Entry Point: Ransomware Readiness Assessment
Most-Exploited Paths (2026)
Initial access is now overwhelmingly identity- and edge-device-driven — identity is the vector in 79% of 2026 intrusions (Sophos), RDP is present in 84% of lateral movement, and ClickFix-style social engineering (fake browser update → paste command → RMM install) sits behind 47% of Microsoft Defender Experts' observed attacks. By group: Akira/REDBIKE enters via edge-device CVEs (SonicWall SonicOS CVE-2024-40766) before pivoting to encrypt ESXi, Hyper-V, and now Nutanix AHV; a suspected China-nexus actor exploited the vCenter RCE CVE-2026-59310 within 5 days of disclosure directly against management planes; Kyber runs coordinated Windows+ESXi campaigns using native esxcli to shut down VMs before encrypting datastores; VECT moves laterally into ESXi/Linux via stolen SSH credentials; and Gunra modifies the authentication server directly so any attacker-chosen MFA code validates. The common sequence once inside, across all of them: enable SSH → disable ESXi lockdown mode → alter VIB signing policy → deploy payload.
Do Right Now — Mid-Market
Patch VPN/firewall firmware and, if running VMware, vCenter/ESXi specifically (CVE-2026-59310, CVE-2024-37085) — this closes the two most current exploited entry points in one pass. Enforce MFA on every VPN, RDP gateway, and admin console, disable RDP everywhere it isn't explicitly needed, and disable SSH on ESXi hosts in favor of Strict Lockdown Mode. Deploy Microsoft LAPS for unique local admin passwords, and verify — don't assume — that backups are immutable in Compliance mode (not Governance) with a timed restore on record. Since ESXi and NAS can't run EDR, centralize their logs and alert on snapshot deletion and SSH enablement as a compensating control.
Tools
- CISA Ransomware Readiness Assessment (RRA) — self-assessment with scored dashboard
- PingCastle — AD security audit, runs in minutes, no installation
- BloodHound CE — map AD attack paths (how an attacker reaches Domain Admin)
- Backup recovery test — can you actually restore a server from backup right now?
Immediate Risk Check
# Find AD servers running out-of-support OS (62% of compromised servers)
Get-ADComputer -Filter {OperatingSystem -like "*2012*" -or OperatingSystem -like "*2008*"} `
-Properties OperatingSystem | Select Name, OperatingSystem
# Find accounts with SPN set (Kerberoastable)
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} `
-Properties ServicePrincipalName | Select Name, ServicePrincipalName
# Find RDP exposed internally (should be restricted)
Get-NetTCPConnection -LocalPort 3389 -State Listen
Output
One-page maturity scorecard (red/amber/green per loop) + prioritized roadmap. Includes insurance gap analysis — what controls are missing for underwriting approval.
- Document who has authority to kill internet access company-wide — before the crisis, not during
- Pre-define the business-critical allow-list (10–20 URLs the company cannot survive without). Must also account for DNS — C2 over DNS is real
- Document every system with non-AD credentials that need separate rotation (hypervisors, NAS, Linux local accounts, network devices, printers, service accounts)
- Print emergency contact sheet: IT team personal phones, cyber insurer claim number, legal counsel, law enforcement (FBI IC3, local CERT)
- Set up out-of-band comms — Signal group or personal phones for the crisis team. Corporate email/Teams may be encrypted.
- Playbook 1 — Kill Internet: Deny all ingress/egress with pre-defined allow-list. Include DNS kill. Plan per-location, per-business-unit. Test that it actually works.
- Playbook 2 — Kill Authentication: Revoke ALL sessions, rotate ALL credentials — not just AD. Include hypervisors, network devices, NAS, Linux, service accounts, application-specific creds. Start with domain admin/enterprise admin, expand outward.
- Ransomware tabletop exercise: "It's Saturday 2 AM, file servers are encrypting, AD is compromised, backups status unknown." Walk the team through both playbooks.
- Staff rotation policy for extended IR — max shift durations. AD restoration failure at hour 23 proves burnout kills recovery.
