Ransomware Resilience Package

Recovery Without Paying — Defense in Depth for Mid-Market (50–500 seats)

96%
of ransomware victims are SMBs
67%
of breaches have an identity-related root cause
21 days
median recovery time
$140K
median ransom paid — down 3 yrs running (DBIR 2026)
66%
of cases involve internal RDP
Methodology: Ransomware detection relies on universal baseline rules (shadow copy deletion, backup agent termination) that work across every environment. See Detection Engineering for the three-tier model.
Incident in progress? The response steps are on Ransomware Response. This page is how you get ready.
The question isn't "will you get hit" — it's "can you recover without paying?" 54% of victims recover via backups. 49% pay. 69–83% who pay get hit again. The entire program below is designed to put you in the 54% who recover, not the 49% who pay.
Attack timing: 88% of ransomware encryption happens outside business hours (nights/weekends). 79% of data theft also occurs off-hours. Your defenses must work when nobody is watching.
Why recovery itself is now the target: Mandiant's M-Trends 2026 reframes ransomware as "a resilience problem." Modern actors deliberately deny recovery by hitting your Trusted Service Infrastructure — identity, virtualization management, and backup planes — before they encrypt. The defensive goal is a recovery fabric architecturally severed from the production attack surface, which is exactly what the loops below prioritize.
A second track is emerging: exfiltration without encryption. Coveware/Veeam's Q2 2026 data shows median ransom payments falling (down 50% to $150K) while the average spikes (+176% to $1.88M) — driven by high-value, encryption-free data-theft extortion (Silent Ransom/Luna Moth against law firms via vishing, no malware at all). Unit 42 found encryption in only 78% of 2025 extortion cases, down from >90%. If your exposure is confidentiality (legal, healthcare, financial advisory), immutable backups don't cover this — exfiltration/DLP detection matters just as much.

Entry Point: Ransomware Readiness Assessment

Score each OODA loop. Determine if the organization can survive a ransomware event today. Identify the gap between current state and insurability.
1–2 days Entry point / loss leader

Most-Exploited Paths (2026)

Initial access is now overwhelmingly identity- and edge-device-driven — identity is the vector in 79% of 2026 intrusions (Sophos), RDP is present in 84% of lateral movement, and ClickFix-style social engineering (fake browser update → paste command → RMM install) sits behind 47% of Microsoft Defender Experts' observed attacks. By group: Akira/REDBIKE enters via edge-device CVEs (SonicWall SonicOS CVE-2024-40766) before pivoting to encrypt ESXi, Hyper-V, and now Nutanix AHV; a suspected China-nexus actor exploited the vCenter RCE CVE-2026-59310 within 5 days of disclosure directly against management planes; Kyber runs coordinated Windows+ESXi campaigns using native esxcli to shut down VMs before encrypting datastores; VECT moves laterally into ESXi/Linux via stolen SSH credentials; and Gunra modifies the authentication server directly so any attacker-chosen MFA code validates. The common sequence once inside, across all of them: enable SSH → disable ESXi lockdown mode → alter VIB signing policy → deploy payload.

Do Right Now — Mid-Market

Patch VPN/firewall firmware and, if running VMware, vCenter/ESXi specifically (CVE-2026-59310, CVE-2024-37085) — this closes the two most current exploited entry points in one pass. Enforce MFA on every VPN, RDP gateway, and admin console, disable RDP everywhere it isn't explicitly needed, and disable SSH on ESXi hosts in favor of Strict Lockdown Mode. Deploy Microsoft LAPS for unique local admin passwords, and verify — don't assume — that backups are immutable in Compliance mode (not Governance) with a timed restore on record. Since ESXi and NAS can't run EDR, centralize their logs and alert on snapshot deletion and SSH enablement as a compensating control.

