Getty Images/iStockphoto
How to tackle a ransomware readiness self-assessment, with template
Ransomware readiness self-assessments are key to spotting vulnerabilities and preparing for third-party assessments. Use this template to evaluate your organization's preparedness.
Ransomware continues to be a major threat to all organizations. CISOs must prioritize conducting periodic ransomware readiness self-assessments and mitigating any issues identified during those assessments. CISOs can also use assessment results to educate board members and other executives about the organization's current state of ransomware readiness.
This article provides CISOs with advice on planning and conducting ransomware readiness self-assessments. It also offers a worksheet-style template that CISOs can fill out during a self-assessment.
How to tackle a ransomware readiness self-assessment
Numerous guides are publicly available for doing ransomware readiness self-assessments, such as the Ransomware Self-Assessment Tool from the Conference of State Bank Supervisors. However, these guides tend to focus on providing a set of questions for any organization to answer. They often don't provide a broad explanation of the self-assessment process or take into account an organization's unique situation.
Here are the basic steps your organization should follow to plan, execute and learn from a ransomware readiness self-assessment:
- Identify the assessment requirements. A self-assessment guide can give you a head start on these requirements, and some industries have sector-specific self-assessment guides. However, it's important to consider all relevant laws, regulations and other external requirements your organization is subject to, as well as all internal requirements, such as organizational policies. Many organizations are typically subject to multiple reporting and notification requirements for ransomware incidents.
- Assess and document the results for each requirement. Self-assessments are typically conducted at a high level to provide a broad picture of the organization's readiness without requiring significant effort.
- Identify and document gaps and other weaknesses. This step is vital for improvement purposes. It's also valuable for sharing with executives and staff.
- Prepare a plan to remediate gaps and other weaknesses. The plan should include estimates of the time and resources needed for each remediation action, as well as any dependencies among the actions. Prioritization of the remediations is especially important because there is no way to prevent all ransomware infections; scarce resources are generally better allocated to higher-impact remediations.
- Solicit stakeholder input and buy-in for the remediation plan. This needs to include executive support for the plan and budget, as well as having leadership reinforce to staff how important the remediation plan is for preventing future ransomware incidents and limiting ransomware damage.
Best practices for a ransomware readiness self-assessment
As your organization plans, executes and learns from a self-assessment, keep the following best practices in mind to improve your long-term results:
- Perform a ransomware readiness self-assessment at least annually. Also conduct a self-assessment after a major ransomware incident to identify the factors that enabled the incident and caused significant damage. It is generally prudent to conduct a self-assessment before having a third party conduct an independent assessment. This enables the organization to address obvious shortcomings before paying for an independent assessment.
- Involve all pertinent stakeholders in the self-assessments. Executive buy-in is critical to conducting self-assessments and understanding the results. Involve other stakeholders, such as cybersecurity management, incident response teams, staff, legal and compliance professionals, to ensure their viewpoints are taken into account during each step of the process.
- Compare self-assessment results over time. While the details of each self-assessment might vary from year to year, most requirements remain the same. This enables you to monitor trends over time to see which known issues were effectively addressed and which are lingering concerns to prioritize.
Template for conducting a ransomware readiness self-assessment
An excellent starting point for a ransomware readiness self-assessment is "Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile" from the NIST. Based on its content, here is a worksheet-style template that CISOs can fill out to assess ransomware readiness, then share the results with board members and other executives. The template asks a series of questions to elicit insights into the thoroughness and effectiveness of the organization's preparations.
Download our free, editable template
Download a copy of the ransomware readiness self-assessment template to evaluate your organization's preparedness.
NIST's Ransomware Community Profile uses the following categories and subcategories from the NIST Cybersecurity Framework 2.0 as the structure for explaining how organizations should manage their ransomware risk.
Govern
- Organizational context
- How have the organization's priorities for organizational mission, objectives and activities been implemented in contingency planning for future ransomware incidents?
- How have the cybersecurity risk management needs and expectations of the organization's internal and external stakeholders been used in contingency planning for future ransomware incidents?
- How have the organization's legal and regulatory requirements for cybersecurity and privacy been established in contingency planning for future ransomware incidents?
- Risk management strategy
- How are the organization's risk appetite and tolerance used to help the organization make decisions during ransomware incident response and recovery?