Both playbooks tested quarterly. Kill switches pre-configured in firewall. Credential inventory maintained and rotation automated. Crisis team can evict an attacker and begin recovery within 2 hours of detection, at any hour.
- Scatter Canarytokens on file shares — fake "Payroll_2026.xlsx" and "passwords.docx". Ransomware encrypts everything, including canaries. Instant detection.
- Deploy OpenCanary honeypots — fake SMB/RDP/SSH services on each VLAN. Lateral movement hits them. Any connection = alert.
- Enable Windows Event Log forwarding for key events: Event ID 4625 (failed logons), 4648 (explicit credential logons), 4720 (account creation), 4732 (user added to admin group), 1102 (audit log cleared)
- Install CrowdSec on internet-facing systems — community-sourced IP blocking, detects brute force/scanning
- Enable PowerShell Script Block Logging (GPO) — ransomware operators use PowerShell extensively. Without logging, you're blind.
- Increase log retention to 365 days on every server — Windows Event Log defaults (20MB) overwrite in hours. Set to 1GB+ per channel. Linux syslog: 12 months. Forward to central logging AND keep on-host copies. 1TB disk costs less than a coffee per day. On-host logs are your forensic backup if central is compromised.
- Deploy Wazuh (open-source XDR/SIEM) — agents on all endpoints, file integrity monitoring (detects mass encryption), active response (auto-isolate), log analysis
- EDR deployment: Sophos Intercept X (CryptoGuard anti-encryption), Bitdefender GravityZone, or Huntress managed EDR ($5–15/device/month)
- Configure off-hours alerting — 88% of encryption happens nights/weekends. Alerts must reach humans 24/7, not just during business hours.
- RDP monitoring — alert on RDP sessions from unexpected sources (RDP is in 84% of lateral movement)
- Deploy Velociraptor for endpoint forensic triage — real-time hunt for attacker artifacts across all endpoints
Lateral movement detected within hours. Mass file operations trigger automated isolation. Off-hours coverage via MDR or 24/7 alerting. Canary files and honeypots provide early warning across all network segments.
- Deploy Microsoft LAPS via GPO — unique local admin password per machine. Single biggest quick win for stopping lateral movement. Built into Windows, free.
- Disable RDP on all machines where it's not needed. Where needed, require VPN + MFA. Never expose directly.
- Disable SSH on ESXi hosts and enable Strict Lockdown Mode — manage only via vCenter or out-of-band (iLO/DRAC). The documented 2026 attack pattern across Kyber, VECT, and Akira is identical: enable SSH → disable lockdown → alter VIB policy → deploy payload.
- Block legacy auth in Entra/AD — IMAP, POP3, SMTP basic auth, WMI, older PowerShell remoting
- Separate admin accounts from daily-use accounts — no one should browse email and manage AD with the same account
- Run PingCastle and fix the top 5 findings (usually: stale admin accounts, Kerberoastable SPNs, weak trust configurations)
- Verify backup admin credentials are separate from domain admin — different accounts, different MFA
- Enable Controlled Folder Access (Windows Defender) on critical servers — blocks unauthorized processes from modifying protected folders
- Immutable backup implementation: 3-2-1-1 rule (3 copies, 2 media, 1 offsite, 1 immutable). S3 Object Lock / Wasabi / Backblaze B2 for WORM storage. Restic or BorgBackup with append-only repos.
- Backup isolation: No domain join for backup servers. Separate VLAN. No network path from production to backup admin interface. Separate credentials.
- Hypervisor/NAS compensating controls: ESXi and NAS can't run EDR — centralize hostd.log, shell.log, vobd.log, auth.log and alert on snapshot deletion, SSH enablement, VIB acceptance changes, and root password-change events. Set
VMkernel.Boot.execInstalledOnly=TRUE, disable SLP (port 427). - Backup restore testing: Full server restore drill. Document actual RTO. If it takes 4 days to restore, that's your real RTO — not the 4 hours in the DR plan.
- AD hardening: Tiered admin model (Tier 0: AD/identity, Tier 1: servers, Tier 2: workstations). Eliminate DA tokens on workstations. Remove out-of-support AD servers.
