Mission and audience
Make ransomware less likely to succeed, less able to spread, and less capable of destroying recovery options.
Ransomware resilience depends on architecture, identity, configuration, detection, incident command, backups, and restoration—not on one security product.
Guided phase
Know the attack surface
Identify the hardware, software, vulnerabilities, and business assets that shape ransomware exposure.
Actions to take
- Inventory externally reachable, privileged, legacy, and high-impact assets.
- Prioritize exploitable vulnerabilities and exposed remote access.
- Map critical data, dependencies, and recovery priorities.
Hardware Inventories
Inventories of hardware managed by the organization are maintained
Software, Service, and System Inventories
Inventories of software, services, and systems managed by the organization are maintained
Identify and Record Vulnerabilities
Vulnerabilities in assets are identified, validated, and recorded
Guided phase
Reduce entry and spread
Limit privilege, unauthorized execution, weak configurations, and lateral movement paths.
Actions to take
- Reduce standing privilege and shared credentials.
- Harden configurations and restrict unauthorized code execution.
- Segment critical systems and backup administration paths.
Manage Permissions and Authorizations
Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
Configuration Management
Configuration management practices are established and applied
Prevent Unauthorized Software
Installation and execution of unauthorized software are prevented
Protect Networks and Environments
Networks and environments are protected from unauthorized logical access and usage
Guided phase
Protect recovery capability
Create backups and resilience mechanisms that attackers cannot easily discover, alter, or destroy.
Actions to take
- Use immutable, offline, or logically isolated recovery copies.
- Separate backup identities, networks, consoles, and credentials.
- Test restoration against realistic loss and compromise scenarios.
Create, Protect, Maintain, and Test Backups
Backups of data are created, protected, maintained, and tested
Resilience Mechanisms
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Guided phase
Detect, contain, and eradicate
Recognize destructive activity quickly and prevent additional systems or recovery assets from being affected.
Actions to take
- Detect encryption, backup tampering, credential abuse, and mass changes.
- Pre-authorize containment actions and isolation paths.
- Preserve evidence while removing persistence and compromised access.
Monitor Computing and Runtime Environments
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Contain Incidents
Incidents are contained
Eradicate Incidents
Incidents are eradicated
Guided phase
Restore trusted operations
Verify restoration assets and prove that recovered services are trustworthy and operational.
Actions to take
- Validate backup integrity before restoration.
- Rebuild from known-good sources when trust cannot be established.
- Verify identity, configuration, data integrity, monitoring, and business function after recovery.
Verify Backups and Restoration Assets
The integrity of backups and other restoration assets is verified before using them for restoration
Verify Restored Assets and Normal Operations
The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed
Completion evidence
What should exist when this playbook is working?
- Prioritized ransomware attack-path and critical-asset map.
- Privilege, segmentation, hardening, and execution-control evidence.
- Isolated backup architecture and tested restore results.
- Ransomware detection use cases and containment runbooks.
- Documented recovery priorities, clean-room procedures, and trust-validation criteria.
- Executive and operational exercise results with tracked improvements.
Relationship boundaries
Use the playbook as a decision aid.
Playbook sequence, priorities, checkpoints, and completion evidence are original Bare Metal Cyber editorial guidance. NIST informative references, source-control relationships, D3FEND semantic mappings, curated ATT&CK mitigation mappings, and inferred ATT&CK relationships retain their established labels and limitations.
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST or MITRE. This playbook does not establish legal applicability, contractual scope, compliance, control inheritance, product effectiveness, or guaranteed mitigation.