New Blog
Ransomware Resilience: What ISO 27001 Requires Businesses to Do
This blog explains how ISO 27001 helps organisations build ransomware resilience through a layered security approach. It explores the key Annex A controls that support prevention, detection, response and recovery, including multi-factor authentication, vulnerability management, secure backups, access control reviews, least privilege, business continuity planning and threat awareness.


Ransomware Resilience: What ISO 27001 Requires Businesses to Do
ISO 27001 as a standard asks business to protect themselves against multiple attack vectors such as a Ransomware by focusing on various domains which indirectly contribute to a defence in depth framework.
The multiple controls on Annex A address ransomware resilience effectively through the below control mechanisms which are given an overview below:
Identity and Access Management
MFA makes it harder for cybercriminals to gain initial access to your device, account and information by making them have to jump through more security hoops and additional authentication layers. This means that the cybercriminal will have to spend more time, effort, and resources to get into your
device before any ransomware attacks can begin. Two-factor authentication (2FA) is the most common type of MFA. It provides enhanced security to traditional usernames and passwords/passphrases and increases confidence that the user requesting access is actually who they claim to be.
Vulnerability Management
Having an up-to-date operating system (Windows, macOS or other) and security software reduces the chance of a cybercriminal using a known weakness to hack your computer. It also provides security upgrades and protections for your device against other threats.
Backups
A backup is a digital copy of your most important information (e.g. financial information or organisation sensitive records) that is saved to an external storage device or to the cloud. Backing up is a precautionary measure, so that your information is accessible in case it is ever lost, stolen or damaged through a ransomware attack.
The best recovery method for a ransomware attack is a regular offline backup made to an external storage device and additionally a backup in the cloud. Regularly backing up your files is recommended. What that looks like, whether it’s daily, weekly, monthly or less often, is ultimately up to you. Backup frequency depends on the number of
new files you load onto your device and the number of changes you make to files.
ISO 27001 goes an additional step further and requires that organisations also verify the backups taken through restoration drills conducted periodically which ensures that backed up information is indeed restorable during an emergency.
Access Control Reviews
Implementing access controls is an important step in managing who can access what on your devices. This is especially true in a business context. Access controls help minimise the risk of unauthorised access to important information, which then helps to minimise the consequences of ransomware running
on devices by limiting the amount of information it can encrypt, steal and delete.
Principle of least privilege
The principle of least privilege is the safest approach
for most. It gives users access only to the software applications and files they need to perform their job.
In addition to implementing correct access controls ISO 27001 also asks organisations to conduct Access control reviews on multiple platforms and maintain records of these hence these can be always reviewed, and access control is securely maintained.
Business Continuity Planning
Requires organisations to plan how they will maintain an appropriate level of information security during disruptions. This includes maintaining integrity and confidentiality of information, so under this control you should ensure that information security controls still work in case of a disruption.
Organisations should make sure controls also work in times of crisis or have alternative controls in place to compensate in times of crisis. Also requires organizations to verify how their information and communication systems (ICT systems) work in times of disruption.
ISO 27001 furthermore requires organisations to conduct simulation exercises to test their business continuity planning which proves as an effective mitigation control when an organisation wide cyber crisis like a ransomware is being faced.
Remain vigilant and informed
While it is one thing to have built up your defences to protect your information, it is best to remain on the lookout for evolving cyber threats and trends which could impact you at any time.
ISO 27001 asks organisation security and technology teams to subscribe and be a part of special security forums hence keeping them updated for any zero day exploits etc.
Strengthen your ransomware resilience with ISO 27001.
Our ISO 27001 specialists can help you implement practical controls, identify gaps and build a stronger approach to information security.
Get in touch to find out how we can support your journey to ISO 27001 certification.
Share your challenge with us and we’ll help you find the right level of support for your business.














