teams Actually Use, and weigh coverage economics in Cyber Insurance and Affordable MDR: The New Economics of SME Resilience.

Email, endpoint and network hardening (points 21 to 26)

Most ransomware still arrives by email or through an unpatched internet-facing service. These six checks shrink the initial-access surface: mail filtering, macro controls, a patch cadence on exposed systems, and segmentation that stops one host from becoming the whole estate.

21. Email security with SPF, DKIM, and DMARC enforced, plus attachment sandboxing. 22. Macro and script controls that block macros from the internet and constrain scripting engines. 23. Patch SLA for internet-facing and critical systems, remediating known-exploited (KEV) flaws within days. 24. Network segmentation that limits east-west movement. 25. Application allowlisting or an equivalent control on critical servers. 26. Vulnerability scanning and external attack-surface monitoring.

Governance, testing and insurance (points 27 to 30)

The last four points separate a control set from a program. They confirm you rehearse the scenario, train people, carry insurance that matches your controls, and have worked through the legal and disclosure duties of an extortion event before the clock starts.

27. Tabletop exercise run within the last 12 months. 28. Security awareness and phishing-simulation program active and measured. 29. Cyber insurance reviewed, with your controls meeting the policy's stated requirements. 30. Legal and regulatory plan: a ransom-payment stance, breach-notification duties under GDPR and NIS2, and law-enforcement contacts.

What does your score mean, and what do you fix first?

Total your 60-point score and read the band. 0 to 24 is high risk: a common attack likely succeeds and recovery is uncertain. 25 to 42 is developing: you survive some scenarios but have exploitable gaps. 43 to 54 is solid: fix the specific low-scorers. 55 to 60 is mature: validate with an independent test.

  • 0 to 24, high risk: start with phishing-resistant MFA, an immutable backup, and a tested restore; those three moves prevent most total-loss outcomes.
  • 25 to 42, developing: close detection and segmentation gaps and run a tabletop.
  • 43 to 54, solid: attack your own lowest scores and verify each claim with evidence.
  • 55 to 60, mature: commission independent validation and adversary emulation.
  • Any single 0 in backups or MFA is a red flag regardless of your total.

How TuniCyberLabs helps

We run this assessment as a formal, evidence-based audit: validating backups with a live restore test, checking detection coverage, and pressure-testing your response with a tabletop, then handing you a prioritized remediation plan mapped to your score. We work with SMEs and scale-ups across the EU and North Africa.

Book a ransomware readiness audit: contact our team.

TAGS
RansomwareReadiness AssessmentBackupsIncident ResponseResilienceSME SecurityMFA

Frequently Asked Questions

How often should you test ransomware backups?

+

Test a full, end-to-end restore at least every 90 days and after any major infrastructure change. A backup that has never been restored is an assumption, not a recovery capability. Time the restore so you can compare it against your documented recovery objective, and rotate who performs it so recovery does not depend on one person.

What is the 3-2-1-1 backup rule?

+

The 3-2-1-1 rule means keeping three copies of your data on two different media types, with one copy offsite and one copy offline or immutable. The final one, an air-gapped or object-locked copy attackers cannot alter, is what specifically defeats ransomware that hunts down and encrypts connected backups.

Does cyber insurance require multi-factor authentication?

+

Most cyber insurers now require MFA on email, remote access, and privileged accounts as a condition of coverage, and may deny claims if it was missing. Beyond MFA, expect requirements for EDR, tested backups, and email filtering. Review your policy control checklist before renewal so a technicality does not void a payout.

What is the single most important ransomware control?

+

There is no single control, but a tested, immutable backup combined with phishing-resistant MFA prevents the most total-loss outcomes. MFA blocks the common credential-based initial access, and an immutable backup guarantees recovery even if encryption succeeds. Detection and segmentation then reduce how much damage occurs in between.

Should you pay a ransomware demand?

+

Paying is a last resort with no guarantee of a working decryptor or deletion of stolen data, and it may carry legal and sanctions risk. Decide your stance in advance, involve legal counsel and law enforcement, and treat a tested restore as the primary path. Payment should never be your only recovery plan.

How long does ransomware recovery take?

+

Recovery ranges from days to several weeks depending on backup quality, scope of encryption, and whether restores were rehearsed. Organizations with tested, immutable backups and a written runbook often recover core systems in days; those improvising from untested backups can take weeks and may never fully recover their data.

Need help with
this topic
?

Our team specializes in the technologies and strategies discussed in this article. Let’s talk about how we can help your business.

Get in Touch