Four principles for sustainable defense
- Protect the assets that sustain revenue, customer service, billing, identity and recovery first.
- Reduce common entry paths through patching, phishing-resistant MFA, controlled remote access and practical training.
- Separate privilege, networks and backups so one compromised account or computer cannot reach the entire business.
- Test restoration and response before an incident; copied files alone do not prove that the company can resume operations.
1. Identify what must keep working and its dependencies
Begin with a maintainable inventory of devices, servers, accounts, applications, cloud services, data and providers. Assign an owner, location, platform, support status and criticality. CISA includes physical and logical asset inventory among its preparation practices because an organization cannot reliably secure, update or recover something it does not know it has.
Connect each critical process with its dependencies. Issuing an invoice may require connectivity, identity, an application, database, certificate, printer and backup. Define acceptable disruption and a temporary work method. This prioritization prevents resources from being spread evenly across unequal risks and lets recovery begin with business capability rather than whichever computer makes the most noise.
- Assets and accounts with an accountable owner.
- Internet-facing systems and remote access paths.
- Essential data and its actual location.
- Dependencies for billing, sales, appointments and communication.
- An agreed order for restoring services.
Include cloud services and computers used outside the office. Provider hosting does not remove the customer’s responsibility for identities, configuration, exportability and continuity.
2. Reduce the most usable entry paths
Keep operating systems, browsers, applications, firmware and network devices on supported versions. Prioritize exploited vulnerabilities and assets reachable from the internet. CISA recommends avoiding direct exposure of remote services where possible and applying compensating controls when they are necessary. Disable services, protocols, accounts and software that no longer have a current purpose.
Protect email and identity with multifactor authentication, unique passwords, filtering and request verification. Apply MFA especially to email, administration, cloud, VPN and remote access. Add centrally managed endpoint protection with alerts reviewed by an accountable person. Security tools only help when they are current, their coverage has been checked and someone acts on their warnings.
- A recurring update process with evidence and managed exceptions.
- MFA on critical accounts and removal of shared credentials.
- Remote access through managed routes rather than ad hoc exposure.
- Operated endpoint and email protection.
- Training to report phishing, suspicious files and unusual access.
3. Limit what a compromised identity can reach
Everyday work should not use administrative privileges. Separate user and administrator accounts, grant only the access required and remove it when roles or contracts change. Review groups, shared folders, applications and service credentials. Unnecessary access turns a contained incident into a broader business disruption.
Segment networks and services according to function and criticality. User computers, servers, backups, cameras and third-party devices should not communicate without a business need. Store sign-in, administrative change and security logs where an attacker cannot readily erase them. Segmentation is not merely a firewall purchase; it requires documented rules, testing and an owner for approving exceptions.
- Separate administrative accounts protected with MFA.
- Role-based permissions with reviews and removal dates.
- Separated networks for users, servers and special devices.
- Restricted execution tools where the work does not require them.
- Centralized logs with risk-appropriate retention.
Do not let one credential administer email, cloud, backups, networking and every endpoint. Separation preserves recovery paths when one identity is lost.
4. Design backups that can survive the incident
Define which data and configuration are backed up, how often, for how long and who watches for failures. Keep copies separated from the normal environment and limit the credentials that can delete them. A permanently attached drive or repository available to the same account may be encrypted or removed along with production data.
Test restoration of files, systems and configuration on a regular schedule. Record duration, dependencies, errors and the process owner’s acceptance criterion. The test must establish whether the company can recover a clean, usable version, not merely whether backup software displays a green status. Protect documentation, keys and contacts needed for recovery when normal systems are unavailable.
- Defined backup scope, frequency, retention and owner.
- An isolated, immutable or offline copy appropriate to risk.
- Separate backup credentials using least privilege.
- Failure alerts that are reviewed and documented.
- Restoration tests validated by the business process owner.
5. Rehearse containment, decisions and recovery
Write a concise plan with owners, alternates, phone numbers outside corporate email, providers, advisers and escalation criteria. CISA recommends determining which systems are affected and isolating them immediately; when several systems or subnets are involved, network-level containment may be required. Employees should know whom to call and must not improvise deletion, reboots or payments.
During an incident, preserve evidence, identify related accounts and protect recovery systems. Do not assume encryption is the only impact: data theft or an earlier intrusion may also exist. Coordinate technical, legal, operational and communication decisions. The FBI discourages paying because payment does not guarantee data recovery and can encourage further attacks; decisions require appropriate authorities and advisers.
- Isolate affected systems without destroying evidence.
- Protect identities, backups and administration tools.
- Activate alternatives for the highest-priority processes.
- Notify according to contracts, jurisdiction and data type.
- Recover from a clean baseline and review the cause before reconnecting.
Do not connect a trusted backup to an environment that remains compromised. Containment, eradication and validation must come before restoration.
Frequently asked questions
Questions that should be settled before acting
Is antivirus enough to prevent ransomware?
No. It is a useful layer but does not replace inventory, patching, MFA, least privilege, segmentation, protected backups and response. Some incidents use valid credentials or legitimate tools, so complementary controls are necessary.
Is a cloud backup automatically protected?
That depends on identity, configuration, retention and recovery capability. If one account can alter or delete production and backup copies, the risk remains connected. Review privilege separation, versioning, immutability and testing.
Should we power off a computer showing a ransom note?
Isolate it from the network immediately and follow the response plan. Powering off, rebooting or manipulating it may affect evidence or recovery; the technical incident owner should make that decision based on the situation and applicable guidance.



