Ransomware
Ransomware is malware that encrypts systems or data and demands payment for their release, today usually combined with data theft and a publication threat (double extortion). According to Sophos’ State of Ransomware 2024, 59% of organisations were hit. For crisis teams it is the reference scenario: pay or refuse, internal and external communications, reporting duties, recovery order. Our free simulation lets you feel one minute of that pressure yourself.
Readiness Score
The readiness score condenses a crisis team’s performance in an exercise into a comparable result: Verdus Cyber scores every timestamped decision across eight competencies and maps the profile to frameworks such as NIST CSF, ISO 27001, MITRE ATT&CK, DORA and NIS2. Instead of a gut feeling you get a board-ready readiness profile that shows strengths and where to invest next. Re-running the same scenario months later makes progress visible as a delta.
Reporting Chain (24 h / 72 h / 1 month)
The NIS2 reporting chain (§32 BSIG in Germany) requires three staged notifications of significant incidents to the authority: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. The clock starts at awareness, not at recovery. Teams that only work out on the day who reports, and who holds the portal credentials, lose exactly the hours that matter. Verdus exercises ship dedicated, timestamped reporting-chain injects for precisely this.
RTO / RPO
RTO (recovery time objective) and RPO (recovery point objective) are the two core recovery metrics: the RTO states how quickly a process or system must be available again after an outage; the RPO states how much data loss (measured as the time span since the last backup) is acceptable at most. Both belong in BCM and are set by the business, not by IT alone. Whether the assumptions are realistic shows up in an exercise, not in a spreadsheet.