Ransomware readiness: protect continuity & recovery with confidence and trust

The 16-year prison sentence was recently handed to Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, is a substantial law-enforcement outcome. His arrest disrupted the group’s growth, and his prosecution removed an experienced operator who had spent years building ransomware infrastructure and recruiting participants.

For businesses, however, the more consequential lesson lies elsewhere.

Ransom Cartel attacked at least 18 organisations between 2021 and 2023. Its operating model was really really ORGANISED, it separated the people building and administering the ransomware operation from affiliates carrying out intrusions. Participants could obtain compromised access, encryption tools and infrastructure for managing attacks, negotiating with victims and distributing criminal proceeds.

The sentence may weaken “one criminal operation”. It does little to change the underlying economics that made the operation possible.

Ransomware has become less dependent on a single attacker, malware strain or criminal group. Access can be obtained separately, attacks can be executed by affiliates, data can be stolen before systems are encrypted, and the victim can face several forms of pressure simultaneously.

That changes the question companies should be asking.

Preventing ransomware remains necessary. The harder question is whether the business can continue operating when prevention fails.

A recent cyberattack on French rugby club Stade Français offers a useful contrast.

The club said parts of its information systems were disrupted, but it restored its IT environment from clean backups and continued normal operations. Its ticketing platform and online store remained operational.

Yet recovery did not end the incident.

A sample of data allegedly stolen during the attack appeared online, forcing the organisation to investigate the extent of the breach, determine whose information may have been affected, engage authorities and manage communications with stakeholders.

The paradox is clear.

An organisation can restore its systems and still remain inside the crisis.

That distinction should shape how boards and management teams assess ransomware readiness.

A traditional ransomware discussion often concentrates on whether endpoint controls are working, vulnerabilities are being patched, backups exist and security teams can detect

malicious activity.

Those measures matter. They do not establish whether the enterprise can sustain its critical business operations while technology teams investigate, isolate and rebuild compromised systems.

The immediate challenge is operational continuity.

For a bank, the issue may be whether customer transactions and critical financial services remain available. For an insurer, it may be claims processing, policy servicing or partner connectivity. A pharmaceutical company could face disruption to manufacturing, quality or supply-chain processes. A manufacturer may have to determine which plants, production lines, logistics systems and enterprise applications can operate safely while parts of the technology environment remain isolated.

This is where ransomware moves beyond cybersecurity.

Management has to decide which business services must continue, which systems can be taken offline, which manual alternatives are viable, which dependencies have to be restored first and how long the organisation can tolerate degraded operations.

Those decisions cannot be developed for the first time during an attack.

The second issue is recovery confidence.

A backup is an asset. A tested ability to restore the business from a trusted state is evidence of resilience.

The distinction matters because an organisation recovering from ransomware cannot simply restore data and assume that the problem has disappeared. CERT-In’s ransomware guidance specifically advises organisations to ensure that previous vulnerabilities and threats have been eliminated and to restore from backups or restore points that have been verified as infection-free.

That creates a more demanding management question: how does the organisation know that the environment being returned to production is clean?

Recovery confidence therefore depends on more than backup completion percentages.

It depends on whether recovery sequences have been tested, whether identities and privileged accounts can be trusted, whether compromised systems have been rebuilt where necessary, whether dependencies between applications are understood, whether recovered data is usable and whether the business has established acceptable recovery priorities.

A technically successful restoration that introduces the attacker back into the environment is not recovery.

Nor is restoring hundreds of systems over several weeks necessarily a satisfactory outcome if the systems supporting revenue, customers or critical operations were unavailable for most of that period.

Boards should therefore be cautious about ransomware-readiness reporting based largely on technical activity. Patch rates, security alerts, endpoint coverage and backup-success percentages provide useful information, but they do not answer the more consequential question: how much business can the organisation continue if its primary technology environment becomes unavailable?

The third issue is data.

The Ransom Cartel cases illustrate the economics of double extortion. Attackers stole information before encrypting systems and then demanded money either for decryption or for a promise that stolen information would not be published.