- How does the organization's risk management governance take ransomware risks into account when establishing organizational cybersecurity policies?
- Roles, responsibilities and authorities
- How is everyone in the organization made to understand their roles, responsibilities and authorities in the event of a ransomware attack?
- Cybersecurity supply chain risk management
- How are the organization's suppliers, customers and partners made to understand their roles and responsibilities regarding the prevention of ransomware infections and subsequent response and recovery actions?
- How are suppliers and third-party providers engaged in the organization's ransomware contingency planning activities?
Identify
- Asset management
- How accurate and comprehensive is the organization's software inventory? How quickly is software typically updated once updates become available?
- How well are the organization's communications and data flows understood for use in future ransomware incident responses? How accurate and comprehensive is the organization's catalog of connections to external information systems?
- How have the organization's data and software assets been prioritized based on classification, criticality and impact on mission?
- Risk assessment
- How accurate and comprehensive is the organization's identification of vulnerabilities in assets?
- How do the business impacts of potential ransomware incidents factor into cybersecurity cost-benefit analyses and into response and recovery activity prioritization?
- How effective is contingency planning of responses to projected risks?
- How is the authenticity and integrity of hardware and software assessed prior to acquisition and use?
- Improvement
- How thoroughly do the organization's response and recovery plans address future ransomware incidents? How often are ransomware response and recovery plans tested?
Protect
- Identity management, authentication and access control
- How strong are the organization's credential management practices, including which types of credentials are used and how the credentials are issued, managed, revoked and recovered?
- How strong are the organization's authentication methods in terms of phishing resistance? How strong are the organization's zero-trust architecture implementations?
- How effective is the organization at preventing user credential compromise and restricting privileged access?
- How effective are the organization's physical access measures against insider attacks?
- Awareness and training
- How effective are the organization's security training practices at reducing the frequency of users engaging in unsafe practices?
- Data security
- How effectively are regular backups maintained? How frequently are regular backups tested?
- Platform security
- How effective are the organization's configuration management practices at reducing the prevalence of exploitable vulnerabilities?
- How quickly does the organization replace software that is no longer supported? How quickly does the organization install software updates?
- How readily available is the organization's audit and log record data for proactive anomaly detection and forensic activities?
- How effective are the organization's controls for preventing the installation and execution of unauthorized software?
- Technology infrastructure resilience
- How effective are the organization's controls for protecting network connections from unauthorized logical access and usage?
Detect
- Continuous monitoring
- How effective is the organization's network monitoring at detecting ransomware attacks early in the attack lifecycle?
- How effective is the organization's personnel activity monitoring at detecting insider threats and insecure staff practices to prevent ransomware incidents?
- How effective is the organization's monitoring of external service provider activity at detecting exploitable vulnerabilities?
- How effective is the organization's monitoring of computing hardware and software, runtime environments, and its data at detecting ransomware before it is executed?
- Adverse event analysis
- How effective is the organization's analysis of potentially adverse events at preventing or mitigating ransomware attacks?
- How does estimating the impact and scope of adverse events inform the organization's ransomware response and recovery priorities?
Respond
- Incident management
- How quickly is the organization's incident response plan executed once a ransomware incident is declared?
- Incident response reporting and communication
- How efficiently are the organization's internal and external stakeholders notified of ransomware incidents?
- How efficiently is information on ransomware incidents shared with the organization's internal and external stakeholders?
- Incident mitigation
- How efficiently are ransomware incidents contained?
- How efficiently are ransomware incidents eradicated?
Recover
- Incident recovery plan execution
- How quickly is the recovery portion of the organization's incident response plan executed once recovery is initiated from the ransomware incident response process?
- How are recovery actions selected, scoped, prioritized and performed for the organization's ransomware incidents?
- How is the integrity of the organization's backups and other restoration assets verified before using them to recover from a ransomware incident?
- Incident recovery communication
- How efficiently and effectively is information on the organization's ransomware incident recovery process communicated to internal and external stakeholders?
- How efficiently and effectively is information on the organization's ransomware incident recovery shared with the public?
Karen Kent is the principal consultant at Scarfone Cybersecurity in Clifton, Va. She provides cybersecurity publication consulting to organizations and was formerly a senior computer scientist for NIST.