Enya Security
Request an audit
SERVICE

Ransomware
readiness audit

Assess how well your organisation would withstand a ransomware attack and strengthen your resilience before one happens.

Technical and
operational approach
100% remote
no downtime
Concrete, prioritised
recommendations
Rigorous
methodology
Response within 24-48 business hours
Workstations & servers
Identity & access
Detection & response
Recovery plan
Network
Staff awareness
Critical data
Backups

WHAT WE ASSESS

Attack surface

  • Exposed services
  • Remote access (RDP, VPN...)
  • Known vulnerabilities
  • Filtering & segmentation

Backups

  • 3-2-1 rule applied
  • Offline copies
  • Restore test < 6 months
  • Network isolation of backups

Systems & patching

  • Antivirus deployed & current
  • Critical patches < 30 days
  • Office macros disabled
  • MFA on critical access

Response & resilience

  • Incident response plan
  • Crisis RACI matrix
  • Former staff accounts disabled
  • Password manager in place

OUR APPROACH IN 6 STEPS

1

Discovery

Understanding your environment and what matters to you.

2

Collection

Gathering technical and organisational information.

3

Analysis

Assessing your readiness against a ransomware scenario.

4

Scoring

Overall readiness score and risk prioritisation (P1, P2, P3).

5

Report

A clear report with findings, impacts and practical recommendations.

6

Action plan

Debrief call and an action plan to strengthen your resilience.

DELIVERABLES

  • PDF audit report

    4-5 pages (Express) to 8-12 pages (Standard)

  • Incident response plan

    1-page crisis sheet (Express) or full 2-page plan with RACI matrix (Standard)

  • Kill switch sheet

    Network isolation procedure to print and post on the wall

  • Police report template

    Pre-filled Word document

  • Crisis contact directory

    5 to 10 key contacts depending on the tier

  • Awareness handout

    1 page to circulate among your team

WHY ENYA SECURITY?

  • Complete independence

    No partnership with any software vendor.

  • Modules matched to your setup

    Cloud, Active Directory, regulated sector, IT providers — only where relevant.

  • Clarity over jargon

    A report and crisis plan the whole team can follow.

  • Flexibility

    Fully remote engagements, with no interruption to your business.

  • Transparency

    Fixed fees, no surprises.

FREQUENTLY ASKED QUESTIONS

What does this audit involve in practice?

It assesses how ready you are for a ransomware attack: attack surface, backups, systems and patching, and response capability. Unlike an intrusive technical audit, it relies on a questionnaire, an inventory and, where available, read-only access or screen sharing.

Will this disrupt my operations?

No. The audit is non-intrusive: interviews, document review and light technical checks such as an external exposure scan. No service interruption is required.

What if I have no server or Active Directory?

The Express tier is designed exactly for small organisations without complex infrastructure — standalone workstations, no domain. Optional modules (Cloud, Active Directory, regulated sector, IT providers) are only activated, and only billed, where they are relevant to your setup.

Would you recommend paying the ransom?

No. In line with guidance from national cybersecurity agencies, paying a ransom is strongly discouraged: it does not guarantee you get your data back and it funds criminal groups. The response plan we build with you is designed precisely to reduce your dependence on that option.

Is my data kept confidential?

Yes. A non-disclosure agreement is signed before any technical discussion, and the information collected is handled under our internal data management policy. More detail in our privacy policy.

Ready to test your resilience against ransomware?

Tell us about your situation and get a tailored quote in under 48 hours.

Request an audit Response within 24-48 business hours