A ransomware readiness assessment is a structured check of whether your organisation could stop a ransomware attack, contain it and recover from it. It looks at three things: how attackers would get in, how far they could spread, and how quickly you could restore the systems your business depends on. The output is a ranked list of gaps, not a pass or fail.
Most small and mid-sized organisations already own some of the right controls. What they rarely know is whether those controls would hold up on a bad Tuesday. That is the question a ransomware readiness assessment answers, and it is cheaper to ask it now than during an attack.
Table of Contents
What does a ransomware readiness assessment cover?

The best assessments follow the attack, not a product list. Ransomware crews need a way in, a way to move, and a way to put pressure on you. A good review tests each stage.
- Entry points: exposed remote access, unpatched internet-facing systems, weak or reused passwords, and phishing resistance.
- Spread: flat networks, admin accounts used for everyday work, and shared credentials between systems.
- Detection: whether anyone would notice odd logins or mass file changes at 3am.
- Recovery: backups, restore speed, and who makes decisions during an incident.
The UK National Cyber Security Centre (NCSC) frames its own advice around four actions: make backups, prevent malware delivery and spread, prevent malware execution, and prepare for incidents. Those four make a sensible skeleton for any review.
How is it different from a penetration test?
A penetration test asks, “Can someone break in?” A readiness assessment asks, “If someone does, what happens next?” They overlap, but they answer different questions.
A pen test is hands-on. Testers try to exploit weaknesses in your systems, as an attacker would. An assessment is broader and often more about process: policies, backup evidence, response plans and staff roles. It may include technical checks, though it rarely tries to exploit anything.
Used together, they work well, because each one fills the gaps the other leaves. The assessment shows where your defences are thin, and an internal network penetration test proves whether an intruder could actually reach your most valuable systems from a single compromised laptop.
What questions should a good assessment ask?
You can run a first ransomware readiness assessment without a consultant. Work through these questions with your IT lead and be honest about the answers.
Backups
- Is there at least one backup copy that is offline or cannot be altered from the main network?
- When did you last restore from it, and how long did it take?
- Does the backup include everything the business needs, such as cloud data and line-of-business databases?
The NCSC puts it bluntly: “Up-to-date backups are the most effective way of recovering from a ransomware attack.” The word that matters is tested. A backup nobody has restored is a hope, not a plan.
Access and identity
- Is multi-factor authentication switched on for email, VPN and remote access?
- Do administrators use separate accounts for admin work?
- Is Remote Desktop Protocol exposed to the internet?
CISA’s #StopRansomware Guide recommends phishing-resistant MFA and limiting RDP exposure. Even ordinary MFA helps, but it has limits, as we explain in our piece on what MFA stops and what still gets through.
Patching and exposure
- Do you know every system that faces the internet?
- How fast do you patch critical flaws on firewalls, VPNs and mail servers?
Response
- Is there a written incident response plan, and does it include who to call out of hours?
- Has anyone rehearsed it?
- Do you know who would decide whether to involve the police, your insurer and the ICO?
CISA advises organisations to “create, maintain, and regularly exercise a basic cyber incident response plan” along with a communications plan. Plans that sit in a drawer tend to fail early, which we covered in why incident response plans fail in the first hour.
Is there a free ransomware readiness tool?
Yes. CISA published a Ransomware Readiness Assessment, available inside its CSET tool, which compares your answers against established good practice. It was built for US organisations, but the questions travel well.
Free tools are useful for a first pass, so use them to start. They rely on you answering accurately, though, and they cannot check your claims. Someone who says “we test backups” may mean “we tested them in 2022”.
How often should you run a ransomware readiness assessment?
Once a year is a reasonable baseline. Run one sooner after a major change: a cloud migration, an acquisition, a new remote working setup or a significant staff turnover in IT. Each of these changes who can reach what.
Who should take part in the review?
Do not leave it to IT alone. Ransomware is a business problem, so the people who run finance, operations and customer service should be in the room. They know which systems cannot go down for a day and which can wait a week.
Ask each team one plain question: “If this system vanished this morning, what would we do by lunchtime?” The answers often reveal manual workarounds nobody has written down. They also show which systems deserve the fastest recovery, so your restore order is based on real business need and not on guesswork.
Include whoever manages your suppliers too. Attackers regularly get in through a third party, and a vendor with remote access to your network is part of your exposure. Check what access they hold, whether it uses MFA, and whether it is switched off when no work is happening.
What happens after the assessment?
A good ransomware readiness assessment ends with a short, prioritised list. Fix the cheap, high-impact items first: switch on MFA, close exposed RDP, and run a real restore test. Then schedule the bigger projects, such as network segmentation.
If you want an independent view, Aardwolf Security is a UK penetration-testing firm, and our penetration testing services can check whether your defences hold up against a realistic attacker. You can also get in touch for a scoped quote.
Frequently asked questions
Does paying the ransom count as a recovery plan?
No. The NCSC says it does “not encourage, endorse nor condone the payment of ransom demands”. Paying gives no guarantee you get your data back, and it can mark you as a target for future attacks.
Is a small business really at risk?
Yes. Attackers often scan the internet for exposed systems and do not pick victims by size. A small firm with open remote access is just as easy to find as a large one.
Who should run the assessment?
Your IT team can do a first pass. For an unbiased view, use an outside specialist who has no stake in the answers looking good.
What is the single most useful thing to check first?
Restore a backup. If you can bring back a critical system within the time your business can tolerate, you have already beaten the main pressure ransomware gangs rely on.
Do I need a readiness assessment if I have Cyber Essentials?
Cyber Essentials covers important basics, and our Cyber Essentials service can help you get certified. But it does not test your recovery plan or your response, so the two work best side by side.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.