Ransomware is an operational risk before it is a technical event. The most useful preparation is the work that helps a team contain an intrusion, keep essential services running and recover with confidence.
Singapore's Cyber Security Agency reported 165 ransomware cases in 2025. Most affected organisations were small and medium enterprises in wholesale and retail trade, manufacturing and construction. CSA also notes that ransomware is likely underreported. The lesson is practical: smaller organisations need a response model they can operate with the people and systems they actually have.
1. Know which systems must recover first
Start with the services the business cannot operate without. Map each service to its applications, identities, data, infrastructure, vendors and recovery dependencies. This makes recovery priorities explicit and stops a team from discovering hidden dependencies during an incident.
2. Protect identities as carefully as endpoints
Attackers often use valid credentials to move through an environment. Enforce multi-factor authentication for privileged and remote access, remove dormant accounts, separate administrator identities from day-to-day accounts and review external access regularly. Privileged sessions should be controlled and auditable.
3. Monitor the signals that show an attack unfolding
Endpoint, network, cloud and identity events provide different parts of the same story. A managed detection and response service should connect these signals, investigate credible activity and follow agreed escalation and response playbooks. The goal is not a larger queue of alerts. It is faster understanding and action.
4. Make recovery evidence-based
Keep protected backups, define recovery time and recovery point objectives, and test restoration. A successful backup job does not prove that an important service can be restored within the time the business expects. Record test results and close the gaps found.
5. Rehearse the decisions
A short tabletop exercise exposes unclear authority, missing contacts and untested assumptions. Decide who can isolate systems, stop services, contact customers, notify regulators and engage external responders. NIST's current incident response guidance treats preparation and improvement as part of ongoing cybersecurity risk management, rather than a plan that is opened only during a crisis.
Prioritise the systems that support revenue, safety, customer service and regulatory duties. Then validate identity controls, monitoring coverage, containment authority and recoverability around those systems.