Tools

Immediate Risk Check

# Find AD servers running out-of-support OS (62% of compromised servers)
Get-ADComputer -Filter {OperatingSystem -like "*2012*" -or OperatingSystem -like "*2008*"} `
  -Properties OperatingSystem | Select Name, OperatingSystem

# Find accounts with SPN set (Kerberoastable)
Get-ADUser -Filter {ServicePrincipalName -ne "$null"} `
  -Properties ServicePrincipalName | Select Name, ServicePrincipalName

# Find RDP exposed internally (should be restricted)
Get-NetTCPConnection -LocalPort 3389 -State Listen

Output

One-page maturity scorecard (red/amber/green per loop) + prioritized roadmap. Includes insurance gap analysis — what controls are missing for underwriting approval.

1 Containment — Evict the Attacker
Active ransomware incident. Encryption in progress or attacker discovered pre-encryption. Two playbooks that buy time: Kill Internet and Kill Authentication.
Quick Wins (Day 0, Free)
  • Document who has authority to kill internet access company-wide — before the crisis, not during
    15 minFree
  • Pre-define the business-critical allow-list (10–20 URLs the company cannot survive without). Must also account for DNS — C2 over DNS is real
    1 hourFree
  • Document every system with non-AD credentials that need separate rotation (hypervisors, NAS, Linux local accounts, network devices, printers, service accounts)
    2 hoursFree
  • Print emergency contact sheet: IT team personal phones, cyber insurer claim number, legal counsel, law enforcement (FBI IC3, local CERT)
    15 minFree
  • Set up out-of-band comms — Signal group or personal phones for the crisis team. Corporate email/Teams may be encrypted.
    10 minFree
Core Engagement (2 days)
  • Playbook 1 — Kill Internet: Deny all ingress/egress with pre-defined allow-list. Include DNS kill. Plan per-location, per-business-unit. Test that it actually works.
  • Playbook 2 — Kill Authentication: Revoke ALL sessions, rotate ALL credentials — not just AD. Include hypervisors, network devices, NAS, Linux, service accounts, application-specific creds. Start with domain admin/enterprise admin, expand outward.
  • Ransomware tabletop exercise: "It's Saturday 2 AM, file servers are encrypting, AD is compromised, backups status unknown." Walk the team through both playbooks.
  • Staff rotation policy for extended IR — max shift durations. AD restoration failure at hour 23 proves burnout kills recovery.
Target State

Both playbooks tested quarterly. Kill switches pre-configured in firewall. Credential inventory maintained and rotation automated. Crisis team can evict an attacker and begin recovery within 2 hours of detection, at any hour.

2 Detection — See It Before Encryption
Median time from initial access to encryption is 3–4 days. That's your detection window. If you can detect during lateral movement (before encryption), you can contain without data loss.
Quick Wins (Day 0, Free)
  • Scatter Canarytokens on file shares — fake "Payroll_2026.xlsx" and "passwords.docx". Ransomware encrypts everything, including canaries. Instant detection.
    30 minFree
  • Deploy OpenCanary honeypots — fake SMB/RDP/SSH services on each VLAN. Lateral movement hits them. Any connection = alert.
    4 hoursFree / OSS
  • Enable Windows Event Log forwarding for key events: Event ID 4625 (failed logons), 4648 (explicit credential logons), 4720 (account creation), 4732 (user added to admin group), 1102 (audit log cleared)
    2 hoursFree
  • Install CrowdSec on internet-facing systems — community-sourced IP blocking, detects brute force/scanning
    2 hoursFree / OSS
  • Enable PowerShell Script Block Logging (GPO) — ransomware operators use PowerShell extensively. Without logging, you're blind.
    30 minFree
  • Increase log retention to 365 days on every server — Windows Event Log defaults (20MB) overwrite in hours. Set to 1GB+ per channel. Linux syslog: 12 months. Forward to central logging AND keep on-host copies. 1TB disk costs less than a coffee per day. On-host logs are your forensic backup if central is compromised.
    1 hourLow cost
Core Engagement (2–3 days)
  • Deploy Wazuh (open-source XDR/SIEM) — agents on all endpoints, file integrity monitoring (detects mass encryption), active response (auto-isolate), log analysis
  • EDR deployment: Sophos Intercept X (CryptoGuard anti-encryption), Bitdefender GravityZone, or Huntress managed EDR ($5–15/device/month)
  • Configure off-hours alerting — 88% of encryption happens nights/weekends. Alerts must reach humans 24/7, not just during business hours.
  • RDP monitoring — alert on RDP sessions from unexpected sources (RDP is in 84% of lateral movement)
  • Deploy Velociraptor for endpoint forensic triage — real-time hunt for attacker artifacts across all endpoints
Target State

