CISO Tribune

Analysis

Ransomware readiness: the leadership checklist that actually matters

What executives and boards should verify about ransomware preparedness — recovery reality, decision rights, and the questions that expose gaps.

By CISO Tribune Editorial · Published July 9, 2026 · 2 min read

TL;DR: Ransomware readiness is measured in hours-to-restore, not tools deployed. The leadership job is verifying four uncomfortable realities: that backups actually restore (proven by drill, not policy), that the payment decision has an owner and a rehearsal, that the business can limp without its systems, and that the insurance policy says what everyone assumes it says.

What does ransomware actually test?

Not your prevention stack — your recovery reality. Modern operators don't just encrypt; they exfiltrate first and extort twice (decryption plus non-publication), target backups deliberately, and time detonation for maximum leverage. The scenario therefore stresses four things simultaneously: technical recovery (can you rebuild?), business continuity (can you operate meanwhile?), decision-making under extortion (who chooses what, how fast?), and disclosure (multiple regulatory clocks start — NYDFS explicitly covers ransomware deployment and extortion payments; the SEC's materiality question arrives on day one).

What are the four leadership verifications?

1. Restoration, proven. Not "we have backups" — when did we last restore the crown-jewel systems from them, end to end, and how long did it take? The honest answer is the company's real recovery time objective, whatever the document says. Backups must also be isolated or immutable, because attackers hunt them first.

2. The payment decision, rehearsed. Who owns the pay/don't-pay call? Legal must brief the sanctions constraint (payments to sanctioned entities are prohibited, full stop); the insurer has contractual say; negotiation firms exist and the IR retainer should name one. This decision should be made calmly once in a tabletop before it's made desperately at 3 a.m.

3. Manual-mode capacity. How long can order-taking, payroll, patient care, or production run degraded? The companies that suffer least aren't the ones that recover fastest — they're the ones that could function meanwhile. This is a business-continuity question security can't answer alone.

4. Insurance, actually read. Ransomware sub-limits, panel requirements, notice deadlines, the war exclusion, and whether the application's control claims (MFA coverage, backup isolation) still match reality — because at claim time, they'll be checked.

What belongs on the prevention side?

The short, unfashionable list that maps to how these incidents actually start: MFA on all remote access and privileged accounts; EDR deployed and monitored (a 2 a.m. alert nobody sees is decoration); aggressive patching of internet-facing systems; privileged access management; and email defenses paired with a reporting culture. Every one of these appears on cyber-insurance applications for a reason — carriers have the loss data.

How should leadership exercise this?

One executive tabletop a year on a ransomware scenario with teeth: backups partially compromised, data exfiltrated, a deadline, a journalist. Force the real decisions — pay or not, disclose when, restore or rebuild, what to tell customers on day one. Then fund whatever the exercise exposed. The pattern across public incidents is consistent: the differentiator was never the sophistication of the attack; it was whether the victim had practiced being one.

Frequently asked questions

What should a board ask about ransomware readiness?
Four questions: When did we last actually restore critical systems from backup, and how long did it take? Who decides whether we pay, and have they rehearsed it? How long can the business operate without its core systems? And does our insurance actually cover this scenario, on terms we've read?
Should companies pay ransomware demands?
Payment is a last-resort business and legal decision, not a security one: it is legally constrained (sanctions), doesn't guarantee recovery, and marks the payer for repeat targeting. The honest preparation is making payment unnecessary through tested recovery — and rehearsing the decision anyway.
What is the most important ransomware control?
Tested, isolated backups — specifically the tested part. Untested backups are a hypothesis. After that: MFA on remote access and privileged accounts, EDR coverage, and a practiced incident decision process.

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.