Ransomware planning usually fails for one boring reason: nobody can tell what “ready” means. You hear advice like “have backups” or “train your staff”, but you still do not know whether you could keep the business moving next week if your systems got hit.

NIST’s ransomware risk management profile (NIST IR 8374 Revision 1) is basically a map of the outcomes that matter. You can turn it into a simple owner-friendly scorecard and use it to decide what to fix this quarter.

What NIST means by a “CSF 2.0 ransomware profile”

Think of the NIST Cybersecurity Framework (CSF) 2.0 as a menu of security outcomes. A “profile” is a curated set of those outcomes for a specific goal.

In this case, the goal is straightforward: reduce the chance of a ransomware event, and make sure you can respond and recover if it happens.

The CSF 2.0 is organised into six functions, and the ransomware profile maps what “good” looks like across all six. For this post, we are going to turn that into a scorecard you can use in a leadership meeting.

The 20-minute ransomware readiness scorecard (0, 1, 2)

Give each line a score:

  • 0: Not in place, or it exists on paper only.
  • 1: Partly in place, or in place but not dependable.
  • 2: In place, maintained, and you can prove it.

Your goal is not to get all 2s overnight. Your goal is to find the few 0s and 1s that would force you into paying because you cannot restore.

Governance: can you make calm decisions fast?

Ransomware is a business interruption problem first. Governance is where you decide who is allowed to make which calls, and what “acceptable downtime” even is.

Score yourself on these:

  • An owner for ransomware readiness. One named person is accountable for driving the plan (often a COO, CFO, or vCIO), not “IT in general”.
  • A written decision policy on ransom payments. You have a clear stance decided in advance, aligned with legal counsel and cyber insurance, so you are not debating it for the first time at 2am.
  • Business priorities are documented. You can name your top systems (email, ERP, line-of-business app, file shares) and the order they must come back.
  • Third-party dependencies are known. You know which vendors hold critical access or data (payroll, accounting, MSP tools, backups, EDR), and you have current contacts and escalation paths.

If you only do one governance task this quarter, do this: set two numbers for the business, your acceptable downtime and your acceptable data loss. Those targets drive every technical decision that follows.

Backups: could you restore clean, quickly, and at scale?

Backups are where a lot of “we’re fine” confidence goes to die. The hard part is not making copies. The hard part is making copies that ransomware cannot destroy, and then restoring enough to run the business.

Score yourself on these:

  • Backups are isolated from day-to-day access. At least one backup copy is offline or otherwise protected so normal admin credentials cannot simply delete or encrypt it.
  • Backup coverage matches how you work. You are backing up more than a server in a closet. That includes cloud data you rely on (for many businesses, Microsoft 365 data is the big one).
  • Restore tests are real. You are not just checking that a job “succeeded”. You are restoring files and systems on a schedule, and confirming they open and work.
  • A “known good” restore point exists. You can restore to a point in time before encryption and before any attacker tampering, and you have retention long enough to reach it.
  • Recovery is planned, not improvised. You have a written restore order (what comes back first, what can wait), and you know roughly how long each step takes.

A practical way to raise your score fast: run a restore drill that includes a business user. If they cannot do real work on the restored system, you did not actually test recovery.

Identity: can attackers still get in, and can they take over everything?

A lot of ransomware incidents start with stolen credentials. Once an attacker has the right account, they do not need movie-style hacking. They sign in and use the tools you already have.

Score yourself on these:

  • MFA is enforced for everyone, especially admins. Not “available”, not “encouraged”, enforced. Admin accounts should have stronger controls than standard users.
  • Admin access is limited and separated. People who do normal work all day are not also domain admins or global admins. Admin accounts are used only for admin tasks.
  • You can disable access quickly. You can lock accounts, revoke sessions, and reset credentials quickly during an incident, without breaking the ability to recover.
  • Device access is controlled. You have a way to prevent unknown or unmanaged devices from accessing sensitive systems, especially cloud apps.

If you are not sure where to start, start with your “keys to the kingdom” accounts: Microsoft 365 global admins, backup admin accounts, remote access accounts, and anything tied to finance.

Incident response: do you have a playbook for the first day?

When ransomware hits, speed matters, but not panic-speed. A simple, rehearsed process beats a 40-page binder nobody has read.

Score yourself on these:

  • A ransomware-specific response checklist exists. It covers isolation steps, who to call, what to preserve, and what not to do.
  • Logging and evidence are kept. You have logs that would help confirm what happened and what was touched, and you know how to preserve them.
  • Internal and external communications are planned. You have draft messages for staff, customers, and vendors, and you know who is allowed to send what.
  • A tabletop exercise has happened. You have walked through a ransomware scenario with leadership, IT, and operations, and updated the plan based on what broke.

A simple “this quarter” goal: do one 60-minute tabletop exercise. Pick a realistic scenario, like “file server encrypted at 9:15am on a Tuesday”, and walk through decisions and actions hour by hour.

What to do this quarter (a realistic 4-part plan)

If your scorecard showed a mix of 0s and 1s, do not try to fix everything at once. Pick the moves that most directly reduce the chance you would feel forced to pay.

  • Governance: set recovery targets and decision owners. Document your critical systems, set downtime and data loss targets, and name who owns the plan.
  • Backups: make one copy hard to destroy, then prove restore. Add an isolated backup copy and run a restore drill that brings back something the business actually uses.
  • Identity: tighten the accounts attackers love. Enforce MFA everywhere, separate admin accounts, and confirm you can rapidly disable access without locking out recovery.
  • Incident response: write the first-day checklist and rehearse it. A one to two page ransomware checklist plus a tabletop exercise will surface gaps faster than another security product.

Want a second set of eyes on your scorecard?

You do not need a perfect programme to be meaningfully more resilient by the end of the quarter. You need clear targets, a restore plan you have proven, and identity controls that keep one stolen password from becoming a full takeover.

If you would like help turning NIST’s ransomware profile into a practical plan for your business, the Flexnet Networks team can walk you through the scorecard and build a quarter-by-quarter roadmap.

Sources