Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
What Berlin's Refusal Teaches You About Ransomware DefenseBreach Response Services
5 min readFor Chief Information Security Officers (CISOs)

What Berlin's Refusal Teaches You About Ransomware Defense

When Berlin's state government announced it wouldn't pay extortionists after the August 2026 breach of its administrative network, it reinforced a principle many CISOs already know: your incident response plan can't assume you'll buy your way out. The Rhysida group claimed to have exfiltrated 5.79 terabytes of data between August 7 and August 12, yet Berlin's Senate Chancellery made its position clear without hesitation. That decision only works if you've built resilience into your architecture before the breach, not after.

This checklist translates Berlin's stance into actionable controls. Each item reflects what "no ransom" preparedness actually requires: defense-in-depth, containment architecture, and recovery capabilities that function independently of attacker cooperation.

Prerequisites

Before you start this checklist, confirm you have:

  • Authority to enforce technical requirements across departments. Network segmentation and MFA mandates fail when business units opt out.
  • Current network topology documentation. You can't segment what you can't map.
  • Executive commitment to a no-ransom policy. This checklist assumes your organization won't negotiate. If that's not settled, pause here and get board-level clarity.
  • Access to forensic and legal resources. Berlin worked with state criminal police, prosecutors, and federal security authorities. Know who you'll call before you need them.

Checklist Items

1. Multi-factor authentication (MFA) is mandatory on all external-facing remote services.

CISA's advisory on Rhysida documents valid account compromise as a primary access vector, particularly at organizations without MFA enabled by default. Your VPN, webmail, remote desktop, and cloud admin portals must enforce MFA with no exceptions for convenience.

What good looks like: Zero external services authenticate with username and password alone. Your authentication logs show MFA challenges on every remote access attempt. When you audit privileged accounts, you find hardware tokens or app-based authenticators, not SMS fallbacks.

2. Known exploited vulnerabilities from CISA's catalog are patched within your defined SLA.

Rhysida's use of Zerologon (CVE-2020-1472) demonstrates that old vulnerabilities remain viable. Microsoft patched that elevation-of-privilege flaw in August 2020; six years later, it's still in active exploitation chains.

What good looks like: You maintain a cross-referenced list of CISA KEV entries against your asset inventory. Your patch management system flags KEV matches automatically, and your SLA for these is shorter than your standard patch cycle. When you pull reports, zero KEV vulnerabilities appear in your production environment beyond the SLA window.

3. Network segmentation isolates critical departments and prevents lateral movement.

Berlin disconnected affected departments on August 14, seven days after the first detected outflow. That containment decision limited spread, but it also meant housing benefit applications went offline. Segmentation done in advance would have reduced both the blast radius and the operational disruption.

What good looks like: Your network architecture enforces segmentation at the VLAN and firewall rule level, not just logical subnets. Critical systems sit behind access control lists that whitelist specific source IPs and ports. When you test lateral movement scenarios, an attacker with domain admin credentials in one segment can't pivot to finance, HR, or operational technology without crossing a monitored boundary that triggers alerts.

4. Data exfiltration monitoring is active on all egress points.

Berlin's forensic work revealed outflows dated between August 7 and August 12. The department reported the first outflow on August 7, but the full scope emerged later. Your detection must catch abnormal data movement before terabytes leave.

What good looks like: You've baselined normal egress volumes by department, time of day, and destination. Your SIEM generates alerts when any endpoint exceeds baseline thresholds by a defined percentage. You can demonstrate in tabletop exercises that your SOC receives and investigates egress anomalies within your target detection window.

5. Offline, immutable backups exist for all critical systems and are tested quarterly.

If you won't pay ransom, you must restore from backup. Berlin's decision only holds if recovery doesn't depend on the attacker's decryption key.

What good looks like: Your backup architecture includes air-gapped or immutable storage that ransomware can't encrypt. You've documented recovery time objectives (RTOs) for each critical system. Your quarterly restore tests prove you can rebuild production environments from backup within your RTO, and your test logs show actual completion times, not estimates.

6. Incident response playbooks define roles, communication protocols, and decision trees for ransomware scenarios.

Berlin convened a special Senate session and coordinated with law enforcement, prosecutors, and federal security authorities. That response structure existed before the breach.

What good looks like: Your IR playbook names specific individuals (with backups) for technical lead, legal counsel, communications, and executive decision-maker roles. It includes contact information for breach coach, forensic vendors, law enforcement liaisons, and your insurer's First Notice of Loss process. When you run tabletop exercises, participants can locate and follow the playbook without prompting.

7. Breach notification requirements are mapped to your data inventory.

Berlin's Senate Chancellery said personal or other nonpublic data couldn't be excluded from what was taken. As of August 29, the government had published no guidance for affected individuals. You need faster clarity on notification obligations.

What good looks like: You maintain a data inventory that classifies information by regulatory regime (GDPR, state breach notification laws, sector-specific requirements). Your playbook includes notification templates and a decision matrix that maps data types to notification triggers and timelines. When you test this, your legal and compliance teams can determine notification scope within 24 hours of confirming data types involved.

Common Mistakes

Assuming MFA on some services is enough. Attackers find the unprotected entry point. Berlin's breach demonstrates that partial coverage leaves gaps. Your external attack surface needs uniform authentication standards.

Treating network segmentation as a one-time project. Segmentation degrades as you add cloud services, merge with acquired companies, and grant exceptions. Quarterly architecture reviews catch drift before it becomes a highway for ransomware.

Testing backups without testing restoration. Backup success logs don't prove you can recover. Berlin's departments went offline for days. Your RTO only matters if you've proven you can meet it under pressure.

Waiting for legal guidance during the incident. Berlin's coordination with prosecutors and data protection authorities worked because those relationships existed. Identify your breach coach and establish law enforcement contacts now, not when you're managing containment.

Next Steps

Within 30 days: Complete items 1, 2, and 6. MFA, KEV patching, and playbook documentation are table stakes. If you're breached tomorrow without these, your insurer will ask why they weren't in place.

Within 90 days: Implement network segmentation (item 3) and data exfiltration monitoring (item 4). These require architecture changes and tuning, but they're what separate containment from catastrophic spread.

Within 6 months: Validate your backup and restore capability (item 5) and complete your breach notification mapping (item 7). These prove you can execute a no-ransom strategy.

Berlin's refusal to pay wasn't a symbolic gesture. It was a calculated decision backed by containment, investigation, and recovery capabilities. Your organization needs the same foundation. This checklist gives you the specific controls that make "we don't negotiate" a credible position, not a hope.

GDPR

Application Security Isn’t Optional Anymore.

You Might Also Like