How to Prepare for a Ransomware Attack: A 90-Day Security Operations Plan for Mid-Market Organizations

By Ron Samson

The operating problem is bigger than endpoint prevention

Ransomware preparation is not a software shopping exercise. For a mid-market organization, it is the discipline of proving that identities, endpoints, backups, network controls, and decision makers will work together during a fast-moving business interruption. Attackers increasingly steal data before encrypting it, turning recovery into a legal, customer, and negotiating event as well as an IT incident. The practical question is not whether a tool blocks every malicious file. It is whether your team can recognize lateral movement, contain affected systems, preserve evidence, restore priority services, and communicate with confidence before disruption becomes existential.

That standard matters because the middle market carries enterprise attack surface without enterprise staffing depth. Cloud applications, remote administration, supplier connections, and acquisitions create blind spots faster than an internal team can normalize logs and rehearse recovery. Verizon’s 2025 Data Breach Investigations Report identifies credential abuse and vulnerability exploitation among leading initial access paths, while ransomware remains a material action pattern in breaches. A ninety-day operations plan converts those findings into owned work, measurable evidence, and a response capability that survives weekends, turnover, and pressure.

💡 Operating principle: prioritize recoverability and time to contain over a long list of controls. A partially deployed platform, untested backup, or alert queue nobody owns is not resilience.

What success looks like on day ninety

By day ninety, leadership should be able to answer five questions without assembling a crisis committee: Which services must return first? Who can isolate an endpoint or disable a privileged account? Which detections create a human investigation? Where are immutable recovery copies? Who has authority to declare an incident, engage counsel, notify insurers, and speak externally? The plan below is sequenced deliberately. Early work reduces immediate exposure; middle work improves visibility and containment; final work validates the operating model. It does not assume a new security stack is necessary. It requires that the existing stack produces dependable decisions.

Phase Days Objective Evidence for leadership
Stabilize 1–30 Remove easy access paths Named owners, protected identities, tested backup scope
Instrument 31–60 Detect and contain real attack behavior Coverage map, tuned alerts, isolation workflow
Validate 61–90 Prove response and recovery Exercise results, remediation backlog, executive metrics

Assign one executive sponsor, one operational owner, and named technical owners for identity, endpoints, backups, network, applications, legal, and communications. A RACI is useful only when it names an on-call decision maker and a backup. Track every action in a short weekly operating review: status, blocker, risk accepted, evidence collected, and next decision. This is how security work remains visible when production priorities compete for the same engineers.

How to Prepare for a Ransomware Attack: A 90-Day Security Operations Plan for Mid-Market Organizations
A ninety-day plan makes ransomware readiness an operating discipline.

Days one through thirty: stabilize identity and recovery

Start with the routes attackers use to become trusted. Inventory administrator accounts across identity providers, endpoints, firewalls, backup consoles, cloud tenants, and SaaS applications. Eliminate shared privileged accounts where possible; require phishing-resistant multifactor authentication for administrators; and remove dormant accounts, stale service credentials, and unnecessary remote access. Review break-glass accounts separately: they should be tightly controlled, monitored, documented, and tested, not forgotten exceptions. CISA’s ransomware guidance emphasizes multifactor authentication, patching, and tested backups because these measures interrupt common intrusion paths before encryption begins. If legacy systems cannot support modern controls, place them behind compensating network restrictions and create a dated replacement decision.

Deliverables for the first thirty days:

  • A privileged-access register with owner, purpose, MFA status, and quarterly review date.
  • A ranked external attack-surface list, including internet-facing VPN, remote desktop, appliance, and cloud administration exposure.
  • A recovery inventory that maps critical applications to recovery objectives, dependencies, copy locations, and restoration owners.
  • An immutable, offline, or logically isolated backup copy, with a documented restore test for each tier-one service.

Backup status deserves particular skepticism. A green dashboard may prove a job completed, not that a clean application can be restored within the business tolerance. Select two tier-one services and perform a measured restoration into an isolated environment. Record elapsed time, missing dependencies, credential requirements, data integrity checks, and approvals needed to return service. Those facts establish realistic recovery time objectives and expose whether attackers could reach the backup control plane using ordinary administrator credentials.

Days thirty-one through sixty: instrument detection and containment

Visibility work begins by deciding what activity should force investigation. Centralize identity, endpoint, firewall, VPN, DNS, email, cloud audit, and backup-administration telemetry. Do not confuse ingestion with detection. For each critical source, document retention, parsing quality, coverage percentage, alert owner, and the response action an analyst can take. Prioritize behaviors that precede ransomware impact: unusual privileged sign-ins, impossible travel paired with token abuse, mass account changes, remote-tool deployment, disabling security software, suspicious archive creation, and rapid file-encryption activity. MITRE ATT&CK is a practical common language for mapping these use cases to adversary techniques and finding coverage gaps. The goal is fewer alerts with clearer escalation paths, not a larger dashboard.

Mid-market teams often own capable EDR and SIEM technology but lack round-the-clock triage, correlation tuning, and incident authority. That gap is operational, not merely technical. A provider should explain which telemetry it monitors, how it validates alerts, when it can isolate a host, how it preserves customer context, and how its analysts coordinate with your internal administrators. Clearnetwork’s Managed Detection and Response approach is relevant when endpoint signals require active investigation, while Managed SOC Services can extend monitoring across the broader control environment. Ask for workflows, service-level commitments, escalation examples, and reporting that shows analyst decisions rather than raw alert volume.

💡 Detection test: simulate a disabled endpoint sensor, a suspicious administrator login, and an attempted backup-console login. Confirm that the right people receive actionable context, know their authority, and record the outcome.

