1. Test Your Backups and Restoration Process
Having backups is fundamental, but untested backups are merely a prayer. Ransomware attackers now deliberately target and encrypt backup files to eliminate recovery options and force a payout. The gold standard is the 3-2-1 rule: maintain at least three
copies of your data on two different types of media, with at least one copy stored offline or in an immutable format—meaning it cannot be altered or deleted. During this awareness month, don't just verify that backups are running. Conduct a full restoration drill. Can you actually recover critical systems within your target time? If you’ve never tested a full restore, you don't have a recovery plan; you have a recovery wish.
2. Run a Phishing Simulation
More than 90% of successful cyberattacks begin with a phishing email. The human element remains the most exploited part of the attack surface. Threat actors use sophisticated, personalized emails to trick employees into clicking malicious links or divulging credentials. An effective way to gauge your readiness is to run a phishing simulation. These controlled tests mimic real-world phishing attacks, providing a safe way to see how employees respond. The goal isn't to punish those who click, but to use the results as a learning opportunity, identifying gaps in awareness and tailoring future training to address specific weak spots. A well-trained workforce that can recognize, reject, and report suspicious emails is one of your most effective defenses.
3. Review and Rehearse Your Incident Response Plan
When a ransomware attack hits, chaos is the enemy. A well-documented Incident Response Plan (IRP) ensures everyone knows their role and can act decisively under pressure. This plan should be more than a document sitting on a server; it should be a playbook rehearsed by your team. Conduct a tabletop exercise where you walk stakeholders—from IT to legal to executive leadership—through a realistic ransomware scenario. Do they know who to contact? What are the immediate steps for containment, like isolating infected systems? Is there a clear communication plan? You should also have printed copies of the plan, as a network-wide encryption event could make digital files inaccessible.
4. Audit Access Controls and Permissions
Attackers often rely on overly broad user permissions to move laterally through a network after gaining an initial foothold. The principle of least privilege is a powerful defense: every user and system should only have the absolute minimum level of access required to perform its function. Use this month to conduct a thorough audit of access controls. Review who has administrative rights. Do former employees still have active accounts? Are there service accounts with passwords that never expire? Pay special attention to access for remote tools like VPNs and Remote Desktop Protocol (RDP), which are common entry points for attackers. Enforcing multi-factor authentication (MFA) everywhere possible is one of the single most effective steps to block credential-based attacks.
5. Assess Your Patch Management Cadence
Unpatched vulnerabilities in software and operating systems are open doors for cybercriminals. Many ransomware attacks succeed not by using exotic, zero-day exploits, but by taking advantage of known vulnerabilities that organizations have failed to patch. A robust patch management program is therefore critical. Review your current process. How quickly are you able to deploy critical security patches, especially for internet-facing systems? Prioritize patching based on risk, focusing on vulnerabilities known to be exploited in the wild, as listed in resources like CISA's Known Exploited Vulnerabilities (KEV) catalog. An effective, timely patching strategy closes the window of opportunity for attackers before they can strike.
6. Evaluate Your Cyber Insurance Policy
In the event of a catastrophic attack, a cyber insurance policy can be a financial lifeline. However, not all policies are created equal, and the market is hardening. It's crucial to understand exactly what your policy covers—and what it doesn't. Does it cover the cost of ransom payments, business interruption losses, and data recovery services? What are the specific requirements for making a claim? Many insurers now mandate that clients have specific security controls in place, such as MFA and endpoint detection, as a condition of coverage. Review your policy with your legal counsel and broker to ensure it aligns with your risk profile and that you are in full compliance with its requirements before an incident occurs.













