Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIST ransomware profile mapping CSF 2.0 functions govern, identify, protect, detect, respond and recover to ransomware

NIST Ransomware Profile: The Essential 2026 Guide to NIST IR 8374 Rev. 1

The NIST ransomware profile is a Cybersecurity Framework 2.0 Community Profile that shows which CSF outcomes matter most for governing, identifying, protecting against, detecting, responding to and recovering from ransomware. Published by NIST as IR 8374 Revision 1, it replaces the original 2022 profile that was built on CSF 1.1, and it gives security and risk teams a ready-made way to check their ransomware readiness against a recognized framework instead of inventing their own checklist.

This guide explains what the profile is, how it is organized around the six CSF 2.0 functions, how to run a readiness assessment with it, what practical controls matter most, and how to present the results. It is general information, not legal advice, and you should read the NIST document itself before you rely on the details.

What the NIST ransomware profile is

NIST describes the document as Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile, published on 11 June 2026, with the authors Murugiah Souppaya, William Barker, William Fisher and Karen Kent. It supersedes NIST IR 8374 from February 2022. According to its abstract, it identifies the CSF 2.0 security outcomes that support governing, identifying, protecting against, detecting, responding to and recovering from ransomware events, and it serves as a guide to assessing readiness and developing countermeasure strategies. You can find it on the NIST Computer Security Resource Center.

NIST defines ransomware as an attack in which attackers encrypt an organization’s data and demand payment to restore access, and notes that attackers may also steal information and demand a further payment not to disclose it. That double pressure is why the profile covers more than backups: it treats ransomware as a governance, detection and legal problem as well as a technical one.

What a community profile is

A profile in the CSF is a selection of outcomes from the framework, prioritized for a purpose. A community profile does that for a group with a shared interest, here anyone facing ransomware. You can use it directly, or fold its priorities into your own organizational profile. Our guide to the CSF organizational profile explains how current and target profiles work, and the overview of NIST CSF 2.0 covers the framework itself.

How the NIST ransomware profile uses the six CSF functions

CSF 2.0 functionRansomware question it answers
GovernWho owns ransomware risk, and what are the policies, roles and risk appetite?
IdentifyWhich assets, data and suppliers would hurt most if encrypted or stolen?
ProtectWhat stops an attacker from getting in, spreading and destroying backups?
DetectHow quickly would we notice early signs, such as unusual encryption or credential abuse?
RespondWhat do we do in the first hours, and who decides on containment and communications?
RecoverCan we restore critical services, and can we prove the restored data is clean?

The Govern function is new in CSF 2.0, and it is where many organizations discover their weakest ransomware preparation. Our guide to the CSF Govern function explains it.

Running a readiness assessment with the NIST ransomware profile

  1. Set scope. Choose the business services you would most want to keep running, and the systems that support them.
  2. Take the profile outcomes. List the outcomes the profile highlights for each function.
  3. Score current state. For each outcome, record whether it is in place, partly in place or missing, and what evidence supports that. Use a simple scale, and require evidence for any “in place” rating.
  4. Set the target. Decide what level is right for your organization given its risk appetite and resources. Our note on CSF tiers can help you set expectations for rigor.
  5. Find and rank gaps. Prioritize by impact on critical services and by effort.
  6. Plan actions. Assign owners, dates and measures of success.
  7. Repeat. Reassess at least yearly and after incidents or major changes.

Controls that matter most in the NIST ransomware profile

The profile is outcome-based, so it does not prescribe products. The practices below are widely recognized as central to ransomware resilience, and they line up with the outcomes the profile draws from CSF 2.0.

  • Backups that survive an attack. Keep copies that an attacker with administrator credentials cannot alter or delete, such as offline or immutable copies, and protect the backup systems’ own credentials.
  • Restore testing. A backup that has never been restored is a hope. Test full restores of critical services and record how long they take.
  • Strong access control. Multi-factor authentication, least privilege and tight control of administrator accounts limit how far an intruder can travel.
  • Patching and exposure management. Reduce internet-facing weaknesses, especially in remote access and edge devices.
  • Segmentation. Limit lateral movement so that one compromised system does not become an enterprise-wide outage.
  • Detection and response. Monitor for early signs and rehearse a response plan with legal, communications, operations and executive roles clear.
  • Supplier awareness. Know which suppliers could be a route in, or whose failure would stop your operations.

Decisions that need leadership, not just IT

Several ransomware decisions cannot be made by the security team alone. Set them in advance: who can authorize shutting down systems, when to involve law enforcement and insurers, what to tell customers and regulators and when, and how the organization will approach the question of paying a ransom. Payment can raise legal issues, including sanctions rules, and it does not guarantee that data is recovered or not published, so obtain legal advice before an incident and record the decision process. The Govern outcomes in the profile point to this: policies, roles and risk appetite should be settled before the pressure arrives.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

A worked example

The following is a hypothetical illustration. A regional logistics company runs a readiness assessment using the profile. Its critical service is order dispatch, which depends on a warehouse system, a routing platform and a shared file server. In the Govern area, there is no written ransomware policy and no agreed owner, so the team rates that as missing. In Protect, backups exist but share credentials with the domain administrators, so they are rated partly in place. In Recover, nobody has tested a full restore of the warehouse system. The company’s top three actions are to assign an executive owner and write a short decision playbook, to move backup credentials out of the domain and add an immutable copy, and to run a timed restore test within 90 days. The test takes 31 hours against a stated business need of 8, which becomes the next project, with a clear number to improve.

Common mistakes when using the NIST ransomware profile

  • Treating it as a backup project. Backups matter, but ransomware also involves data theft, extortion and governance.
  • No restore evidence. Reporting green on backups without ever running a restore.
  • Response plans that nobody has rehearsed. A document in a drawer fails on the first day.
  • Unclear decision rights. Arguing over who can shut down a system while it spreads.
  • Ignoring suppliers. Third-party access is a common entry point and a common source of outages.
  • One-time assessment. A single review that is never repeated as systems and threats change.

Presenting results to leadership

Give executives a one-page view: the critical services in scope, current versus target rating for each function, the top gaps in plain language, the cost and timeline of the plan, and the decisions needed from them. Add one or two numbers that mean something, and keep the narrative short, such as measured restore time compared with the recovery time the business needs. Link the results to your existing framework work, such as the move from CSF 1.1 to 2.0, so that the ransomware assessment supports the broader program instead of creating a separate one.

Documenting your NIST ransomware profile program

A defensible program has a ransomware policy, a risk assessment, a backup and recovery standard, an incident response plan and playbook, a communications plan, a supplier requirement, and assessment records. The NIST CSF Toolkit provides templates for CSF 2.0 policies, profiles and assessments that you can adapt to your organization. Keep the documents short, assign owners and test them, and store a copy of the incident plan and contact list somewhere that is still reachable if your main systems are encrypted.

NIST ransomware profile FAQ

Is the NIST ransomware profile mandatory?

No. It is voluntary guidance that helps organizations assess and improve their ransomware readiness using the CSF 2.0 outcomes. Some regulators and insurers may ask about similar practices.

What replaced the earlier ransomware profile?

NIST IR 8374 Revision 1, published in June 2026, supersedes the February 2022 version and is based on CSF 2.0.

Do we need to adopt CSF 2.0 to use it?

You can use the profile on its own, but it is written in terms of CSF 2.0 outcomes, so familiarity with the framework helps.

Does the profile tell us to pay or not to pay a ransom?

It focuses on preparation, and payment involves legal and operational considerations. Settle your decision process with counsel and leadership beforehand.

How often should we reassess?

At least annually, and after any major change, incident or test that shows a gap, such as a failed restore.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.