Lateral movement detected within hours. Mass file operations trigger automated isolation. Off-hours coverage via MDR or 24/7 alerting. Canary files and honeypots provide early warning across all network segments.

3 Posture — Harden the Attack Surface
The three things that matter most: identity (67% of breaches have an identity-related root cause — Sophos AAR 2026), RDP (66% of cases involve internal RDP), and backups (94% targeted by attackers). Harden these three and you've addressed the bulk of the attack chain.
Quick Wins (Day 0, Free)
  • Deploy Microsoft LAPS via GPO — unique local admin password per machine. Single biggest quick win for stopping lateral movement. Built into Windows, free.
    4–8 hoursFree (built into Windows)
  • Disable RDP on all machines where it's not needed. Where needed, require VPN + MFA. Never expose directly.
    1 hourFree
  • Disable SSH on ESXi hosts and enable Strict Lockdown Mode — manage only via vCenter or out-of-band (iLO/DRAC). The documented 2026 attack pattern across Kyber, VECT, and Akira is identical: enable SSH → disable lockdown → alter VIB policy → deploy payload.
    1 hourFree
  • Block legacy auth in Entra/AD — IMAP, POP3, SMTP basic auth, WMI, older PowerShell remoting
    30 minFree
  • Separate admin accounts from daily-use accounts — no one should browse email and manage AD with the same account
    2 hoursFree
  • Run PingCastle and fix the top 5 findings (usually: stale admin accounts, Kerberoastable SPNs, weak trust configurations)
    Half dayFree
  • Verify backup admin credentials are separate from domain admin — different accounts, different MFA
    30 minFree
  • Enable Controlled Folder Access (Windows Defender) on critical servers — blocks unauthorized processes from modifying protected folders
    30 minFree
Core Engagement (3–4 days)
  • Immutable backup implementation: 3-2-1-1 rule (3 copies, 2 media, 1 offsite, 1 immutable). S3 Object Lock / Wasabi / Backblaze B2 for WORM storage. Restic or BorgBackup with append-only repos.
  • Backup isolation: No domain join for backup servers. Separate VLAN. No network path from production to backup admin interface. Separate credentials.
  • Hypervisor/NAS compensating controls: ESXi and NAS can't run EDR — centralize hostd.log, shell.log, vobd.log, auth.log and alert on snapshot deletion, SSH enablement, VIB acceptance changes, and root password-change events. Set VMkernel.Boot.execInstalledOnly=TRUE, disable SLP (port 427).
  • Backup restore testing: Full server restore drill. Document actual RTO. If it takes 4 days to restore, that's your real RTO — not the 4 hours in the DR plan.
  • AD hardening: Tiered admin model (Tier 0: AD/identity, Tier 1: servers, Tier 2: workstations). Eliminate DA tokens on workstations. Remove out-of-support AD servers.
  • Network segmentation: VLANs for workstations, servers, backups, management. Firewall rules between zones. Backup infrastructure fully isolated.
  • MFA everywhere: VPN, RDP gateway, admin consoles, cloud services. FIDO2 for privileged accounts.
Target State

Backups are immutable, isolated, and tested. RDP restricted to VPN+MFA only. Every machine has a unique local admin password. Admin accounts are tiered. Network is segmented. Attacker who compromises one workstation cannot reach AD, backups, or other segments.

