Call Book a fit call
Free resource

A readiness checklist for the morning you hope never happens.

Ransomware is a recovery problem long before it is a malware problem. Score yourself on the three lists below - the first one decides how bad it gets, the second how fast it ends.

Before - the controls that decide the outcome

Ransomware outcomes are mostly decided before the attack, by five or six unglamorous controls.

  • At least one backup copy is offline or immutable - a backup the ransomware can reach is not a backup
  • Somebody has watched a full restore succeed, recently, and knows how long it takes
  • MFA is on for email and every remote access path - VPN, remote desktop, admin portals
  • Updates land within 30 days on every machine, and unsupported systems are isolated or retired
  • Admin accounts are separate from daily accounts, so one clicked link cannot take the whole network
  • Endpoint protection runs on every computer and somebody would actually see its alerts

The first hour - decided in advance, on paper

When screens lock, nobody thinks clearly. The plan has to exist before, printed, where people can find it.

  • The first call is your cyber insurer’s breach line - calling vendors first can jeopardize coverage
  • Disconnect affected machines from the network - do not power them off, evidence lives in memory
  • One named person speaks for the office; everyone else preserves and does not touch
  • The plan exists on paper, off the systems that just locked - with insurer, bank, IT and legal numbers filled in
  • Nobody pays, promises or posts anything in hour one - those are decisions for daylight, with your insurer and counsel

The questions to answer this month

Five questions, answered while it is hypothetical, that are brutal to answer live.

  • Which three systems does the business actually stop without - and which gets restored first?
  • Could the office run a day on paper while systems come back? Has anyone thought it through?
  • Where are the backup credentials stored, and can the right person reach them if email is down?
  • Who are you legally required to notify, and when - PIPEDA for most businesses, PHIPA for health information in Ontario?
  • When did you last rehearse any of this - even as a 60-minute tabletop conversation?

Ready to see where you stand?

Start with a baseline security checkup. We review your environment, score the highest-risk gaps, and hand you a plain-English 30-day plan.

Book the baseline checkup - from $750+