1. Reduce the easiest entry paths
Prioritise known exploited vulnerabilities on internet-facing systems, remove unnecessary remote services and require phishing-resistant MFA for privileged and remote access where practical.
2. Detect behaviour, not only file signatures
Monitor mass file changes, unusual encryption activity, service disruption, backup tampering and suspicious administrative commands. Alerts should identify the affected host, account and process chain.
3. Make recovery observable
Keep protected backups, separate recovery credentials and test restoration. Record recovery time, missing dependencies and the decisions that slowed the exercise.
Quarterly evidence
- Internet-facing assets have named owners.
- Privileged access and recovery identities are separated.
- Endpoint and server telemetry reaches the response team.
- A restoration test completed successfully.
- The incident contact tree is current.
