Ransomware Preparedness in Practice: Crisis team meets during a cyber incident.

Ransomware Preparedness: How to Prepare Your Team for the Day It Happens.

Ransomware preparedness rarely fails due to technical issues. It fails because of the question of who is authorized to decide at 3:00 a.m. that the production environment should be taken offline. Organizations invest in backups, segmentation, and detection, only to discover during an actual incident that no one knows who has the authority to make that decision. The NCSC notes that the initial reaction is often to kick attackers off the network as quickly as possible, whereas it is precisely at that moment—when working systematically under pressure —that the difference is made between a controlled recovery and a second incident. Ransomware preparedness is therefore primarily a matter of team organization, not of tools.

The roles you assign in advance, not during

Ransomware preparedness starts with the realization that an attack can impact four different areas within an hour: technology, management, communications, and legal. In most organizations, those four areas have never been brought together in the same room before things go wrong. That is the first gap in the ransomware preparedness of virtually every company I come across.

The NCSC recommends always conducting exercises as part of a multidisciplinary team, which—in addition to management—should include a central point of contact for internal and external communication, someone responsible for reporting and support, a person in charge of IT system security, and someone authorized to make decisions. That last role is the most important and, at the same time, the most vaguely defined. Who is authorized to decide that 500 employees cannot work today? The manual for cyber drills details this organizational structure, including the alert schedule and the fixed consultation structure that you establish in advance.

In practical terms, ransomware preparedness means setting out four mandates in writing before anything happens. Who is authorized to isolate systems without seeking permission? Who is authorized to communicate externally on behalf of the organization? Who is authorized to seek external assistance, and up to what amount? And who makes the decision to pay? Without those mandates, the first critical hour is wasted searching for someone who dares to say yes.

The ransom decision has no place in the crisis

Asking whether you should pay is the worst possible question to ask for the first time while the systems are down. The police are clear on this: it’s best not to pay, because payment offers no guarantee that the data will be released and increases the likelihood that criminals will continue their activities. Anyone who does pay or is considering doing so is asked to always report this to the police, because payment information is valuable to the criminal investigation.

Strong ransomware preparedness means that the board has adopted and formalized this position in advance, as part of the ransomware preparedness strategy it promotes. Not as a moral statement, but as a decision with preconditions: under what circumstances do we deviate from this, who is authorized to make that decision, and what information must be on the table at that time. A board that makes this assessment for the first time while the phone is ringing off the hook will handle it poorly.

The same applies to the legal side of things. A ransomware attack almost always involves a data breach, because the attacker must have had access to the files in order to encrypt them, and this must be reported to the Dutch Data Protection Authority within 72 hours. That clock starts ticking at the moment of discovery, not when recovery is complete. Anyone who waits until the incident is underway to figure this out wastes hours that the team needs elsewhere. It helps to make this part of the conversations you’re already having to get your management team on board with security.

Backups you've never restored aren't really backups

Almost every organization claims to have backups. Significantly fewer organizations have ever restored an entire volume to measure how long it takes. The NCSC states that a good backup must be tested and verified for integrity—free of malware or unwanted encryption—and that only a restore test of an entire volume or system can reveal realistic recovery times. That figure is the foundation of your ransomware preparedness, because it determines what you can promise to your board.

The reality is often sobering. A restore that’s supposed to take eight hours on paper ends up taking three days in reality because the sequence of dependencies wasn’t thought through: you can’t start the application until the database is back online, and you can’t get the database back online until authentication is working. You only discover these kinds of chains by actually doing it once, and that’s precisely where ransomware preparedness proves its value. Schedule that test during a quiet period, with the people who would actually have to carry it out during an incident.

Ransomware preparedness also requires clarity on what you will not restore. Not every system needs to be back up and running within a day. By defining three categories in advance, the team knows exactly what to expect during an incident without having to hold a meeting about it. In practice, this saves half a day of discussion at the very moment when it’s most costly.

