Ransomware Readiness Guide
Ransomware encrypts or steals an organization's data and holds it for ransom, and public entities — cities, counties, school districts, special districts, and their risk pools — are some of the most frequently targeted victims. Here is KYND's guide to understanding and managing ransomware risk.
What is ransomware?
Ransomware is malicious software that encrypts an organization's files and systems, rendering them unusable until a ransom is paid — often alongside a threat to leak stolen data if payment isn't made (“double extortion”). It typically spreads after a threat actor gains initial access through phishing, an exposed remote access service, or an unpatched vulnerability.
Why does ransomware succeed?
Ransomware relies on a single point of initial access spreading before it's detected. Attackers move quietly through a network, escalating privileges and disabling backups before triggering encryption, which is why the damage is often discovered only once it's already widespread.
Why are public entities a target?
Public entities manage essential services that cannot easily be paused — payroll, utilities, courts, emergency response — which creates pressure to pay quickly rather than rebuild from scratch. Limited IT security staffing relative to the size of the network also means gaps can go unnoticed for longer than in a well-resourced private organization.
What if we don't prepare for ransomware?
Without tested backups and a response plan, a ransomware event can take critical systems offline for weeks, not days. Beyond the ransom itself, incidents can trigger state breach notification requirements, legal and forensic costs, and lasting damage to public trust.
Which frameworks should we be aligned to?
NIST Cybersecurity Framework (CSF) 2.0 covers ransomware readiness across Identify, Protect (backups, patching, access control), Detect, Respond, and Recover. CIS Controls v8 provides more specific guidance, particularly Control 11 (Data Recovery) and Control 4 (Secure Configuration of Enterprise Assets).
Building operational resilience
Maintain backups that are encrypted, immutable, and tested through regular restoration drills, with at least one copy stored offline or off-network. Maintain a documented incident response plan so staff know their role in the first hours of an event, not just the technical remediation steps.
Technical controls that reduce ransomware risk
Patch internet-facing systems and VPNs promptly, require multi-factor authentication (MFA) on all remote access and administrative accounts, and segment networks so a single compromised device can't reach every system. Disable or tightly control remote desktop protocol (RDP) exposure to the internet.
Checklist
When building or reviewing your ransomware defense program, consider the following:
- Are backups encrypted, immutable, and tested through regular restoration drills?
- Is at least one backup copy stored offline or otherwise isolated from the production network?
- Is MFA enforced on all remote access, administrative, and email accounts?
- Are internet-facing systems and VPNs patched on a regular, documented cadence?
- Is remote desktop protocol (RDP) access restricted or disabled from the public internet?
- Does your incident response plan assign clear roles for the first hours of a confirmed ransomware event?