Cyber Security

Ransomware Resilience, Backup and Cyber Recovery

What matters in a ransomware attack is not whether it was prevented but, when it was not, how quickly and with how much data loss the organisation can get back on its feet. ONGSEC redesigns the backup architecture around an attack…

3-2-1-1-0Immutable repositoryAir-gapped copyAD forest recoveryClean roomRTO / RPO measurement
01

Resilience Assessment

We first measure how the current backup and recovery design would hold up against an attack.

  • Review of the backup architecture and retention chain
  • Identification of points where backups could be encrypted or deleted
  • Recoverability of the identity infrastructure (Active Directory)
  • RTO / RPO targets for critical systems agreed with business units
  • A map of dependencies that break in a ransomware scenario
  • Gap report and a prioritised improvement plan
02

Immutable and Segregated Backup Architecture

The 3-2-1-1-0 rule is applied: three copies, two media types, one off-site, one immutable or offline, zero verification errors.

  • Immutable repository and object-lock configuration
  • Offline or logically air-gapped copies
  • A separate identity plane and MFA for the backup console
  • Segregation of backup traffic on the network
  • Approval and delay on deletion and retention changes
  • Automatic verification and alerts for corrupt backups
03

Identity and Directory Recovery

Even if encrypted files return, service does not resume unless Active Directory does; directory recovery is treated as its own workstream.

  • Active Directory forest recovery plan
  • Documented recovery order and dependencies
  • Clean-room recovery environment design
  • Reset of privileged accounts after recovery
  • Recovery of the certificate and key infrastructure (PKI)
04

Recovery Drills and Timing

You only know a backup works when a restore has been attempted. Drill results are compared against written targets.

  • A schedule of periodic restore drills
  • End-to-end scenario exercises against the clock
  • Comparison of measured time with the RTO target
  • Drill report and improvement actions
  • An evidence file that can be presented at audit
05

Ransomware Response Runbook

There is no time to decide during an incident; what will be done is written in advance and rehearsed.

  • First response, containment and isolation steps
  • Evidence preservation and the order of forensic imaging
  • A no-ransom principle and legal assessment
  • Regulatory notification and customer communication
  • Clean rebuild and staged return to service
  • Post-incident root cause analysis and closure report

Typical deliverables

  • Resilience gap report
  • Backup architecture design
  • Recovery runbook
  • Drill report
  • RTO / RPO measurement record

Let us define the scope together

A short discovery call is enough to identify the slice of this portfolio you actually need.

Request a quote

Get started

Let us talk about your project.

The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.

Fill in the enquiry form

WhatsApp