Ransomware readiness
Ransomware readiness assessment for UK organisations
Ransomware readiness depends on more than endpoint protection. Organisations need controlled administration, vulnerability management, network and identity containment, protected backups, known recovery priorities, an exercised decision process and evidence that restoration works within acceptable business timescales.
Control checklist
What to verify first.
Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.
Identify the services, data and dependencies that the organisation must recover first.
Restrict privileged access and separate administrative activity from normal user work.
Prioritise vulnerabilities using exploitation and asset-criticality evidence.
Test rapid isolation for compromised identities, endpoints and network segments.
Protect backups from routine administrator compromise and destructive changes.
Record recovery time and recovery point requirements with accountable owners.
Test restoration of representative systems and data, not only backup completion.
Exercise technical, leadership, legal, communication and supplier decisions together.
Decision flow
Move from uncertainty to evidence.
The sequence keeps discovery, control changes and proof connected.
- 01
Prepare
Map business priorities, authority, communications and technical dependencies.
- 02
Contain
Limit attacker access and prevent a local event becoming organisation-wide.
- 03
Recover
Restore in business priority order from known, protected recovery points.
- 04
Improve
Turn exercise and incident evidence into owned control changes.
Assessment template
Record control status and evidence.
Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.
Related service
Cyber Resilience
Map essential services, test response decisions and validate recovery through realistic, business-led exercises.
Official sources
Continue with primary guidance.
Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.
Related analysis
Apply the guide to current risks.
July 2026 threat landscape: massive Patch Tuesday and supply chain disruption
Microsoft releases 570+ patches, CISA warns of Langflow vulnerabilities, and Coca-Cola suffers ransomware disruption. Speed of containment is paramount.
Read insight ↗
Healthcare cyber incidents: operational lessons from July 2026
Recent healthcare incidents show how cyber extortion can disrupt medical operations. These are the containment and resilience lessons for care providers.
Read insight ↗