Communication has become a security task

In modern attacks, data is stolen first and only then encrypted, which changes the requirements for ransomware preparedness. This fundamentally alters the communication challenge: you not only have to explain a system outage, but possibly also a leak of customer data. Attackers nowadays publish data as a means of pressure, sometimes with a timeline that is publicly visible. Your communication is then racing against a clock that isn’t under your control.

One effective strategy for ransomware preparedness is to draft three messages in advance and have them approved: an internal announcement for employees, a message for customers or supply chain partners, and a statement in case the press calls. They don’t have to be perfect—they just need to be there. A draft that’s already prepared can be adapted within twenty minutes; a message written from scratch while everyone is talking over each other takes hours and contains errors that will later be used against you.

This is also where the connection to the security team’s day-to-day operations lies. A team that is accustomed to meticulously documenting its observations demonstrably communicates better under pressure. That is exactly what good work processes deliver, and why practical SOC playbooks are more valuable than extensive documentation that no one ever opens during an incident.

Practice is the only way to demonstrate readiness

A plan that has never been used is merely an assumption. The NCSC defines a good crisis exercise as one with pre-communicated exercise objectives and multiple rounds of consultation in which new information—known as “injects”—is continuously introduced, after which the team forms a picture of the situation, assesses it, and makes a decision. This approach reveals within two hours where the decision-making process is stalling. We developed a similar framework in our playbook for incident response exercises, which can be carried out without an external agency.

The difference between knowledge and skill is stark in this regard. Someone can explain exactly what containment entails and then freeze up when the moment actually arrives. That is why we consistently prioritize hands-on incident response training with simulations over theoretical modules, and why a course alone is not enough to ensure performance under pressure. Ransomware preparedness comes from having gone through it once, even if it was in a simulated setting.

Use that exercise to test the full scope of your ransomware preparedness, not just the technical aspects. The most valuable insights come from moments when the crisis team must choose between two bad options based on incomplete information. Have someone who isn’t participating observe as an independent observer, and conduct the evaluation in a setting where mistakes can be openly discussed. An evaluation where no one dares to say what went wrong is pointless.

The people who have to do it need to be able to do it

Ransomware preparedness stands or falls on a handful of people who know what they’re looking at. Someone must be able to determine whether the attacker is still inside the system, which accounts have been compromised, and whether data has been exfiltrated. That’s high-level analytical work, and it can be learned. The SOC T1 + T2 Analyst course lays the foundation for structured triage, while the SOC T3 Analyst course focuses on independent investigation and escalation. For organizations that want to be able to reconstruct exactly what happened after an incident, the Cyber Forensics Expert course provides the investigative skills, and the Windows Memory Forensics & Malware Analysis course delves deeper into the malware used.

The non-technical aspects can also be trained. Employees who dare to report a suspicious email instead of quietly deleting it measurably reduce the detection time; targeted Cyber Awareness Training focuses on that behavior. How to assign roles related to detection and response is detailed in our article on building a security team. And be mindful of the strain on that team: a group that has been suffering from alert fatigue for months will not perform well during a three-day crisis.

What happens if things go wrong

The return on investment for ransomware preparedness can be calculated. Every day that the primary process is down costs revenue, staffing, and recovery capacity; our overview of what a cyber incident truly costs outlines the calculation method. A team that manages to get through the first day typically shortens the total recovery time by several days. That’s the comparison you present to the board, not the number of blocked attacks.

The organizations that have this well in place don’t have a larger budget. They’ve defined their mandates, tested the recovery process, prepared three messages, and have a team that’s practiced this once. That can be organized within a quarter. The page for employers explains how we build that capacity together with teams, from open-enrollment classes to in-company programs in their own environment. If you’d like to see the course overview first, the page listing all training programs features the full range of offerings, including the comprehensive Cyber Security Specialist program for employees transitioning from an IT role into security. Want to assess how well-prepared your team really is against ransomware? Check out the upcoming start dates or schedule an introductory meeting to discuss which program is the best fit for your team.