Ransomware Readiness Scorer
Score your organisation across prevention, detection, backup integrity and recovery capability, and see which control gaps contribute most to the residual risk.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Prevention fails eventually, recovery is what decides the outcome
Organisations that recover from ransomware without paying overwhelmingly share one characteristic: a backup that the attacker could not reach and that had been restored from recently enough to trust. Organisations that pay usually had backups too. The difference is almost always that the backups were on the same domain, reachable with the same credentials, and encrypted alongside everything else, or that nobody had ever attempted a full restore and it did not work.
The 3-2-1-1-0 rule and why the extra digits exist
The old rule was three copies, two media types, one offsite. Ransomware added two more requirements: one copy immutable or air gapped, and zero errors on a verified restore. The immutability matters because modern operators specifically hunt and delete backups before triggering encryption, often after weeks inside the network. The verification matters because an untested backup is a hypothesis, and the moment of an incident is the worst possible time to discover it was wrong.
Dwell time is where detection earns its value
Attackers typically operate inside a network for days to weeks before encrypting, moving laterally, escalating privileges and exfiltrating data for the second extortion lever. Every one of those steps is detectable. An organisation that detects on day two loses far less than one that discovers the intrusion when the ransom note appears, and the difference is not the encryption itself but whether the data was stolen first, which no backup fixes.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What is the single most valuable control?
An immutable or genuinely offline backup copy that has been test restored. Modern operators specifically seek out and delete backups before encrypting, so a backup reachable with the credentials they already hold is not a backup.
Does paying the ransom work?
Sometimes, partially. Published incident data consistently shows a substantial share of paying organisations do not recover all their data, decryption tooling is often slow and buggy, and paying marks you as willing, which correlates with being targeted again. Several jurisdictions also restrict payments to sanctioned entities.
What is double extortion?
Exfiltrating data before encrypting it, so the victim faces publication as well as loss of access. Backups solve the availability problem entirely and do nothing about the disclosure, which is why detection during the dwell period matters as much as recovery capability.
How often should restores be tested?
A full restore of critical systems at least quarterly, with the recovery time measured rather than estimated. Restoring a single file proves the media is readable; it does not prove you can rebuild a domain controller or a database cluster under pressure.
Does cyber insurance replace controls?
No. Insurers now require specific controls, multi factor authentication and endpoint detection among them, as a condition of cover, and they decline claims where attested controls were not in place. Insurance transfers some financial risk and none of the operational risk.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Answer each question honestly to get a readiness score with the highest impact gaps identified.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.