Containment must be preauthorized where speed matters. Define device-isolation criteria, account-disable criteria, emergency firewall changes, and approvals for taking a business application offline. Build a contact roster that includes executives, incident counsel, cyber insurer contacts, forensics support, communications, and key vendors. Then run a thirty-minute tabletop: an employee reports encrypted files, the EDR reports credential dumping, and a customer asks whether data was taken. Measure decision latency and unresolved questions. This baseline guides the final month.

Days sixty-one through ninety: validate the business response

During the final thirty days, treat the plan as a production service. Conduct a scenario-based exercise that begins with a realistic alert and progresses through containment, executive notification, evidence preservation, recovery prioritization, and customer communication. Include a decision inject: the attacker claims exfiltration, a critical vendor is unavailable, or a restore reveals dormant malware. The exercise should not reward polished slides. It should reveal delays, missing access, unclear authority, and technical assumptions. NIST’s Cybersecurity Framework 2.0 and its incident-response guidance offer useful structure for governing these activities across identify, protect, detect, respond, and recover outcomes. Convert every finding into a named remediation item with due date, business owner, and verification method.

Metric Target Why it matters
Mean time to acknowledge High-severity alerts reviewed within agreed operating window Shows whether monitoring reaches a human
Mean time to contain Tested isolation completed within a defined business threshold Measures authority and technical execution
Restore confidence Tier-one restore demonstrated and documented Measures recovery rather than backup completion
Detection coverage Critical assets sending usable telemetry Identifies blind spots before an attacker does

Report these measures monthly to leadership alongside material exceptions: unsupported systems, systems without endpoint coverage, privileged accounts lacking phishing-resistant MFA, untested recovery tiers, and detections without owners. Avoid vanity metrics such as events ingested or training modules assigned. Executives need trend, exposure, decision, and investment information. A concise scorecard also gives finance and procurement a defensible basis for prioritizing hardening work, specialist support, and cyber-insurance requirements.

Technology decisions: buy coverage, not another console

Tool decisions should follow the operational design, not lead it. Start by confirming what your current identity platform, EDR, backup product, firewall, email security service, and SIEM can actually enforce or detect. Then identify the gap: telemetry absent, detection untuned, analysts unavailable, containment too slow, or recovery unproven. Buying an overlapping product may improve a demo while leaving the underlying gap intact. For endpoint-heavy environments, managed endpoint operations such as Managed CrowdStrike can add continuous alert triage and policy attention. For organizations centralizing logs, the AlienVault platform can support SIEM monitoring when correlation rules, asset context, and response workflows are actively maintained. The decision criterion is accountable coverage: who watches, what they can do, and how success is evidenced.

Provider evaluation should therefore include a live discussion of the handoff, not a feature checklist. Ask how the service handles incomplete asset inventories, new acquisitions, false-positive tuning, after-hours escalation, and a customer who cannot approve an action immediately. Confirm data ownership, log retention, investigation records, threat-hunting scope, and exit support. A strong managed relationship makes internal teams more effective; it does not hide the controls or replace executive accountability. Organizations considering build versus buy can also assess SOC as a Service against staffing cost, coverage requirements, and the maturity of their existing tools.

Make ransomware readiness a repeatable operating capability

A ninety-day plan is valuable because it establishes cadence, evidence, and accountability. It is not a one-time certification. Repeat the access review, restore test, alert validation, and executive exercise on a schedule tied to business change. Add new subsidiaries, applications, suppliers, and critical data flows to the scope before they become urgent. When a ransomware event occurs, the organization should not be improvising roles or debating where logs reside. It should be executing a practiced sequence with known limits, clear escalation, and recoverable services. That is the business outcome security leaders can defend: less uncertainty, shorter disruption, and decisions made from evidence rather than fear.

Need an independent ransomware readiness review?

Clearnetwork helps mid-market teams turn security investments into monitored, tuned, and tested operations. Review your priorities, coverage gaps, recovery evidence, and incident workflows with practitioners who understand the handoff from alert to action.

Request a cybersecurity assessment

Sources and further guidance

Verizon, 2025 Data Breach Investigations Report.

CISA, StopRansomware Guide and ransomware response resources.

NIST, Cybersecurity Framework 2.0 and Computer Security Incident Handling Guide.

Questions security leaders should settle before an attack

How often should we test ransomware recovery?

Test tier-one recovery at least quarterly and after material changes to identity, backup architecture, applications, or infrastructure. Test more than file retrieval: validate application dependencies, administrator access, data integrity, security-tool health, and the time needed for business owners to accept service. The right frequency is the one that keeps your recovery evidence current enough for the rate of change in your environment.

What is the first action after suspected encryption?

Protect people and contain spread. Activate the incident lead, isolate affected endpoints according to preapproved criteria, preserve volatile evidence where feasible, and disable compromised accounts or sessions. Do not immediately reboot, wipe, or broadly restore systems before scoping the intrusion. Engage counsel, your insurer, and qualified response support early, then use your written service priorities to guide recovery. Every action should be timestamped and recorded for investigation, notification, and lessons learned.

The next ninety days begin with ownership

Choose a small set of actions that change your exposure this week: protect privileged identities, verify one restore, confirm endpoint coverage, and assign incident authority. Next, make the results visible. A weekly review should force decisions on exceptions, funding, ownership, and dates instead of allowing risk to remain a spreadsheet entry. Over the next quarter, extend that discipline into detection engineering, after-hours response, and rehearsed communications. The organization does not need perfect certainty to improve ransomware resilience. It needs a realistic view of what can fail, a practiced way to contain failure, and evidence that critical operations can return. That combination gives boards and operating leaders something more useful than assurances: demonstrable control over the moments that determine whether a security incident becomes a prolonged business crisis. Start with ownership; keep testing every critical assumption.


About

Ron Samson