The Stade Français incident illustrates the consequence. Systems can return while uncertainty about stolen information continues.

This creates two recovery timelines. The TECHNOLOGY RECOVERY & THE STAKEHOLDER RECOVERY

The technology recovery timeline concerns systems, applications, infrastructure and data restoration. This is usually very clear & fast.

The stakeholder recovery timeline can be considerably longer. It may involve forensic investigation, legal assessment, regulatory reporting, customer notification, employee communication, contractual questions and continuing uncertainty over whether stolen information will appear publicly.

An organisation can therefore meet its recovery-time objective and still face a prolonged business crisis.

The fourth issue is governance.

The governance question may prove harder than the technical one because ransomware compresses decisions that would ordinarily be taken over weeks into hours.

Who can authorise the isolation of a critical business system?

Who determines whether operations continue in a degraded state?

Who decides when recovered systems are sufficiently trusted to return to production?

Who has authority over communications with an attacker?

Who coordinates regulators, law enforcement, customers, employees, partners and the media?

And if operational continuity conflicts with forensic preservation or containment, who makes the final decision?

These are questions of authority and accountability.

Indian financial-sector regulation increasingly reflects that reality.

The Reserve Bank of India’s Information Technology Governance, Risk, Controls and Assurance Practices Directions place strategies and policies covering business continuity, cybersecurity, incident response, recovery management and cyber-crisis management under board approval. RBI also requires regulated entities to test crisis-communication processes and periodically restore backed-up data to verify usability. Critical systems are subject to disaster-recovery testing that includes operating from the alternate environment.

SEBI’s Cybersecurity and Cyber Resilience Framework similarly establishes a formal resilience framework for regulated entities in the securities market, with further clarifications issued during 2025. IRDAI maintains its Information and Cyber Security Guidelines for insurance-sector regulated entities.

For pharma and manufacturing companies, the regulatory structure is different, but the operational problem is no less material. CERT-In’s directions apply broadly to service providers, intermediaries, data centres, body corporates and government organisations, including requirements for specified cyber incidents to be reported within 6 hours of noticing them.

This makes ransomware readiness particularly relevant to BFSI, insurance, pharma and manufacturing organisations, though for different reasons.

But Boards need assurance that management / organisations at large understands how a ransomware incident becomes a business interruption. That evidence should come from practising the scenarios the organisation may face under realistic conditions.

Eg: A meaningful ransomware exercise should force leadership to operate with incomplete information. Some systems should be unavailable. A backup should be questioned. Stolen information should appear externally. A critical supplier should become unreachable. Regulators, customers or journalists should begin asking questions before the technical investigation has reached a conclusion.

The objective is not to demonstrate that everyone knows the incident-response plan.

It is to determine whether the organisation can make defensible decisions while revenue, operations, regulatory obligations and stakeholder confidence are simultaneously under pressure.

The CFO may need to assess financial exposure and payment controls. Operations leaders must determine whether critical services can continue. Legal teams need to consider notification, contractual and evidentiary questions. Communications teams have to manage information that may remain incomplete. Risk leaders need an enterprise view of the consequences. The CEO may ultimately have to arbitrate between competing priorities.

The Silnikau prosecution demonstrates that ransomware operators can be identified, extradited, prosecuted and imprisoned. It also demonstrates how industrialised the operating model has become: one person can create infrastructure that allows others to acquire access, attack organisations and conduct extortion at scale.

That makes waiting for the threat environment to improve an inadequate strategy.

The more useful standard is whether the enterprise can ABSORB the attack.

Ransomware readiness should therefore be treated as an enterprise operating capability, tested under pressure and measured against continuity, recovery confidence and trust.

For leadership teams reviewing their preparedness, the executive conversation can begin with one question:

If ransomware disabled a critical part of the organisation tonight, what evidence gives the board confidence that the business could continue tomorrow?

AmbiSure works with boards, executive teams and security leadership to examine that question through ransomware-readiness assessments, executive cyber exercises and incident-governance reviews, with the discussion centred on business continuity, recovery confidence and decision readiness rather than technology alone.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top