← Insights and resources

Ransomware readiness

Ransomware readiness assessment for UK organisations

Ransomware readiness depends on more than endpoint protection. Organisations need controlled administration, vulnerability management, network and identity containment, protected backups, known recovery priorities, an exercised decision process and evidence that restoration works within acceptable business timescales.

Practical assessment guideReviewed UK organisations

Control checklist

What to verify first.

Use evidence from the real environment. A written policy without current configuration, ownership or testing is not enough.

  1. Identify the services, data and dependencies that the organisation must recover first.

  2. Restrict privileged access and separate administrative activity from normal user work.

  3. Prioritise vulnerabilities using exploitation and asset-criticality evidence.

  4. Test rapid isolation for compromised identities, endpoints and network segments.

  5. Protect backups from routine administrator compromise and destructive changes.

  6. Record recovery time and recovery point requirements with accountable owners.

  7. Test restoration of representative systems and data, not only backup completion.

  8. Exercise technical, leadership, legal, communication and supplier decisions together.

Decision flow

Move from uncertainty to evidence.

The sequence keeps discovery, control changes and proof connected.

  1. 01

    Prepare

    Map business priorities, authority, communications and technical dependencies.

  2. 02

    Contain

    Limit attacker access and prevent a local event becoming organisation-wide.

  3. 03

    Recover

    Restore in business priority order from known, protected recovery points.

  4. 04

    Improve

    Turn exercise and incident evidence into owned control changes.

Assessment template

Record control status and evidence.

Use the blank fields in a workshop or print this page. Mark a control evidenced only when the supporting record is current and attributable.

Control areaEvidence to locateStatusOwner / action
Critical services Prioritised service and dependency map Gap Partial Evidenced
Containment Identity, endpoint and network isolation procedures Gap Partial Evidenced
Protected recovery Backup access model, immutability and restore test Gap Partial Evidenced
Decision authority Named incident roles and out-of-hours contacts Gap Partial Evidenced
Exercise evidence Scenario, decisions, timings and owned improvements Gap Partial Evidenced

Related service

Cyber Resilience

Map essential services, test response decisions and validate recovery through realistic, business-led exercises.

Explore Cyber ResilienceDiscuss this assessment

Official sources

Continue with primary guidance.

Requirements and platform capabilities change. Confirm time-sensitive decisions against the current source.

Related analysis

Apply the guide to current risks.

Start with a conversation

Turn the assessment into an owned plan.

Share the scope, evidence and highest-priority gap. We’ll help define a proportionate next step for your environment.

Talk to an expert