// tool reference · Governance & Advisory
Ransomware Readiness Free
Self-assess your resilience to a ransomware attack.
Open Ransomware Readiness → Engine: /security-tools/ransomware_readiness
What it does
A structured questionnaire that scores your readiness and ranks the gaps that actually decide outcomes: backup isolation, MFA coverage, segmentation, and whether the IR plan has ever been tested.
When to use it
- Board reporting; insurance questionnaires; deciding where the next control budget goes.
Inputs
Field names are the actual form parameters, verified against source.
| Field | Type | Required | Notes |
|---|---|---|---|
| (questionnaire) | form | required | Multiple-choice readiness questions. |
What you get back
A readiness score with prioritised gaps.
Worked example
Input
(questionnaire: backups yes / isolated no / MFA partial / segmentation no / IR plan untested)
Output (abridged)
READINESS: 42/100 -- HIGH RISK GAPS, ranked by what actually decides the outcome: 1. BACKUPS NOT ISOLATED (critical) You have backups. Ransomware operators target backups FIRST -- this is the single control that decides whether you pay. An online, domain-joined backup is not a backup during ransomware. -> One offline or immutable copy. Nothing else here matters more. 2. IR PLAN NEVER TESTED (critical) An untested plan is a document, not a capability. The first time you discover the restore does not work should not be at 02:00. 3. MFA PARTIAL (high) Partial MFA is the gap that gets used. Remote access first. 4. NO SEGMENTATION (high) Determines blast radius: one host, or all of them. Fix 1 and 2 and this score moves to ~75 -- they are also the two cheapest items on the list.
How it works
Deterministic scoring — same answers, same score, every time. Offline.
Limits
Read live from the platform configuration.
| Rate limit | 30 requests / 60s (platform default) |
Limitations — what it does not do
Self-assessment. It scores your ANSWERS, not your reality -- an optimistic answer produces an optimistic score. The value is in the ranking, not the number.
Privacy
Answers are scored in memory.
Standards
NIST CSFCISA #StopRansomware