Protego field desk
Security Best Practices and Priorities / 20-25% of exam

L1.Ransomware Resiliency, BCDR & Secure Recovery

Course outlineLesson 1 of 18

Design a ransomware-resilient strategy that starts with critical business assets, protects recovery paths, and proves that backups can actually restore operations.

Start with business-critical assets

An architect does not begin with a product list. Identify the processes the organization must restore, the data and identities those processes depend on, and the acceptable recovery time and recovery point. Threat modeling then connects likely attacks to those assets so investment follows business impact.

Protect the recovery system

Backups are part of the security boundary. Separate backup administration from production administration, use immutable or logically isolated copies, require strong authentication for destructive operations, and monitor changes to backup policy. A backup is not a recovery capability until the organization has restored it in a controlled test.

RequirementArchitecture response
Limit blast radiusSegmentation and least privilege
Preserve recovery dataIsolated, immutable backup copies
Recover within the targetTested runbooks and dependency order
Resist admin compromisePrivileged access workstations and just-in-time roles

Prioritize privileged access and updates

Ransomware commonly turns one foothold into broad impact through privileged accounts and unpatched systems. Treat privileged access, emergency access, security updates, endpoint protection, and BCDR as one resiliency program. Rank remediation by exposure and business consequence, not only by vulnerability severity.

Validate the design

Run restore exercises that include identity, networking, secrets, applications, and data. Capture measured recovery time, missing dependencies, and decisions that need an owner. The exam favors designs that prove recovery over designs that only state a backup policy.

Exam Focus Points
  • Prioritize threats to business-critical assets before selecting controls
  • Secure backup administration and keep isolated or immutable recovery copies
  • Treat privileged access and BCDR as primary ransomware mitigations
  • A successful restore test is stronger evidence than backup-job success
Knowledge Check

1. Which result gives the strongest evidence that a ransomware recovery design meets business requirements?