Free · About 15 minutes · No software installation

How ready is your business for ransomware?

Twelve practical questions across six areas. Get a readiness score, a short list of next actions, and a printable checklist to discuss with your IT team.

This is directional education—not an audit, certification, or guarantee. We do not ask for passwords, logs, or sensitive system details.

Already know you need help? Request an environment review →

Answer what you know.

Choose the most accurate answer today. “Partly / not sure” is useful information.

0 of 12 answeredIdentity

Identity

01 / IdentityIs multifactor authentication required for email, remote access, and administrator accounts?

Strong coverage includes every privileged and externally accessible account, not just some employees.

02 / IdentityDo administrators use separate accounts for privileged work instead of daily email and browsing?

Separating daily and administrative access limits what an attacker can do with one compromised account.

03 / IdentityAre former employees and contractors removed promptly from email, cloud applications, and remote access?

A repeatable offboarding process prevents forgotten accounts from becoming an easy way back into the business.

Endpoints

04 / EndpointsCan your team confirm that every active laptop, workstation, and server has current endpoint protection?

A reliable inventory should include remote devices and systems that rarely connect to the office network.

05 / EndpointsCan your IT or security team isolate a suspicious device quickly without being physically present?

Fast remote isolation can stop one compromised endpoint from reaching shared systems.

Backups

06 / BackupsAre critical backups protected from the same accounts and systems used in daily operations?

Attackers often target accessible backups before encrypting production data.

07 / BackupsHas your team successfully restored important data or a critical system within the last six months?

A completed restore test is stronger evidence than a backup dashboard showing green status.

Response

08 / ResponseIs one person clearly authorized to coordinate technical and business decisions during a cyber incident?

A named owner reduces delay when systems, insurance, legal counsel, and customer communication must align.

09 / ResponseCan your team reach IT, leadership, insurance, and outside response contacts without relying on company email?

Ransomware can make normal email, files, and contact lists unavailable at the moment they are needed.

Recovery

10 / RecoveryHas leadership identified which business systems and processes must return first?

Recovery is faster when technical restoration follows agreed business priorities.

11 / RecoveryHas the organization practiced a ransomware or major-outage scenario in the last year?

A short tabletop exercise exposes unclear authority, missing contacts, and unrealistic recovery assumptions.

Insurance

12 / InsuranceDo you know whether your cyber-insurance policy requires EDR, multifactor authentication, or continuous monitoring?

Security questionnaires and policy conditions may require more than traditional antivirus. Confirm requirements with your broker or insurer.

Your result

Get your score, action list, and printable checklist.

Share your details to see your score and download the checklist. Tallgrass may follow up once with a useful observation or an invitation to review the score. No spam.

Would you like Tallgrass to review your result with you?

Do not enter passwords, technical logs, employee data, or incident details.

After the check

A starting point for your next security conversation.

  1. 1
    See your readiness band

    Get an immediate score out of 12 and a clear readiness band.

  2. 2
    Prioritize the gaps

    Use your next actions to focus the conversation with your IT team.

  3. 3
    Keep the checklist

    Download the printable workbook or request a review with Tallgrass.