Ransomware Recovery Readiness Audit, Cyber Recovery Audit


Certified Information Systems Auditors.  Know what you could restore, and how long it would take, before you need to.



Every engagement is unique. We are happy to customize our audit services to your specific needs.


Ransomware Recovery Readiness Audit


Ransomware recovery readiness audit

Could You Recover From Ransomware?
Most organizations find out what their recovery is actually worth during the incident, which is the most expensive moment to learn it.  Altius IT's ransomware recovery readiness audit answers three questions before an attacker asks them for you: what could you restore, how long would it take, and what would you lose.

Backups that complete successfully are not the same as backups that restore.  Our audit tests the difference, and reviews the controls that decide whether an intrusion becomes an outage:

  • Backup coverage and integrity - which systems and data are actually covered, immutability and air gapped or offline copies, retention periods, encryption of backup media, and whether backup credentials are separated from production so the same compromise cannot reach both.
  • Restore testing - evidence that restores have been performed, timed, and validated, rather than backup jobs that report success and have never been read back.
  • Recovery objectives - documented recovery time objectives and recovery point objectives for each critical system, measured against how long a restore actually takes, and the gap between the two.
  • Containment and spread - network segmentation, privileged and administrative accounts, multi factor authentication, remote access, endpoint protection, and logging and monitoring that would show an attacker moving before encryption starts.
  • Incident response - a current plan with named roles and contact trees, notification obligations to regulators, clients, and law enforcement, cyber insurance conditions you are required to meet, and evidence the plan has been exercised.

Our report identifies each specific gap and provides detailed instructions to close it, ordered so that the changes which reduce your risk the most come first.

Measured Against Recognized Standards
Findings are mapped to the frameworks your regulators, insurers, and clients already recognize: the Recover and Respond functions of the NIST Cybersecurity Framework, NIST SP 800-34 contingency planning, and the joint CISA and FBI #StopRansomware Guide.  Where a ransomware event would also be a reportable breach, we identify the obligation rather than leave it for your counsel to discover later.

Audit Report
Altius IT's reports provide specific recommendations and detailed steps you can take to address any identified gap in your recovery. After delivery of our reports, Altius IT provides three months of free support to answer any questions you may have. This ensures your recovery gaps are properly mitigated or eliminated.

Certified Auditor Letter
Let your clients, your board, and your cyber insurer know that your recovery has been independently tested.  As an IT security audit company with Certified Information Systems Auditors, we can provide you with our Auditor Opinion Letter stating your systems meet security and compliance requirements.

Audit Team
Altius IT provides a certified auditor with each engagement:

  • Certified Information Systems Auditor
  • Experienced Project Manager
  • Senior Security Engineer

Proposal
Our proposal provides you with detailed information so you know exactly how we will help you:

  • Project scope and tasks
  • Pricing options
  • CV's of our audit and security team members
  • Sample reports you will receive
  • Why Altius IT

We Do Not Sell the Fix
Altius IT sells no backup software, no recovery platform, and no managed service.  Nothing in our report is a product we benefit from you buying, which is what makes the finding worth reading.  See Why Altius IT.

Client Experience
Altius IT works with a diverse number of clients across a wide range of industries.  We help organizations of all sizes, from the smallest mom and pop start-up to the world's largest and most recognized names.  Our case studies show how we have helped organizations identify, manage, and reduce their risks.


If You Want a "Security Audit" You Need a Certified Auditor

Certified Information Systems Auditors

Certified Information Systems Auditors
Unlike a security consultant, Altius IT is certified as a Certified Information Systems Auditor to perform a security audit of your environment and issue reports and recommendations to secure your systems. After your audit, Altius IT's Auditor Opinion Letter and Secure Seal let your clients and prospects know you meet security best practice/compliance requirements.

See our Media page for video clips of our experts as well as over 40 publications featuring Altius IT. In addition to our auditor certifications, we hold many security, technical, and project management credentials.  More information is available on our About Us page.

Our comprehensive audit service uncovers gaps in your existing defenses so that you can better:

  • Fortify your information systems, applications, and network infrastructure
  • Comply with regulatory requirements
  • Protect your valuable assets



Why Altius IT

IT audit, network security audit

Proven solutions that deliver value

Trusted
Trusted for over 25 years to provide faster and more accurate diagnosis of security issues. We understand that it’s not what we say, it’s what we find that matters. 

Clear Independence
Altius IT has no constricting ties and no conflicts of interest. We are dedicated and responsive to our clients, allowing Altius IT to make recommendations that are aligned with your risk tolerance.

Cost Effective Recommendations
Altius IT’s proprietary services provide a thorough 360 degree review of your risks. Our recommendations provide a clear description of risks found and as well as cost effective steps to secure your systems.

Experienced
We know your industry.  Altius IT has over 25 years of security audit experience in every type of industry from small public firms to large government agencies.

Peer Awards and Recognition
Altius IT’s experts are recognized by our peers as leaders in our field. Our staff has been elected by our peers into industry leadership roles and on the Board of Directors of international and national associations.

Best of Breed
Altius IT’s security audit services have been featured in over 40 industry publications. See our Media page.

Highest Caliber Audit Team
Altius IT answers to global certifying bodies so you can be assured that all audits and recommendations are made under the highest level of quality, reliability, and thoroughness.



Service Locations

Altius IT's services are provided throughout the United States and in selected international countries.
Our corporate HQ is located in Orange County California between Los Angeles and San Diego.
Contact us and we will help you choose the right audit.

☎ Call (714) 794-5210 ✉ Email Us