Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

Guided Defense Playbooks

Ransomware Resilience

Reduce ransomware entry and spread, protect recoverability, detect destructive activity, contain impact, and restore trusted operations.

5Guided phases
14CSF outcomes
64Mapped controls
29D3FEND techniques

Resilience playbook · Editorial sequence over source-controlled framework relationships

Open the complete Defense Map →

Mission and audience

Make ransomware less likely to succeed, less able to spread, and less capable of destroying recovery options.

Ransomware resilience depends on architecture, identity, configuration, detection, incident command, backups, and restoration—not on one security product.

Built forSecurity leaders · Infrastructure teams · Incident responders · Backup teams · Business continuity teams
01

Guided phase

Know the attack surface

Identify the hardware, software, vulnerabilities, and business assets that shape ransomware exposure.

Actions to take

  • Inventory externally reachable, privileged, legacy, and high-impact assets.
  • Prioritize exploitable vulnerabilities and exposed remote access.
  • Map critical data, dependencies, and recovery priorities.
ID.AM-02Identify · Asset Management

Software, Service, and System Inventories

Inventories of software, services, and systems managed by the organization are maintained

5 controls3 800-1714 800-172
02

Guided phase

Reduce entry and spread

Limit privilege, unauthorized execution, weak configurations, and lateral movement paths.

Actions to take

  • Reduce standing privilege and shared credentials.
  • Harden configurations and restrict unauthorized code execution.
  • Segment critical systems and backup administration paths.
PR.AA-05Protect · Identity Management, Authentication, and Access Control

Manage Permissions and Authorizations

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

12 controls10 800-1719 800-17212 D3FEND17 mitigations
PR.IR-01Protect · Technology Infrastructure Resilience

Protect Networks and Environments

Networks and environments are protected from unauthorized logical access and usage

5 controls5 800-17115 800-1727 D3FEND15 mitigations
03

Guided phase

Protect recovery capability

Create backups and resilience mechanisms that attackers cannot easily discover, alter, or destroy.

Actions to take

  • Use immutable, offline, or logically isolated recovery copies.
  • Separate backup identities, networks, consoles, and credentials.
  • Test restoration against realistic loss and compromise scenarios.
PR.IR-03Protect · Technology Infrastructure Resilience

Resilience Mechanisms

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

9 controls1 800-1712 D3FEND4 mitigations
04

Guided phase

Detect, contain, and eradicate

Recognize destructive activity quickly and prevent additional systems or recovery assets from being affected.

Actions to take

  • Detect encryption, backup tampering, credential abuse, and mass changes.
  • Pre-authorize containment actions and isolation paths.
  • Preserve evidence while removing persistence and compromised access.
DE.CM-09Detect · Continuous Monitoring

Monitor Computing and Runtime Environments

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

12 controls6 800-17119 800-1727 D3FEND10 mitigations
05

Guided phase

Restore trusted operations

Verify restoration assets and prove that recovered services are trustworthy and operational.

Actions to take

  • Validate backup integrity before restoration.
  • Rebuild from known-good sources when trust cannot be established.
  • Verify identity, configuration, data integrity, monitoring, and business function after recovery.
RC.RP-03Recover · Incident Recovery Plan Execution

Verify Backups and Restoration Assets

The integrity of backups and other restoration assets is verified before using them for restoration

3 controls1 800-1712 800-172
RC.RP-05Recover · Incident Recovery Plan Execution

Verify Restored Assets and Normal Operations

The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

1 controls1 800-172

Completion evidence

What should exist when this playbook is working?

  • Prioritized ransomware attack-path and critical-asset map.
  • Privilege, segmentation, hardening, and execution-control evidence.
  • Isolated backup architecture and tested restore results.
  • Ransomware detection use cases and containment runbooks.
  • Documented recovery priorities, clean-room procedures, and trust-validation criteria.
  • Executive and operational exercise results with tracked improvements.

Relationship boundaries

Use the playbook as a decision aid.

Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.

Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.