← tay.bio

Ransomware Readiness Audit

Twenty minutes on a call. I ask the questions a real incident asks. You find out which ones your organization can't answer yet.

>who declares an incident, and who declares it when they're on a plane >how long you can operate with your systems encrypted >who talks to the attacker, and who is allowed to decide about paying >when legal gets involved, and whether that slows you down or speeds you up >who tells customers, and how long you have before someone else does

I've negotiated with ransomware crews for Fortune 500 companies and one-person IT teams, and sat with boards while an incident was still running. These are the questions that decided how those went.

Most organizations answer the first two comfortably and then slow down. That's the useful part. The questions you stall on are the ones that will cost you hours during the real thing, and hours are the whole game.

You leave with it in writing. What you answered, what you didn't, and the three things I'd fix first.

That document is yours. Send it to your CFO, your board, your insurer, or the person who keeps asking whether you're covered. It's often easier to get budget approved off two pages of your own gaps than off a vendor deck.

Ask me for a time →

Taylor is one of those rare folks that can see the big picture challenges in security, then relate that down to tactical, precise advice.

Eric Ahlm, Security Research Director, Gartner

Who this is for

You carry security risk, and it isn't your only job.

Whether that's you

Most of the people I do this with are directors, VPs, CIOs, or ops leaders in organizations that will never hire a CISO. You inherited security alongside everything else, you're accountable for it, and you have less budget authority than the accountability implies. Sitting CISOs get value from it too, usually as ammunition rather than education.

It works best if you have more than one person who'd be in the room during an incident. If security is genuinely one person and a spreadsheet, we'll find that out in the first five minutes and I'll tell you what to do about it, but you don't need me for that.

If you want a tool evaluation, a compliance gap assessment, or a penetration test, I'm happy to point you somewhere good. This isn't that.

What this is and isn't

no scan
no tooling, no agents, no credentials, nothing touching your network. It's a conversation.
free
actually free, and it stays free if you never hire me
20 min
you and me, no deck, no discovery form to fill in first
private
nothing recorded, nothing shared, nothing entered in a CRM
after
I send the summary, then you don't hear from me unless you write back
honest
if you're in better shape than you think, I'll say so and we're done

At the end I'll tell you whether a tabletop exercise would be worth your money. Sometimes the answer is no, or not yet. I'd rather say that than sell you one.

Book it

Message me with a rough sense of your organization and I'll send you two or three times.

Book it on Signal →

Fastest. I read everything and I reply.

email audit at taylorbanks dot com

If your organization needs a paper trail.

Signal QR code for taylorbanks.42

Why I do these

The honest version

Some of these turn into tabletop exercises, which is how I make a living. Most of them don't, and that's fine. I've negotiated with ransomware crews for Fortune 500 companies and one-person IT teams, and sat with boards while an incident was still running. The pattern is always the same: the technical work is the straightforward half, and the expensive delays come from nobody knowing who's allowed to decide.

Twenty minutes is usually enough to find out whether that's true where you work.

I'm also a volunteer firefighter and EMT, which is where I learned that the difference between a bad night and a catastrophe is almost never equipment.