Cyber Security
Ransomware Resilience, Backup and Cyber Recovery
What matters in a ransomware attack is not whether it was prevented but, when it was not, how quickly and with how much data loss the organisation can get back on its feet. ONGSEC redesigns the backup architecture around an attack…
Scope of service
What we do under this heading
Resilience Assessment
We first measure how the current backup and recovery design would hold up against an attack.…
VIEWImmutable and Segregated Backup Architecture
The 3-2-1-1-0 rule is applied: three copies, two media types, one off-site, one immutable or offline, zero verificatio…
VIEWIdentity and Directory Recovery
Even if encrypted files return, service does not resume unless Active Directory does; directory recovery is treated as…
VIEWRecovery Drills and Timing
You only know a backup works when a restore has been attempted. Drill results are compared against written targets.…
VIEWRansomware Response Runbook
There is no time to decide during an incident; what will be done is written in advance and rehearsed.…
VIEWResilience Assessment
We first measure how the current backup and recovery design would hold up against an attack.
- Review of the backup architecture and retention chain
- Identification of points where backups could be encrypted or deleted
- Recoverability of the identity infrastructure (Active Directory)
- RTO / RPO targets for critical systems agreed with business units
- A map of dependencies that break in a ransomware scenario
- Gap report and a prioritised improvement plan
Immutable and Segregated Backup Architecture
The 3-2-1-1-0 rule is applied: three copies, two media types, one off-site, one immutable or offline, zero verification errors.
- Immutable repository and object-lock configuration
- Offline or logically air-gapped copies
- A separate identity plane and MFA for the backup console
- Segregation of backup traffic on the network
- Approval and delay on deletion and retention changes
- Automatic verification and alerts for corrupt backups
Identity and Directory Recovery
Even if encrypted files return, service does not resume unless Active Directory does; directory recovery is treated as its own workstream.
- Active Directory forest recovery plan
- Documented recovery order and dependencies
- Clean-room recovery environment design
- Reset of privileged accounts after recovery
- Recovery of the certificate and key infrastructure (PKI)
Recovery Drills and Timing
You only know a backup works when a restore has been attempted. Drill results are compared against written targets.
- A schedule of periodic restore drills
- End-to-end scenario exercises against the clock
- Comparison of measured time with the RTO target
- Drill report and improvement actions
- An evidence file that can be presented at audit
Ransomware Response Runbook
There is no time to decide during an incident; what will be done is written in advance and rehearsed.
- First response, containment and isolation steps
- Evidence preservation and the order of forensic imaging
- A no-ransom principle and legal assessment
- Regulatory notification and customer communication
- Clean rebuild and staged return to service
- Post-incident root cause analysis and closure report
On this page
Typical deliverables
- Resilience gap report
- Backup architecture design
- Recovery runbook
- Drill report
- RTO / RPO measurement record
Let us define the scope together
A short discovery call is enough to identify the slice of this portfolio you actually need.
Request a quoteRelated services
What usually runs alongside this
Cyber Security Products and Implementation Services
Requirements analysis, PoC, architecture, deployment and handover for security products from endpoint to cloud.
EXPLORE Cyber SecurityPenetration Testing, Red Teaming and Digital Forensics
Methodology-driven penetration testing, red team operations, digital forensics and incident response.
EXPLORE Cyber SecurityOT / ICS and Industrial System Security
Passive visibility, segmentation and IEC 62443 compliance work in industrial control system environments.
EXPLOREGet started
Let us talk about your project.
The first meeting is a discovery session, not a sales pitch. You are also welcome to evaluate our capability directly through a short pilot or proof of concept (PoC) in your own environment.