Assumed breach and ransomware readiness
Every ransomware incident of the last five years had the same first act: someone got one credential. The interesting part is what happened in the eight days after. We start where the attacker started and measure the distance, including the part most tests skip, whether your backups are reachable from the thing you are backing up.
What is included
- A granted starting foothold, agreed in advance
- Blast radius mapping from that foothold outward
- Backup and recovery reachability from compromised privilege
- Credential exposure: cached, stored, and in scripts on reachable shares
- Egress paths available for staging and exfiltration
- Where available, whether your tooling logged any of it
What you get
- Blast radius map: what one foothold reaches, and in how many hops
- Explicit finding on backup survivability
- Evidence for every reachable system, with the path taken
- Remediation ordered by how much of the radius each change removes
- Live debrief walkthrough
- Attestation letter for auditors and customers, on request
- Remediation attestation after the retest, as a standalone document
Shape of the engagement
- From $1,500Fixed in writing before testing starts. 5 to 10 business daysTypical window. Built around your deadline if you have one. How pricing works
The backup question, asked properly
Most organisations can answer whether backups exist and whether restores have been tested. Fewer can answer the question that decides the outcome of a ransomware incident: can the account that ends up with Domain Admin also delete, encrypt, or modify the backups? If the backup server is domain-joined, the backup service account is a domain administrator, or the immutable storage is protected only by a credential that is reachable, then the backups are part of the blast radius rather than the recovery from it.
We test that specific path, and we report it as a named finding whether the answer is good or bad, because it is the one your board will ask about.
Nothing is encrypted
We do not deploy ransomware, simulated or otherwise, and we do not encrypt anything. Readiness is measured by demonstrating the access that would make encryption possible: we show that this account can write to that share, delete those snapshots, and reach that backup catalogue, and then we stop. The evidence is a directory listing and a permission proof, not damage.
Where this sits next to other engagements
If you want the full enumeration of what is wrong across the estate, that is a network or Active Directory engagement. If you want to know whether your defenders catch someone moving, that is purple team or a red team assessment. This engagement answers a narrower and more actionable question: given one compromise, how much of the business is downstream of it?
Questions
No. Nothing is encrypted and nothing is destroyed. We prove the access that would make encryption possible and stop there, with permission proofs and directory listings as the evidence.
Whatever is realistic for your threat model and agreed in advance. Commonly a standard domain user account, or local access on one workstation as if a laptop had been phished. Both are scoped in writing.
We test whether they are reachable and modifiable from the privilege an attacker would obtain. That is a different question from whether restores work, which your own team should be exercising, and we will say so in the report if it looks like nobody is.
Five to ten business days depending on estate size and how many distinct backup and storage systems are in scope.
From $1,500, scoped like an internal network engagement.
Scope it properly before you buy it.
Thirty minutes on the call, a fixed price in writing within 24 hours, and an honest answer if this is not the engagement you need.