4 Vulnerability Management — Close the Doors
Unpatched edge devices (VPNs, firewalls) and out-of-support OS are mass-scanned by ransomware operators. Patch the perimeter first, then work inward.
Quick Wins (Day 0, Free)
  • Enroll in CISA Cyber Hygiene Services — free external vulnerability scanning, weekly reports. Email [email protected]
    15 min emailFree (US orgs)
  • Inventory all internet-facing services — VPN, RDP, firewalls, web apps, mail servers. If you don't know what's exposed, you can't patch it.
    2 hoursFree
  • Check CISA KEV catalog against your edge devices — these are actively exploited right now
    1 hourFree
  • Patch CVE-2026-59310 (vCenter RCE, CVSS 9.8, patched Jul 2026) and CVE-2024-37085 (AD-group ESXi auth bypass) if running VMware — both are confirmed under active ransomware-linked exploitation
    1–2 hoursFree
  • Run PingCastle monthly — track AD security score drift
    30 min/monthFree
  • Audit out-of-support systems — Windows Server 2012/2008, Windows 7/8. 62% of compromised AD servers run EOL OS.
    1 hourFree
  • Review BloodHound attack paths quarterly — new paths emerge as AD changes
    Half day/quarterFree
Core Engagement (1 day + cadence)
  • Patch SLA definition: Critical edge devices (VPN, firewall) — 48 hours. Critical internal — 7 days. High — 14 days. Medium — 30 days.
  • Edge device inventory + patching cadence: automated scanning, monthly patch cycle, emergency patch process for KEV additions
  • EOL migration plan: timeline and budget for replacing out-of-support systems
  • Backup restore testing cadence: monthly automated, quarterly full DR drill with documented RTO
  • Credential hygiene review: stale admin accounts, Kerberoastable SPNs, orphaned service accounts
Target State

Zero internet-facing systems with known exploited vulnerabilities. Zero out-of-support OS. Patch compliance dashboard with automated reporting. Monthly backup restore tests passing. AD attack paths reviewed and remediated quarterly.

5 Structural — Survive by Architecture
Make ransomware a survivable event, not an existential one. Architecture that limits blast radius, guarantees recovery, and satisfies insurance + regulatory requirements.
Quick Wins (Day 0, Free)
  • Write down the Tier 0 asset list — AD, Entra, identity infrastructure. Then Tier 1: payroll (almost always #1), ERP, core business apps. This determines recovery order.
    1 hourFree
  • Define Recovery Time Objectives per tier — how long can each system be down before unacceptable business impact?
    MeetingFree
  • Review the CISA #StopRansomware Guide — Part 1: Prevention, Part 2: Response checklist
    1 hourFree
Core Engagement (3–5 days)
  • Zero Trust network architecture: identity-verified access to every resource. No implicit trust from network location. Micro-segmentation where feasible.
  • Immutable infrastructure for critical systems: rebuild from code/image rather than restore from backup where possible. Infrastructure-as-code for rapid redeployment.
  • DR runbook with tested RTOs: step-by-step recovery for each tier. Named roles. Tested quarterly. Action cards, not 60-page documents.
  • Cyber insurance application preparation: document all controls against underwriting requirements. Pre-fill application with evidence. Target: 60–90 days to coverage.
  • Board reporting template: ransomware readiness posture, backup test results, patch compliance, insurance status. One page, quarterly.
  • NIS2 alignment: map controls to Article 21 (incident handling, business continuity, supply chain, crisis management)
Target State

Ransomware is a recoverable event. The organization can restore critical systems within defined RTOs from immutable backups. Insurance covers residual risk. Regulatory compliance demonstrated. Board informed quarterly.

