Ransomware Defense
Ransomware defense is the coordinated reduction of risk from attacks that disrupt access to systems or data and may use stolen data for extortion. It combines governance, access control, system hardening, detection, incident response, protected backups, and tested recovery.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Ransomware Defense
Ransomware defense is the work of keeping an attack from turning into a long, expensive argument with your own infrastructure. The ransom note is merely the visible complaint. Before it arrives, an attacker may have entered, borrowed credentials, mapped systems, moved around, taken data, and tried to make recovery awkward. Encryption is one possible finale, which is a remarkably poor time to discover that the backup account has the same keys as production.
The useful mental model has three parts: reduce paths in, limit paths through, and preserve a trustworthy path back. The first part is familiar security work: patch exposed weaknesses, strengthen authentication, restrict remote administration, and protect endpoints and email. The second part is segmentation, boundaries that limit which systems and authority an intruder can reach. It keeps one bad foothold from becoming a guided tour of everything important.
The third part is where the furniture starts moving. A recovery copy is not evidence of recovery because a completed job only says that data was written somewhere. A critical service also needs its configuration, software, identities, dependencies, and a way to validate the result. The surprising bit is that restoring quickly is not automatically good: reconnecting through a compromised identity or management path can invite the attacker back for an encore nobody requested.
During an incident, separate the questions that panic tries to merge. Is attacker access still active? Which identities and control planes are trustworthy? Was data taken as well as encrypted? Which recovery sources are safe? Isolation, evidence preservation, containment, and recovery all become less mysterious when each action answers one of those questions rather than attempting to cure the entire situation with a single dramatic button.
Read the Intro for the six connected outcomes that organize the work. Use the Slides when the campaign path and recovery sequence need to fit on one screen. Keep the Cheatsheet nearby for trust questions, recovery-copy checks, and exercise prompts. The Quiz is for testing the model before a real incident supplies considerably less forgiving feedback.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.nccoe.nist.gov/projects/ransomware-csf-community-profile
Supports
- Ransomware as a disruptive threat that can encrypt critical data and steal information for extortion
- Prioritized outcomes across Govern, Identify, Protect, Detect, Respond, and Recover
- Current-state assessment, target-state definition, gap identification, and improvement prioritization
- Use of the profile for readiness, contingency planning, and countermeasure playbooks
- https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=960361
Supports
- The June 2026 CSF 2.0 Ransomware Community Profile
- Risk-informed ransomware preparation, resistance, response, recovery, and operational resilience
- Asset, identity, data, dependency, protective-control, detection, response, and recovery outcomes
- Current and target organizational profiles for prioritized improvement
- https://www.cisa.gov/stopransomware/ransomware-guide
Supports
- Ransomware and data-extortion preparation, prevention, mitigation, response, and recovery
- Prevention guidance organized by common initial access vectors
- Incident response planning, communications, segmentation, access control, updates, and endpoint protection
- Ransomware as possible evidence of an earlier unresolved compromise
- Determining affected systems, immediate isolation, evidence preservation, threat hunting, containment, eradication, and recovery
- Backup protection, separate copies, immutable storage considerations, rebuild material, and restoration testing
- https://www.cisa.gov/resources-tools/resources/stopransomware-guide
Supports
- The guide as a CISA resource for detecting, preventing, responding to, and recovering from ransomware
- Publication metadata, downloadable guide, and related resources
- https://www.hhs.gov/sites/default/files/2021-retrospective-and-2022-look-ahead-tlpwhite.pdf
Supports
- The 1989 PC Cyborg AIDS Trojan as the first ransomware attack
- https://www.cyber.gc.ca/en/guidance/cyber-threat-bulletin-modern-ransomware-and-its-evolution
Supports
- CryptoLocker as a modern ransomware campaign in 2013
- The proliferation of automated ransomware campaigns from 2014 through 2016
- https://www.gao.gov/blog/ransomware-holding-it-systems-and-data-hostage
Supports
- The 2017 WannaCry and NotPetya incidents
- The 2021 Colonial Pipeline ransomware disruption
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a
Supports
- LockBit predecessor activity in 2019 and LockBit activity from 2020
- LockBit 2.0, StealBit, and the affiliate ransomware-as-a-service model
- Control validation against observed ransomware techniques
- https://www.crowdstrike.com/en-us/platform/endpoint-security/ransomware-protection/
Supports
- CrowdStrike Falcon ransomware detection and response capabilities
- https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint
Supports
- Microsoft Defender for Endpoint as an endpoint security product
- https://azure.microsoft.com/en-us/products/microsoft-sentinel
Supports
- Microsoft Sentinel as a security operations product
- https://www.rubrik.com/solutions/ransomware-recovery
Supports
- Rubrik ransomware recovery and impact assessment capabilities
- https://www.veeam.com/products/veeam-data-platform/backup-recovery.html
Supports
- Veeam Data Platform backup and recovery capabilities
- https://www.cohesity.com/platform/dataprotect/
Supports
- Cohesity DataProtect as a data protection and recovery product