- Network segmentation: VLANs for workstations, servers, backups, management. Firewall rules between zones. Backup infrastructure fully isolated.
- MFA everywhere: VPN, RDP gateway, admin consoles, cloud services. FIDO2 for privileged accounts.
Backups are immutable, isolated, and tested. RDP restricted to VPN+MFA only. Every machine has a unique local admin password. Admin accounts are tiered. Network is segmented. Attacker who compromises one workstation cannot reach AD, backups, or other segments.
- Enroll in CISA Cyber Hygiene Services — free external vulnerability scanning, weekly reports. Email
[email protected] - Inventory all internet-facing services — VPN, RDP, firewalls, web apps, mail servers. If you don't know what's exposed, you can't patch it.
- Check CISA KEV catalog against your edge devices — these are actively exploited right now
- Patch CVE-2026-59310 (vCenter RCE, CVSS 9.8, patched Jul 2026) and CVE-2024-37085 (AD-group ESXi auth bypass) if running VMware — both are confirmed under active ransomware-linked exploitation
- Run PingCastle monthly — track AD security score drift
- Audit out-of-support systems — Windows Server 2012/2008, Windows 7/8. 62% of compromised AD servers run EOL OS.
- Review BloodHound attack paths quarterly — new paths emerge as AD changes
- Patch SLA definition: Critical edge devices (VPN, firewall) — 48 hours. Critical internal — 7 days. High — 14 days. Medium — 30 days.
- Edge device inventory + patching cadence: automated scanning, monthly patch cycle, emergency patch process for KEV additions
- EOL migration plan: timeline and budget for replacing out-of-support systems
- Backup restore testing cadence: monthly automated, quarterly full DR drill with documented RTO
- Credential hygiene review: stale admin accounts, Kerberoastable SPNs, orphaned service accounts
Zero internet-facing systems with known exploited vulnerabilities. Zero out-of-support OS. Patch compliance dashboard with automated reporting. Monthly backup restore tests passing. AD attack paths reviewed and remediated quarterly.
- Write down the Tier 0 asset list — AD, Entra, identity infrastructure. Then Tier 1: payroll (almost always #1), ERP, core business apps. This determines recovery order.
- Define Recovery Time Objectives per tier — how long can each system be down before unacceptable business impact?
- Review the CISA #StopRansomware Guide — Part 1: Prevention, Part 2: Response checklist
- Zero Trust network architecture: identity-verified access to every resource. No implicit trust from network location. Micro-segmentation where feasible.
- Immutable infrastructure for critical systems: rebuild from code/image rather than restore from backup where possible. Infrastructure-as-code for rapid redeployment.
- DR runbook with tested RTOs: step-by-step recovery for each tier. Named roles. Tested quarterly. Action cards, not 60-page documents.
- Cyber insurance application preparation: document all controls against underwriting requirements. Pre-fill application with evidence. Target: 60–90 days to coverage.
- Board reporting template: ransomware readiness posture, backup test results, patch compliance, insurance status. One page, quarterly.
- NIS2 alignment: map controls to Article 21 (incident handling, business continuity, supply chain, crisis management)
Ransomware is a recoverable event. The organization can restore critical systems within defined RTOs from immutable backups. Insurance covers residual risk. Regulatory compliance demonstrated. Board informed quarterly.
