CISA's #StopRansomware Guide, read for cloud infrastructure teams

Short answer

CISA's #StopRansomware Guide asks for offline, encrypted backups tested in a recovery scenario, maintained golden images, infrastructure as code for cloud resources with template backups kept offline, and a rebuild ordered by the priority of critical services. For cloud teams, that means capturing configuration as well as data, and keeping the copies out of reach of production credentials.

Ranking current as of September 2026 · By the Cloud Resilience Vendors research desk

By the Cloud Resilience Vendors research desk · · 4 min read

The #StopRansomware Guide, published by CISA with its partner agencies, is one of the most cited public references on ransomware preparation. Its September 2023 version is the one we read. This briefing picks out the recommendations that apply to cloud infrastructure and says what each means in practice. It does not reproduce the guide; read it in full at the link below.

What does the guide say about backups?

It recommends maintaining offline, encrypted backups of critical data and testing their availability and integrity in a recovery scenario. For cloud estates, two points follow. First, offline means out of reach of the credentials an attacker would take from production: a separate account, separate keys, copies that cannot be deleted from the production side. Second, testing means restoring and running something, not only checking that a backup job completed.

What are golden images and why do they matter?

The guide recommends maintaining golden images of critical systems: preconfigured, regularly updated templates to rebuild from. In the cloud, the equivalent is broader than a machine image. It includes container images, the definitions of managed services and the network and identity settings they depend on. Our glossary defines the term.

What does it say about infrastructure as code?

For cloud resources, the guide recommends using infrastructure as code to deploy and update them, and keeping backups of the template files offline. This is the recommendation most directly about infrastructure recovery. It implies three tasks:

  1. Get the estate into code. Resources created by hand are not covered until they are codified.
  2. Keep the code and its history somewhere an attacker in production cannot change it.
  3. Keep the code current, so a rebuild matches what was running. That is a drift problem, covered in the lesson on configuration drift.

In what order should systems come back?

The guide recommends rebuilding systems by the priority of critical services. In cloud terms, identity and network come first, because nothing starts or connects without them, then configuration and data, and DNS last when traffic moves. Our briefing on rebuilding cloud infrastructure after ransomware sets out that order in detail.

How do the ranked tools map to the guide?

These are the vendors' own statements; the recovery scope matrix shows which layers each one says it restores.

What evidence shows the recommendations are met?

Kept together, these four items answer most of what an auditor or incident lead will ask after a ransomware event.

What should a cloud team do first?

Measure how much of the estate is in code, and where the copies of that code and of the configuration are stored. If both live only in the production account, the guide's offline recommendation is not met, and that is the first gap to close.

Sources