CYBER RESILIENCE

Ransomware Readiness for Boards That Cannot Afford a Week of Downtime

Prevention alone is not a strategy, because determined attackers get in. Readiness is what decides whether an incident is a bad week or an existential one. This page sets out what ransomware readiness actually means and who owns it.

Book a conversation

Why readiness beats prevention alone

Every organisation should work to keep ransomware out, but the businesses that survive an attack are the ones that prepared to be hit. Readiness assumes a breach will happen and asks a harder question: when it does, can you recover quickly enough to stay in business? The IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and for a mid-market business a week of downtime is often the more dangerous number.

What ransomware readiness actually means

Readiness is a small number of things done properly, not a product you buy.

  • Backups that are tested, and kept offline or immutable so ransomware cannot encrypt them too
  • An incident response plan that has been rehearsed, not just written and filed
  • Network segmentation so an intrusion in one place cannot spread across the whole estate
  • Hardened identity and access, since stolen credentials are how most attacks begin
  • Clear board oversight, so the hard decisions are owned before the pressure is on

The board’s role

Ransomware is not something a board can delegate to IT and forget. Directors are accountable for the resilience of the business, and some of the hardest decisions in an incident, including whether to pay a ransom, land at board level under extreme time pressure. A board that has thought those decisions through in advance, and knows its legal and regulatory position, responds far better than one meeting them for the first time mid-crisis. This is core to board cyber governance.

Testing it before you need it

A plan you have never tested is a hope, not a capability. The two tests that matter most are a tabletop exercise, where the leadership team works through a realistic scenario and finds the gaps in decision-making, and a restore test, where you actually recover systems from backup and time how long it takes. Both routinely surface assumptions that would have failed in a real incident. A tested incident response plan is what turns readiness from a document into a capability.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Daniel has built the backup regimes, response processes and board reporting that ransomware readiness demands inside businesses that could not afford extended downtime, and can tell you where your real exposure sits before an attacker does.

Frequently asked questions

What is ransomware readiness?

Ransomware readiness is the ability to recover quickly if you are hit, rather than only trying to prevent an attack. It rests on tested and immutable backups, a rehearsed incident response plan, network segmentation, hardened identity and access, and clear board oversight of the hardest decisions.

What are the most important ransomware controls?

Tested, offline or immutable backups matter most, because they are what lets you recover without paying. Close behind are a rehearsed response plan, network segmentation to stop spread, and strong identity and access controls, since stolen credentials start most attacks.

Should we ever pay a ransom?

It is a board-level decision with legal, regulatory and practical dimensions, and there are no guarantees that paying restores your data or that it is lawful in your circumstances. The point of readiness is to make sure you are never forced into that decision blind, or without tested backups as an alternative.

How do we test our ransomware readiness?

With a tabletop exercise, where the leadership team works through a realistic scenario and finds the decision-making gaps, and a restore test, where you actually recover systems from backup and measure how long it takes. Both surface assumptions that would fail in a real incident.

Who owns ransomware readiness?

Ultimately the board, because it is accountable for the resilience of the business and owns the hardest decisions in an incident. Day to day it is led by whoever holds the security remit, a CISO or a virtual CISO, but it cannot be fully delegated and forgotten.

NEXT STEP

Would your board be ready if it happened tomorrow?

The free Board Cyber Governance check shows where your resilience and accountability gaps sit before an attacker finds them. When you want to talk it through, a conversation is the next step.

Board Cyber Governance check Book a conversation