Executive self-assessment

Ransomware Preparedness Assessment

Measure whether your organization can reduce ransomware impact, contain spread, recover critical services, and make executive decisions under pressure.

Result logic

What this tool evaluates

Evaluates identity, endpoints, vulnerability, segmentation, backup/recovery, incident response, communications, and critical dependencies.

Identity & privilege 22%
Prevention & exposure 22%
Containment 16%
Backup & recovery 25%
Response & decisions 15%
0 / 10
0%
01 Is MFA enforced for administrators, remote access, cloud control planes, and other high-risk access paths?
02 Are privileged accounts minimized, separated, monitored, and recoverable if the main identity environment is compromised?
03 Are high-risk vulnerabilities and exposed services prioritized using exploitability and business criticality?
04 Is endpoint detection/protection deployed and monitored across critical endpoints and servers?
05 Can compromised users, endpoints, servers, cloud workloads, and network segments be isolated quickly?
06 Are backups isolated/immutable enough to resist administrative compromise or ransomware deletion?
07 Have critical systems been restored from backup in a timed, realistic exercise?
08 Are recovery priorities, dependencies, RTO/RPO assumptions, and business validation documented?
09 Are ransomware-specific executive, legal, insurer, customer, regulator, and communications decision paths prepared?
10 Has the organization run a ransomware tabletop that includes loss of identity, endpoints, and key services?