Skip to content

Network

Ransomware
Readiness Assessment

How far one phished laptop gets before something stops it

Starts at $6,000, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need a ransomware readiness assessment

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Your insurer or your board is asking how far ransomware would actually get, and "we have backups" no longer settles it.
  • A cyber-insurance application asks about internal testing, MFA on privileged access, and whether backups are segmented and protected by their own credentials.
  • You have watched ransomware hit firms in your sector and want to know whether one phished laptop could reach your domain and your backups.
  • A phishing incident or a compromised account raised the question of what that access could have reached before anyone noticed.
  • You are a NYDFS-regulated firm and need evidence for 500.5 testing and the 500.16 requirement to maintain and test recovery from backups.

Definition

What is a ransomware readiness assessment?

A ransomware readiness assessment is a hands-on test of how far a ransomware operator would get inside your network, and whether you could detect them and recover. It is not a questionnaire or a maturity score. We start from an assumed breach, one phished laptop or one standard user account, and we walk the same kill chain a real group would: escalate to Domain Admin, reach the systems that matter, and try to reach and disable the backups, while noting exactly where your detection would have fired.

The engagement is the internal-network assumed-breach test, framed and reported for ransomware, from $6,000 for one domain of up to a few hundred hosts, the same as the internal penetration test Small tier. Three add-ons are charged at their published prices: a phishing simulation from $3,600 to measure the human entry point, a Microsoft 365 assessment from $4,200 for the cloud tenant, and an Active Directory assessment from $6,000 when the domain needs testing in more depth than the internal test gives it. There is no bundle markup and no bundle discount: the package is the sum of the tests in it.

Why backups are not enough

Why "we have backups" is only half an answer

Reliable, tested, offline backups remain essential. They are the answer to the encryption. But two things break the comfort they give. First, most modern ransomware groups steal data before they encrypt anything, so backups do nothing about the second extortion demand to stop the stolen data being published. Second, operators go after the backups themselves: they disable recovery, delete shadow copies, and remove backup catalogs before deploying (MITRE ATT&CK technique T1490), and if the backup system trusts the same domain the attacker just took over, there is nothing left to restore from.

So the useful question is not "do we have backups?" but "can the attacker reach them from where they land, and would we notice before they do?" This assessment answers exactly that. Our explainer on how modern ransomware attacks work covers the full kill chain the test follows.

What we look for

What a ransomware readiness assessment proves

Ransomware is an intrusion first and an encryption event last. We test the quiet middle where a real attack is won or lost, and prove, stage by stage, how far a foothold in your network would get.

Initial access exposure

The first link in the chain: the phished credential, the exposed service, or the unpatched host that lets an attacker in. The base engagement assumes this step has already happened; add an external test or a phishing simulation to measure it directly.

We test for

  • Exposed remote services and unpatched internet-facing systems, from an external test where in scope
  • MFA coverage on remote and privileged access
  • Phishing susceptibility, measured by a phishing simulation where added
  • Credentials already exposed in past breaches, where the external test is in scope
  • The realistic foothold we start the rest of the test from

The path to Domain Admin

The long, dangerous middle. From one ordinary account we work toward domain control the way a ransomware operator would, before any encryption.

We test for

  • Active Directory attack paths: Kerberos, delegation, ACL, and GPO abuse
  • Credential harvesting, relay, and reuse across hosts
  • Privilege escalation and lateral movement toward tier-zero control
  • Certificate services (ADCS) and hybrid Entra ID paths
  • The crown-jewel systems reachable once domain control is in hand

Backup reachability and immutability

The finding that decides whether you recover or pay. Modern operators disable and delete backups before they encrypt (MITRE ATT&CK T1490, Inhibit System Recovery).

We test for

  • Whether the accounts and paths an attacker holds can reach the backup systems
  • Shadow copies, backup catalogs, and recovery features an attacker would delete
  • Immutability and offline copies: whether any backup survives a domain compromise
  • Backup credentials reused from the general Active Directory
  • Whether a restore path exists that the attacker cannot also reach

Detection and EDR coverage

Encryption is the last thing that happens. Every earlier stage was a chance to detect and stop the attack, so we measure which ones would have fired.

We test for

  • Which kill-chain stages an alert would have fired on, and which ran silent
  • EDR coverage gaps on the hosts and paths that matter
  • Lateral movement and credential abuse that logging did or did not catch
  • The activity mapped to MITRE ATT&CK so your defenders can replay it
  • The log sources and alerts that would have caught the chain earlier

Segmentation and blast radius

Whether a foothold in one area can actually reach everything, or whether your network limits how far ransomware spreads.

We test for

  • Reachability from the foothold to critical and recovery systems
  • Flat-network paths that let one host reach the whole estate
  • Segmentation between user, server, and backup zones, tested in a segmentation test
  • Egress paths a group would use to exfiltrate before encrypting
  • The boundaries that hold, and the ones that only exist on the diagram

Recovery and response readiness

What happens after the alarm. We check the evidence that you could actually restore and respond, not just that a backup job runs.

We test for

  • Evidence of tested restores from backups, not just successful backup jobs
  • An incident response plan that assumes data was stolen, not only encrypted
  • Roles, contacts, and decision authority for a ransomware event
  • Whether recovery would meet the timelines the business needs
  • The gaps between "we have backups" and "we could actually recover"

What insurers and boards ask

The questions this assessment answers

Cyber-insurance applications and board reviews ask about the same controls a ransomware operator tests. This engagement produces the evidence, not just a yes.

