Skip to content
FioSec Consulting

3-minute resilience check

Could you recover from ransomware without paying?

Ransomware comes down to two things: stopping it, and recovering if it gets through. Answer ten quick questions for an honest read on both. Nothing is sent anywhere: your answers are scored right here in your browser.

Ransomware resilience questions

How it’s weighted: the two backup questions count double. Recovery hinges on them: if your backups survive and a restore works, you have options other than paying.

Stopping it

01 · Email filtering

Is inbound email filtered for phishing and malicious attachments before it reaches inboxes?

02 · Phishing awareness

Are staff tested with regular phishing simulations, so the lures that get through are less likely to work?

03 · Multi-factor authentication

Is multi-factor authentication (MFA) enforced on logins, especially remote access and admin accounts?

04 · Endpoint protection

Do endpoints run endpoint detection & response (EDR) that flags ransomware by its behaviour, not just signature-based antivirus?

05 · Patching

Are internet-facing systems patched promptly?

06 · Remote access

Is remote access locked down, with no RDP or similar services exposed directly to the internet?

07 · Network containment

Is your network segmented, so ransomware on one machine can’t spread across everything?

Recovering

08 · Backups: protected counts double

Are backups immutable or air-gapped, so an attacker can’t encrypt or delete them?

09 · Backups: tested counts double

Have you test-restored recently, and do you know your realistic time to full recovery?

10 · Response plan

Do you have a ransomware-specific incident response plan: who to call, and how you’d communicate if systems were down?

Ten questions. Answer “Partly” when a defence covers only some of your environment; “Not sure” is a valid answer too. No email required; scored in your browser, never sent anywhere.