The Enterprise Ransomware Defense Playbook
The full prevention-to-recovery reference: hardening, detection, response, and resilient recovery — the practices that actually move the needle.
14 min read
Prevention: close the doors attackers actually use
Nearly all enterprise ransomware incidents begin one of three ways: phishing-delivered credential theft, exploitation of an internet-facing vulnerability (VPN appliances and RDP are perennial favorites), or compromise via a third party with standing access to your environment. Prevention spend should be allocated in that order of priority, not by what's easiest to buy.
- Enforce phishing-resistant MFA (FIDO2/hardware keys) on every remote-access and privileged path — SMS and app-based OTP are routinely bypassed.
- Patch internet-facing infrastructure on an accelerated cycle; VPN concentrators, firewalls, and RDP gateways should be treated as tier-0 assets.
- Maintain a current, tested inventory of third-party access — vendors, MSPs, and contractors with standing credentials are a disproportionate source of initial access.
- Segment your network so that a single compromised workstation cannot reach domain controllers, backup infrastructure, or file shares across the whole environment.
Detection: assume prevention will eventually fail
Modern ransomware operations spend days to weeks inside a network before encryption — mapping shares, escalating privileges, and exfiltrating data. That dwell time is your best opportunity to catch the intrusion before it becomes a headline.
- Deploy EDR/XDR with 24/7 monitoring — in-house or via an MDR partner — not just endpoint AV.
- Alert on the precursors, not just the payload: mass file renames, disabling of Volume Shadow Copy, unusual use of legitimate admin tools (PsExec, WMI, RDP) off-hours.
- Monitor for large or unusual outbound data transfers — double-extortion groups exfiltrate before they encrypt.
- Run regular tabletop exercises so your team recognizes these signals under pressure, not for the first time during a real incident.
Response: have the plan before you need it
An incident response plan that exists only as a document nobody has rehearsed is close to useless under real pressure. The organizations that recover fastest are the ones who have run a tabletop exercise with their actual leadership team, not just their security team.
- Maintain a written IR plan with named roles, decision authority, and 24/7 contact paths for your IR firm, cyber insurer, and breach counsel.
- Pre-negotiate an incident response retainer — response time and priority during a live event are dramatically better with an existing relationship.
- Run at least one ransomware-specific tabletop exercise per year involving executive leadership, not just IT.
- Decide your ransom-payment policy and decision framework in advance, in consultation with counsel and insurance — this is not a decision to make for the first time under duress.
Recovery: backups are not the same as recoverability
The most common false sense of security in enterprise ransomware readiness is 'we have backups.' Having backups and being able to restore a production environment within an acceptable recovery time are very different claims — and the gap between them is where most prolonged outages come from.
- Maintain immutable, offline (air-gapped or logically isolated) backup copies that ransomware cannot reach or encrypt.
- Test full restores on a schedule, not just backup completion — a backup you've never restored from is a hypothesis, not a plan.
- Document and rehearse your restore sequence: domain controllers, then core infrastructure, then business-critical applications, in the right order.
- Model your actual recovery time objective against your last tested restore — if there's a gap, that gap is your real risk exposure.
Where to start
If you do nothing else this quarter: take the free readiness assessment to see where your organization actually stands against these four pillars, and pre-identify (don't wait to search for) your incident response partner and cyber insurance panel firms.