Skip to main content
    NixInfinity-AI
    Risk Assessment

    How to Assess Ransomware Risk Like a Cyber Assessor

    Published 2 July 2026

    The four dimensions

    1. Threat activity. Is ransomware genuinely active against UK organisations of your size and sector right now? For the last few years the answer has been yes across every sector.
    2. Business impact. If your key systems went offline for 5 days, and 50 GB of client data leaked, what would break? Revenue, contracts, regulatory position, reputation.
    3. Attacker capability. You do not need to name specific groups. Assume affiliates using commodity tooling, stolen credentials and phishing.
    4. Organisational exposure. Your own attack surface: internet-facing systems, admin accounts, patch cadence, MFA coverage, supplier access, backup maturity.

    An SME scoring template

    Score each row as Low / Medium / High. This is a working conversation, not a formal risk methodology.

    • Internet-facing systems – how many, and who owns patching?
    • Admin account count and MFA coverage.
    • Cloud tenants and their conditional access posture.
    • Remote access routes (VPN, RDP, jump hosts).
    • End-user device management consistency.
    • Third-party and MSP access.
    • Sensitive data locations and access lists.
    • Backup immutability and tested restore time.
    • Incident response plan freshness and last tabletop date.
    • Cyber insurance coverage and named contacts.

    Anything scored High on both impact and exposure is your first pass of remediation work.

    Common mistakes when self-assessing

    • Judging likelihood on "have we been hit before?" rather than "are attackers active against organisations like us?"
    • Confusing "we have backups" with "we have tested restore under incident conditions".
    • Assuming an MSP or cloud provider certificate covers your own scope. See why supplier certificates do not extend to customers.
    • Ignoring administrator endpoints. They are often the highest-value target and the least hardened asset.

    How this connects to certification

    Cyber Essentials sets a technical baseline. Cyber Assurance adds governance around risk, data, incident response and supplier assurance. If you cannot honestly answer half of the rows above with evidence, Cyber Assurance is the natural next step after CE.

    Turning the score into action

    1. Fix any High exposure item with a Low control cost first (usually MFA and patching).
    2. Schedule tabletop exercises for the top three scenarios (ransomware, data leak, MSP compromise).
    3. Rework supplier contracts to include breach notification and access controls.
    4. Book a review 6 months out. Scores drift.

    If you want a second pair of eyes on the exercise, our team runs pre-certification readiness reviews that follow the same structure.

    Want an outside view on your ransomware exposure?

    Our IASME-licensed assessors run pre-certification readiness reviews covering scope, controls and evidence.

    Frequently Asked Questions