Ransomware Preparedness: What to Do Before an Attack
By the moment a ransomware notice actually appears on a screen, the range of genuinely good options left available to a business has already narrowed dramatically. Nearly all of the decisions that actually determine how badly a ransomware incident damages a business were made, or not made, well before the attack itself — how systems were segmented, whether backups were genuinely tested, whether staff knew what to do in the first confused minutes. Preparedness, far more than any response decision made in the moment, is what actually separates a business that recovers within days from one facing weeks of disruption and a genuinely difficult ransom decision.
Why Ransomware Preparedness Is Different From General Security
General cybersecurity practice reduces the odds of any attack succeeding in the first place, and that broad prevention work matters enormously. Ransomware-specific preparedness is a distinct, additional layer that assumes, realistically, that despite genuinely good prevention efforts, an attack might still eventually succeed, and asks what specifically needs to be true beforehand to limit the damage when that happens. This is an uncomfortable mindset to adopt, since it requires acknowledging that prevention alone can’t be relied upon completely, but that honest acknowledgment is exactly what produces genuinely better outcomes when an incident does occur.
Network Segmentation Limits How Far an Attack Can Spread
One of the most damaging aspects of a serious ransomware incident is how far it can spread across a flat, unsegmented network, encrypting far more systems than the attacker’s initial point of entry alone would suggest. Genuine network segmentation — dividing systems into isolated zones so that a compromise in one area doesn’t automatically cascade into every connected system — is one of the more technically involved but genuinely high-value preparedness investments a business can make, since it directly limits the blast radius of an incident that does manage to get an initial foothold somewhere in the network.
Backup Isolation Is the Single Most Important Preparedness Step
Ransomware that can reach and encrypt a business’s backups alongside its primary systems removes the single most important recovery option available, forcing a business into a genuinely difficult choice between paying a ransom with no guarantee of actual data recovery, or accepting permanent data loss. Backups that are genuinely isolated — offline, air-gapped, or otherwise architecturally separated from the systems ransomware could reach during an active incident — are what actually preserve a real recovery path independent of whatever happens to the primary network during an attack, and this isolation is worth genuinely prioritizing above almost every other preparedness investment.
Building an Incident Response Plan Specific to Ransomware
A generic incident response plan is a reasonable starting point, but ransomware presents specific decision points that deserve dedicated, advance thought rather than being figured out for the first time under active crisis pressure: who has the actual authority to make a ransom payment decision, what the criteria for that decision would be, which regulatory or legal obligations apply given the specific data potentially involved, and who needs to be notified and in what order. Working through these questions in a calm planning session, well before any actual incident, produces considerably better decisions than attempting to work through them for the first time during a genuine crisis with real time pressure and incomplete information.
Preparedness Priorities in Order of Impact
| Preparedness Action | Primary Benefit | Relative Priority |
|---|---|---|
| Isolated, tested backups | Preserves a genuine recovery path | Highest |
| Network segmentation | Limits how far an attack can spread | High |
| Ransomware-specific response plan | Enables faster, clearer decisions under pressure | High |
| Employee phishing awareness | Reduces likelihood of the initial entry point | High |
| Cyber insurance review | Clarifies coverage and obligations in advance | Moderate |
Employee Awareness Still Matters as a First Line of Defense
Many ransomware incidents originate from a successful phishing attempt or a compromised credential rather than a sophisticated technical exploit, which means genuine employee security awareness remains a meaningfully important preparedness layer, not a separate concern from ransomware readiness specifically. Reducing the odds of a successful initial compromise through consistent, well-designed security awareness training is a genuinely worthwhile preparedness investment precisely because it addresses the most common actual entry point rather than only preparing for the aftermath of an attack that’s already succeeded.
Understanding Cyber Insurance Before You Need It
Cyber insurance can provide genuine financial protection during a ransomware incident, but policies vary enormously in what they actually cover, what conditions must be met for coverage to apply, and what specific incident response obligations a policy might impose, like requiring the use of a specific approved response vendor. Understanding these details before an incident occurs, rather than discovering unexpected limitations while already in the middle of a genuine crisis, is an important but frequently overlooked part of overall ransomware preparedness that deserves a dedicated review rather than an assumption that a policy simply covers whatever eventually happens.
Practicing the Plan, Not Just Writing It
A written incident response plan that’s never actually been practiced tends to reveal real gaps only once it’s genuinely needed, at exactly the worst possible time to discover them. Running a tabletop exercise — walking through a realistic simulated ransomware scenario with the actual people who’d be involved in a genuine response — surfaces confusion about roles, missing contact information, and unclear decision authority while there’s still time to fix these gaps calmly, rather than during an actual incident when there’s no room left for that kind of clarification.
Communication Planning Deserves Advance Thought Too
A ransomware incident often requires communicating with employees, customers, and sometimes regulators or the public, under real time pressure and with limited, evolving information about the actual scope of what happened. Having genuine draft communication templates and a clear understanding of who’s authorized to communicate what, prepared well in advance, prevents a business from having to draft sensitive, high-stakes communications from scratch during an already chaotic and time-pressured situation, when the risk of a poorly considered public statement is at its absolute highest.
Preparedness as the Real Determinant of Outcome
The honest, uncomfortable truth about ransomware is that no business can reduce its risk of an attempted attack to zero, regardless of how much is invested in prevention. What genuinely differentiates businesses that recover relatively smoothly from those that face weeks of damaging disruption is almost always the preparedness work done well before any attack occurred — isolated backups that actually work, a network architecture that limits how far an attack can spread, and a response plan that’s been genuinely practiced rather than simply written and filed away. That preparation, done calmly in advance, is what actually determines how a business experiences the worst day of a ransomware incident, far more than anything decided in the moment itself.
By ZevoniCRM Editorial · Updated June 8, 2026
- ransomware
- cybersecurity preparedness
- incident response