Updated: May 31, 2023 (February 11, 2023)

  Sidebar

What Microsoft Didn’t Disclose About Ransomware Playbooks

Michael Cherry by
Michael Cherry

Michael analyzed and wrote about Microsoft's operating systems, including the Windows client OS, as well as compliance and governance. Michael... more

Because most organizations are working with police and other authorities to investigate attacks such as ransomware attacks, organizations such as Microsoft are not always able to provide details on specific incidents. However, providing more guidance on the following matters would help organizations build their playbooks:

  • What did Microsoft spend on creating its playbook, including salaries, software licensing, and other costs such as costs of compliance?
  • How many employees does Microsoft Digital Security and Resilience (DSR) assign to maintaining the playbook, and are they assigned full-time to maintaining and testing the playbook?
  • How often does Microsoft review the playbook and conduct tests, including table-top tests?
  • What is the level of expertise or experience of the staff assigned to maintaining and testing the playbook?
  • How much does the playbook depend on Microsoft’s security products and services, which are free to the company but could be a significant cost to customers?

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now