Modelling and simulating organizational ransomware recovery: structure, methodology, and decisions
Marius-Constantin Ilau, Adrian Baldwin, Tristan Caulfield, David J. Pym · Journal of Cybersecurity · 2025
Abstract The problem of maintaining organizational resilience in the face of ransomware attacks represents an important issue for modern organizations. Organizational networks and IT infrastructure have become increasingly complex, and it is often unclear how decisions about technology, policy, and recovery strategy will impact resilience. In this context, the paper focuses on two primary objectives. First, to offer security decision-makers a way of better understanding the impact of deploying different recovery solutions at organizational level by means of simulation modelling and comparative analysis of solutions. Second, to illustrate the suitability and benefits of using semantically justified, compositional system models together with a rigorously defined codesign model-construction methodology, in a complex scenario. Our choice of organizational recovery as modelling target is motivated through both form and complexity, allowing for illustrating the model conceptualization and construction methodology in a sufficiently rich context. We conceptualize the ransomware behaviour, organizational structure, IT infrastructure, and recovery choices and behaviour based on literature surveys and expert knowledge. Then, construct a modular, simulation model representing a generic target organization using our codesign approach. We execute the model over 9000 different parameter configurations, totalling an amount of 450 000 iterations. We analyse the results, both in three specific scenarios deemed organizationally relevant and at the general level—through sensitivity analysis—and, exemplify possible ways in which the model can help inform decision-makers about their possible recovery choices.