1. Reduce the easiest entry paths

Prioritise known exploited vulnerabilities on internet-facing systems, remove unnecessary remote services and require phishing-resistant MFA for privileged and remote access where practical.

2. Detect behaviour, not only file signatures

Monitor mass file changes, unusual encryption activity, service disruption, backup tampering and suspicious administrative commands. Alerts should identify the affected host, account and process chain.

3. Make recovery observable

Keep protected backups, separate recovery credentials and test restoration. Record recovery time, missing dependencies and the decisions that slowed the exercise.

Quarterly evidence

  • Internet-facing assets have named owners.
  • Privileged access and recovery identities are separated.
  • Endpoint and server telemetry reaches the response team.
  • A restoration test completed successfully.
  • The incident contact tree is current.
A useful testChoose one critical service and prove that you can isolate its access path, find its latest verified backup and restore it within the time the business expects.