Program Economics (200-seat reference)
| Engagement | Duration | Investment |
|---|---|---|
| Assessment + quick wins handoff | 1–2 days | €1,250 – 2,500 |
| 1 Containment | 2 days | €2,500 |
| 2 Detection | 2–3 days | €2,500 – 3,750 |
| 3 Posture | 3–4 days | €3,750 – 5,000 |
| 4 Vulnerability Mgmt | 1 day + monthly | €1,250 + €5,000/yr |
| 5 Structural | 3–5 days | €3,750 – 6,250 |
| Full program | 12–17 days | €15,000 – 21,250 + retainer |
Tooling Costs (borne by client)
| Category | Options | ~Cost (200 seats) |
|---|---|---|
| EDR | Sophos Intercept X / Bitdefender / Huntress | €12K–36K/yr |
| Immutable backup | Restic/Borg + Wasabi/B2 Object Lock | €1K–5K/yr |
| FIDO2 keys (admins) | YubiKey for 20 privileged accounts | €2K one-time |
| SIEM (optional) | Wazuh (self-hosted, free) | €0 |
| MDR (optional) | Huntress / Arctic Wolf / Sophos MDR | €36K–72K/yr |
Defense in Depth: Free Afternoon Deploy
| # | Action | Time | Kills | Tool |
|---|---|---|---|---|
| 1 | Deploy Canarytokens on file shares | 30 min | Detection gap | Canarytokens |
| 2 | Run PingCastle AD audit | 30 min | AD attack surface | PingCastle |
| 3 | Deploy Microsoft LAPS via GPO | 4–8 hrs | Lateral movement | LAPS |
| 4 | Disable RDP where not needed | 1 hour | 84% of attack chains | GPO |
| 5 | Separate admin accounts from daily use | 2 hours | Credential theft value | AD |
| 6 | Enable PowerShell Script Block Logging | 30 min | Attacker invisibility | GPO |
| 7 | Enable Windows Event Log forwarding | 2 hours | Detection blindness | GPO / WEC |
| 8 | Install CrowdSec on edge systems | 2 hours | Brute force / scanning | CrowdSec |
| 9 | Enroll in CISA Cyber Hygiene | 15 min | Unknown exposure | CISA |
| 10 | Deploy OpenCanary honeypots | 4 hours | Lateral movement blindspot | OpenCanary |
| 11 | Verify backup admin creds are separate | 30 min | Backup destruction | Manual check |
| 12 | Enable Controlled Folder Access | 30 min | Unauthorized encryption | Windows Defender |
Cyber Insurance Readiness
Mandatory (will not bind without)
| Control | Status | Addressed In |
|---|---|---|
| MFA on email, VPN, RDP, admin | 99% ask | Loop 3 |
| EDR on all endpoints | Required | Loop 2 |
| Encrypted offline/immutable backups | Required | Loop 3 |
| Incident Response Plan (tested) | Required | Loop 1 |
Strongly Expected
| Control | Addressed In |
|---|---|
| Network segmentation | Loop 3 |
| Privileged access management | Loop 3 |
| Security awareness training | Loop 5 |
| Patch management with SLAs | Loop 4 |
| Email filtering (advanced) | BEC Package |
| 12+ character passwords | Loop 3 |
Free / Open-Source Tools
- PingCastle — AD security audit
- BloodHound CE — AD attack path analysis
- Microsoft LAPS — Local admin password rotation
- Lithnet Access Manager — LAPS web portal
- Wazuh — Open-source XDR + SIEM
- Velociraptor — Endpoint forensic triage
- Restic — Encrypted immutable backups
- BorgBackup — Deduplicating append-only backups
- CrowdSec — Community intrusion prevention
- Canarytokens — Free tripwires
- OpenCanary — Honeypot services
- CISA StopRansomware — Guides + free tools
Key PowerShell Commands
# AD servers on out-of-support OS
Get-ADComputer -Filter {
OperatingSystem -like "*2012*" -or
OperatingSystem -like "*2008*"
} -Properties OperatingSystem |
Select Name, OperatingSystem
# Kerberoastable accounts
Get-ADUser -Filter {
ServicePrincipalName -ne "$null"
} -Properties ServicePrincipalName |
Select Name, ServicePrincipalName
# Stale admin accounts (90+ days)
$cutoff = (Get-Date).AddDays(-90)
Get-ADGroupMember "Domain Admins" |
Get-ADUser -Properties LastLogonDate |
Where-Object {
$_.LastLogonDate -lt $cutoff
} | Select Name, LastLogonDate
# Find forwarding rules (BEC crossover)
Get-Mailbox -ResultSize Unlimited |
Get-InboxRule | Where-Object {
$_.ForwardTo -or $_.RedirectTo
}