What the assessment shows

Is internal testing performed, and how far could an attacker get?
The proven paths from one foothold to Domain Admin and the crown-jewel systems
Is MFA enforced on privileged and remote access?
Where MFA is missing or bypassable on the accounts that matter most
Are backups segmented and protected by their own credentials?
Whether the accounts and paths an attacker holds can reach, alter, or delete the backups
Would you detect an intrusion before encryption?
Which kill-chain stages would fire an alert and which would run silent, mapped to MITRE ATT&CK
Could you recover?
Evidence of tested restores and an incident response plan that assumes data was stolen, not just encrypted

The controls a cyber-insurance application asks about are the controls this test measures, so the report doubles as the evidence for your broker.

Where it fits

The CISA Ransomware Readiness Assessment, and where a real test goes further

CISA publishes a free Ransomware Readiness Assessment (RRA) inside its Cyber Security Evaluation Tool: a structured self-assessment that scores your practices against recognized standards. It is a good starting point, and we encourage teams to run it. What a self-assessment cannot do is prove whether the controls actually hold when someone attacks them.

This engagement is the test that answers what the questionnaire cannot: not "do we have segmentation and protected backups on paper?" but "can a tester who starts from one laptop reach the domain, the crown jewels, and the backups anyway?" The #StopRansomware Guide from CISA, the FBI, the NSA, and MS-ISAC recommends offline, encrypted backups, phishing-resistant MFA, network segmentation, and endpoint detection and response on all assets. Each of those maps onto something this test checks, and the report tells you which ones held.

Methodology

How a ransomware readiness assessment runs

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your ransomware readiness assessment runs through.

  1. 01

    Scope and rules

    The foothold, the crown-jewel systems, the backup estate, and the rules of engagement agreed in writing, with a fixed price.

  2. 02

    Assumed-breach start

    We begin from a standard user account or an unauthenticated foothold on the internal network, through a small appliance or virtual machine we provide, or a VPN.

  3. 03

    Walk the kill chain

    Escalation, lateral movement, and the path to Domain Admin, then toward the backups and crown-jewel systems, each step evidenced.

  4. 04

    Grade the defense

    Which stages detection would have caught, and whether backups could be reached, altered, or deleted, mapped to MITRE ATT&CK.

  5. 05

    Report and retest

    The attack narrative, the fixes that break the most paths, an attestation letter, and a free retest once your fixes ship.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping ransomware readiness assessment.

Still have questions? 
01What is a ransomware readiness assessment?

It is a hands-on test of how far a ransomware operator would get inside your network and whether you could detect and recover. Starting from an assumed breach, one phished laptop or one standard user account, senior testers walk the ransomware kill chain: escalate toward Domain Admin, move laterally to the crown-jewel systems, and try to reach and disable the backups, while grading which stages your detection would have caught. The output is an attack narrative, the specific paths to fix, and honest answers about backups, detection, and recovery.

02How is it different from a normal internal penetration test?

The technical work overlaps, but the framing and the extra checks differ. A ransomware readiness assessment is the internal assumed-breach test aimed specifically at the ransomware kill chain: it adds backup reachability and immutability testing, a detection-coverage review against MITRE ATT&CK, and a recovery-readiness check, and it reports in the terms an insurer or a board asks about. It starts at the same $6,000 as the internal test because it is the same engagement, focused.

03How much does a ransomware readiness assessment cost?

From $6,000, the internal-network assumed-breach test for one domain of up to a few hundred hosts, fixed in writing before work begins, with a free retest. Larger networks are priced on the internal network testing tiers. Add-ons are charged at their published prices: a phishing simulation from $3,600, a Microsoft 365 assessment from $4,200, and an in-depth Active Directory assessment from $6,000, with no bundle markup and no bundle discount. Starting prices for every service are on our pricing page.

04Do you actually try to reach and encrypt our backups?

We prove reachability, not destruction. We show whether the accounts and paths an attacker would hold can reach, alter, or delete your backups, whether backup credentials are reused from the general domain, and whether any offline or immutable copy would survive a full domain compromise. We never encrypt or delete anything: the finding is the proven path, documented with evidence, and we stop at the boundaries the rules of engagement set.

05Will this help with our cyber-insurance application?

Directly. Insurance applications ask about internal testing, MFA on privileged and remote access, whether backups are segmented and protected by their own credentials, and whether an intrusion would be detected before encryption. Those are exactly the controls this assessment tests, so the report and the attestation letter give your broker independent evidence rather than a self-attested yes. Our guide on whether cyber insurance requires a pentest covers what carriers ask and why a wrong answer can void a policy.

06Do you test whether our team would detect the attack?

Yes, as part of the assessment. Because encryption is the last step and every earlier stage is a chance to catch the attack, we record which stages would have fired an alert and which ran silent, and map the activity to MITRE ATT&CK so your defenders can replay the timeline against their own logs. If grading detection is the main goal rather than a by-product, a purple team assessment or a red team is the deeper engagement.

07What do we need to provide?

A foothold to start from, either a standard user account or an unauthenticated position on the internal network, reached through a small appliance or virtual machine we provide or a VPN you provide, plus a contact who can walk us through your backup and restore evidence for the recovery review, and a short scoping call. We agree in advance which systems must stay untouched and stop at those boundaries while documenting the path we would have taken.

Ready to test your defenses?

Talk to our team about scoping ransomware readiness assessment.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.