CISA's #StopRansomware Guide, read for cloud infrastructure teams
CISA's #StopRansomware Guide asks for offline, encrypted backups tested in a recovery scenario, maintained golden images, infrastructure as code for cloud resources with template backups kept offline, and a rebuild ordered by the priority of critical services. For cloud teams, that means capturing configuration as well as data, and keeping the copies out of reach of production credentials.
Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk
The #StopRansomware Guide, published by CISA with its partner agencies, is one of the most cited public references on ransomware preparation. Its September 2023 version is the one we read. This briefing picks out the recommendations that apply to cloud infrastructure and says what each means in practice. It does not reproduce the guide; read it in full at the link below.
What does the guide say about backups?
It recommends maintaining offline, encrypted backups of critical data and testing their availability and integrity in a recovery scenario. For cloud estates, two points follow. First, offline means out of reach of the credentials an attacker would take from production: a separate account, separate keys, copies that cannot be deleted from the production side. Second, testing means restoring and running something, not only checking that a backup job completed.
What are golden images and why do they matter?
The guide recommends maintaining golden images of critical systems: preconfigured, regularly updated templates to rebuild from. In the cloud, the equivalent is broader than a machine image. It includes container images, the definitions of managed services and the network and identity settings they depend on. Our glossary defines the term.
What does it say about infrastructure as code?
For cloud resources, the guide recommends using infrastructure as code to deploy and update them, and keeping backups of the template files offline. This is the recommendation most directly about infrastructure recovery. It implies three tasks:
- Get the estate into code. Resources created by hand are not covered until they are codified.
- Keep the code and its history somewhere an attacker in production cannot change it.
- Keep the code current, so a rebuild matches what was running. That is a drift problem, covered in the lesson on configuration drift.
In what order should systems come back?
The guide recommends rebuilding systems by the priority of critical services. In cloud terms, identity and network come first, because nothing starts or connects without them, then configuration and data, and DNS last when traffic moves. Our briefing on rebuilding cloud infrastructure after ransomware sets out that order in detail.
How do the ranked tools map to the guide?
- Offline, protected copies of data: Veeam describes always-immutable, encrypted, air-gapped backups; Cohesity protects EC2, RDS and S3 with an isolated recovery environment in AWS.
- Infrastructure as code for cloud resources: Firefly, ControlMonkey and StackGuardian generate Terraform for resources not yet in code; HCP Terraform stores code and state history.
- Versioned, protected copies of configuration: Firefly describes versioned infrastructure-as-code snapshots and rollback to a point in time; ControlMonkey takes daily snapshots with a time-machine restore; Commvault Cloud Rewind captures point-in-time, in-sync copies.
- Rebuild into a clean target: Firefly and Arpio document cross-account recovery; Cohesity and Commvault Cloud Rewind describe isolated recovery environments.
These are the vendors' own statements; the recovery scope matrix shows which layers each one says it restores.
What evidence shows the recommendations are met?
- A list of critical services in rebuild order, each with an owner.
- The location and access controls of the offline copies of data and of the infrastructure-as-code templates.
- The date and result of the last restore test, covering configuration as well as data.
- A measure of how much of the estate is in code, and the date drift was last checked.
Kept together, these four items answer most of what an auditor or incident lead will ask after a ransomware event.
What should a cloud team do first?
Measure how much of the estate is in code, and where the copies of that code and of the configuration are stored. If both live only in the production account, the guide's offline recommendation is not met, and that is the first gap to close.
Sources
- CISA #StopRansomware Guide: https://www.cisa.gov/stopransomware/ransomware-guide
- Veeam, Backup for AWS: https://www.veeam.com/products/cloud/aws-backup.html
- Cohesity, AWS: https://www.cohesity.com/solutions/aws/
- Firefly, Cyber resilience: https://www.firefly.ai/use-cases/cyber-resilience
- ControlMonkey, Home: https://controlmonkey.io/
- StackGuardian, Home: https://www.stackguardian.io/
- Commvault, Cloud Rewind: https://www.commvault.com/cloud-rewind
- Arpio, Home: https://arpio.io/