Program Economics (200-seat reference)

EngagementDurationInvestment
Assessment + quick wins handoff1–2 days€1,250 – 2,500
1 Containment2 days€2,500
2 Detection2–3 days€2,500 – 3,750
3 Posture3–4 days€3,750 – 5,000
4 Vulnerability Mgmt1 day + monthly€1,250 + €5,000/yr
5 Structural3–5 days€3,750 – 6,250
Full program12–17 days€15,000 – 21,250 + retainer
ROI: Average ransomware downtime cost is $356K/day for mid-market. Median recovery takes 21 days. The full program costs less than one day of downtime. Average ransom demand is $613K — and 69–83% who pay get hit again.

Tooling Costs (borne by client)

CategoryOptions~Cost (200 seats)
EDRSophos Intercept X / Bitdefender / Huntress€12K–36K/yr
Immutable backupRestic/Borg + Wasabi/B2 Object Lock€1K–5K/yr
FIDO2 keys (admins)YubiKey for 20 privileged accounts€2K one-time
SIEM (optional)Wazuh (self-hosted, free)€0
MDR (optional)Huntress / Arctic Wolf / Sophos MDR€36K–72K/yr

Defense in Depth: Free Afternoon Deploy

12 controls deployable this week with zero budget. Each addresses a specific link in the ransomware kill chain.
#ActionTimeKillsTool
1Deploy Canarytokens on file shares30 minDetection gapCanarytokens
2Run PingCastle AD audit30 minAD attack surfacePingCastle
3Deploy Microsoft LAPS via GPO4–8 hrsLateral movementLAPS
4Disable RDP where not needed1 hour84% of attack chainsGPO
5Separate admin accounts from daily use2 hoursCredential theft valueAD
6Enable PowerShell Script Block Logging30 minAttacker invisibilityGPO
7Enable Windows Event Log forwarding2 hoursDetection blindnessGPO / WEC
8Install CrowdSec on edge systems2 hoursBrute force / scanningCrowdSec
9Enroll in CISA Cyber Hygiene15 minUnknown exposureCISA
10Deploy OpenCanary honeypots4 hoursLateral movement blindspotOpenCanary
11Verify backup admin creds are separate30 minBackup destructionManual check
12Enable Controlled Folder Access30 minUnauthorized encryptionWindows Defender

Cyber Insurance Readiness

41% of applications denied on first submission. 82% of denied claims involved organizations without MFA. These are the controls insurers mandate before binding a policy.

Mandatory (will not bind without)

ControlStatusAddressed In
MFA on email, VPN, RDP, admin99% askLoop 3
EDR on all endpointsRequiredLoop 2
Encrypted offline/immutable backupsRequiredLoop 3
Incident Response Plan (tested)RequiredLoop 1

Strongly Expected

ControlAddressed In
Network segmentationLoop 3
Privileged access managementLoop 3
Security awareness trainingLoop 5
Patch management with SLAsLoop 4
Email filtering (advanced)BEC Package
12+ character passwordsLoop 3
Timeline to coverage: 60–90 days from start. MFA (1–2 weeks) + EDR (2–4 weeks) + underwriting approval (2–4 weeks). The assessment identifies exactly which controls are missing.

Free / Open-Source Tools

Key PowerShell Commands

# AD servers on out-of-support OS
Get-ADComputer -Filter {
  OperatingSystem -like "*2012*" -or
  OperatingSystem -like "*2008*"
} -Properties OperatingSystem |
  Select Name, OperatingSystem

# Kerberoastable accounts
Get-ADUser -Filter {
  ServicePrincipalName -ne "$null"
} -Properties ServicePrincipalName |
  Select Name, ServicePrincipalName

# Stale admin accounts (90+ days)
$cutoff = (Get-Date).AddDays(-90)
Get-ADGroupMember "Domain Admins" |
  Get-ADUser -Properties LastLogonDate |
  Where-Object {
    $_.LastLogonDate -lt $cutoff
  } | Select Name, LastLogonDate

# Find forwarding rules (BEC crossover)
Get-Mailbox -ResultSize Unlimited |
  Get-InboxRule | Where-Object {
    $_.ForwardTo -or $_.RedirectTo
  }