Ransomware-resistant versioned backups, a documented and tested incident response plan, and containment measured in minutes rather than hours.
By The Numbers
Average attacker time-to-ransom
Containment once a threat is confirmed
Restores rehearsed, not assumed
The Real Problem
Ransomware is not instant. From first foothold to encryption, attackers typically spend the better part of a day inside — moving laterally, finding the backups, and disabling what would have saved you. That window is the whole opportunity, and organisations lose it because nothing was watching, or because what was watching only sent an email.
The second half of the problem is recovery. Almost everyone has backup; far fewer have a tested restore with a known duration and a documented order of operations. The gap between those two things is measured in weeks of lost business.
What’s Included
Online and offline copies with full file history, so there is always a clean point before the encryption began.
A copy beyond the reach of a network intrusion, because a backup an attacker can encrypt is not a backup.
Confirmed threats contained on detection — hosts isolated and accounts disabled while the attack is still in progress.
A written runbook naming who does what, rehearsed rather than drafted and filed.
A real, timed answer to how long a full restore takes — before leadership has to ask during an outage.
Every incident produces specific improvements, so the same path cannot be used twice.
Common Questions
Affected hosts are isolated and compromised accounts disabled, usually within minutes of confirmation. Then recovery follows a documented order rather than an argument.
Because they get tested. Scheduled test restores with the result written down are the only meaningful evidence.
The goal is to make that question irrelevant. A clean, isolated restore point and a rehearsed recovery turns an extortion event into an outage.
Related
If the answer is unclear, that’s the finding. We’ll test one with you and time it honestly.