I have a feeling there is a very short security-hygiene checklist that, if followed, could prevent the vast majority of the ransomware attacked that we have seen in the last few years.<p>* Keep all systems up to date with the latest patches.<p>* Have a DR plan and test it regularly.<p>* Make frequent backups, verify them, and keep them <i>offline</i>.<p>Historically organizations have been so bad at backups that the advice has been to automate them as much as possible, to try to ensure that a recent backup at least exists. But I am increasingly of the opinion that the next level of backup maturity is to dial back on the automation and invest <i>manual</i> effort in airgapping the backups.<p>Fully automated backups are necessarily part of the software attack surface.<p>If you have to hire more ops people to rotate tapes by hand every day, that will have to be a cost of doing business safely.