Without segmentation, ransomware can move from one infected system into broader parts of the environment and disrupt more business functions. Without usable backups, recovery becomes slower, more expensive, and in some cases impossible. The result is prolonged downtime, data loss, operational disruption, and greater pressure to consider ransom payment.
Why This Matters for Security Teams
Ransomware is not just an endpoint problem once it crosses a flat network. When segmentation is weak or absent, the blast radius expands quickly because shared credentials, open administrative paths, and overconnected services let attackers reach file shares, virtual infrastructure, backup systems, and identity services. Recovery-ready backups matter just as much: a backup that cannot be restored cleanly, quickly, and safely is not a recovery control, it is a false sense of resilience. The control objective is reflected in the NIST Cybersecurity Framework 2.0, where resilience depends on protecting critical assets and restoring services after disruptive events.
Security teams often underestimate how quickly ransomware turns into a business continuity event. A single compromised workstation can become domain-wide impact if tiering, segmentation, and privilege boundaries are weak. In practice, many security teams encounter the real failure only after encryption has spread into backup repositories and recovery testing has already failed.
How It Works in Practice
Segmentation limits where ransomware can go after initial compromise. In a well-designed environment, user networks, server zones, backup infrastructure, identity services, and management planes are separated so that compromise in one zone does not automatically grant access to the next. This is where principles from NIST SP 800-207 Zero Trust Architecture become operational: trust is not implied by network location, and access decisions are continuously constrained by identity, device posture, and policy.
Recovery-ready backups are equally specific. They need to be isolated from routine administrative access, versioned to survive corruption or encryption, and tested often enough that restoration time is understood before an incident. Backup copies should cover both data and the supporting configurations needed to bring services back online. If backups depend on the same credentials, management network, or storage fabric as production, ransomware can encrypt or delete them too.
- Separate user, server, backup, and management segments so lateral movement is harder.
- Limit administrative reach and enforce privileged access boundaries for backup platforms.
- Store offline or logically isolated backup copies that attackers cannot easily tamper with.
- Test restore procedures for critical systems, not just backup completion jobs.
- Protect identity infrastructure, because stolen credentials often turn local compromise into enterprise compromise.
The operational goal is not perfect containment, which is unrealistic, but controlled failure: if one zone is hit, the rest of the environment still functions and restoration can begin from a trusted copy. The guidance aligns with NIST SP 800-53 Rev 5 Security and Privacy Controls around access control, system integrity, contingency planning, and backup protection. These controls tend to break down in flat networks with shared administrator credentials and backup systems that are administered from the same domain the attacker already controls.
Common Variations and Edge Cases
Tighter segmentation often increases operational overhead, requiring organisations to balance resilience against application complexity and support burden. That tradeoff matters because some environments, such as legacy OT, small branch offices, and highly integrated ERP estates, cannot be segmented cleanly without application redesign or vendor cooperation. Current guidance suggests treating those environments as exceptions to be risk-managed, not as reasons to abandon segmentation entirely.
Backup design has its own edge cases. Immutable snapshots, air-gapped copies, and cloud backups can improve recovery, but only if access to them is genuinely separate from the compromised environment. If ransomware reaches the identity provider or backup orchestration layer, even robust storage controls may not be enough. In regulated sectors, recovery expectations are also shaped by incident reporting and operational resilience obligations, so a technically recoverable system may still be unacceptable if restoration exceeds business or regulatory tolerances.
Threat intelligence can help prioritise what to protect first. The ENISA Threat Landscape shows why ransomware remains a disruption-focused threat rather than a simple malware event, but the main lesson is practical: segmentation reduces spread, and recovery-ready backups reduce leverage. Where both are weak, response options narrow rapidly and negotiation becomes more likely than restoration.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST AI RMF and NIST SP 800-53 Rev 5 set the technical controls, while NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.RP-1 | Recovery planning is central when backups and restoration readiness are questioned. |
| NIST Zero Trust (SP 800-207) | SC-7 | Network segmentation and trust boundaries reduce ransomware lateral movement. |
| NIST AI RMF | The governance function supports resilient control ownership for automated environments. | |
| NIST SP 800-53 Rev 5 | CP-9 | Backup protection and restoration testing directly address ransomware recovery readiness. |
| NIS2 | Resilience and incident handling obligations are relevant where ransomware disrupts services. |
Tie segmentation and recovery testing to business continuity and incident response obligations.
Related resources from NHI Mgmt Group
- What breaks when network segmentation is based on old branch-office assumptions?
- What breaks when a data governance platform reaches end of life before replacement is ready?
- What breaks when OT segmentation depends on static network rules?
- Why does restoring from backups not fully solve ransomware recovery?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org