Tool Gate · How it works
How the Ransomware & AI-Outage Recovery Readiness Drill gate works
How the Ransomware & AI-Outage Recovery Readiness Drill grades a system: six weighted controls and an untested-recovery gate where a restore or AI fallback scored 0 forces WOULD NOT RECOVER — which is how a 78 still fails. Knowing a backup exists isn't knowing it recovers.
How the gate works
This tool grades one critical system's ransomware- and AI-outage recovery posture. Each control is marked from your own evidence and weighted into a 0–100 score — and then the score is run past a gate that can only make the verdict worse.
The 6 weighted controls
| Control | Weight |
|---|---|
| Tested restore (timed end-to-end) | 22 |
| Immutable, isolated, offline backups | 18 |
| Fallback for load-bearing AI dependencies | 20 |
| RTO defined & validated per system | 14 |
| Incident runbook (who-does-what) | 14 |
| Comms & notification plan | 12 |
| Total | 100 |
The verdict bands
A tested restore or an AI fallback scored 0 forces WOULD NOT RECOVER regardless of the score. Knowing a backup exists is not knowing it recovers in time.
In the worked sample it scores 78 out of 100 and still reads WOULD NOT RECOVER — Every backup control is in place, but the restore has never been run end-to-end — scored 0 — so the system reads WOULD NOT RECOVER despite a 78. The one thing to fix first: Run a full timed restore of this system end-to-end, then re-score. A backup you have never restored is a guess, not a recovery..
Common questions
Can something score well on the Ransomware & AI-Outage Recovery Readiness Drill and still fail?
Yes. The weighted score is run past a worsen-only gate — the Untested-recovery gate — that can only make the verdict worse. In the worked sample it scores 78 out of 100 and still reads WOULD NOT RECOVER, because every backup control is in place, but the restore has never been run end-to-end — scored 0 — so the system reads WOULD NOT RECOVER despite a 78.
What is a worsen-only gate?
A dispositive rule that can only lower a verdict, never raise it. One fatal flaw overrides an otherwise-good score, because a single disqualifying gap shouldn't hide behind a high average. The tool also names the one thing to fix first — here, "Run a full timed restore of this system end-to-end, then re-score. A backup you have never restored is a guess, not a recovery.".
Scores the recovery posture you describe, not people. The workbook and engine produce the identical verdict.
Embed this diagram
Free to share and embed with attribution (CC BY 4.0) — keep the link to redhub.ai.
Interactive — renders the live diagram
<iframe src="https://redhub.ai/visuals/tool/ransomware-ai-outage-recovery-readiness-drill.html" title="How the Ransomware & AI-Outage Recovery Readiness Drill gate works — RedHub AI" width="760" height="1590" loading="lazy" style="border:0;width:100%;max-width:760px"></iframe>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai/visuals/tool/ransomware-ai-outage-recovery-readiness-drill">How the Ransomware & AI-Outage Recovery Readiness Drill gate works</a> — by <a href="https://redhub.ai">RedHub AI</a>, the AI that tells you when to doubt it.</p>Image + link — a static picture for any blog
<a href="https://redhub.ai/visuals/tool/ransomware-ai-outage-recovery-readiness-drill"><img src="https://redhub.ai/visuals/tool/ransomware-ai-outage-recovery-readiness-drill-share.png" alt="Diagram of the Ransomware & AI-Outage Recovery Readiness Drill: six weighted controls, an untested-recovery gate, and a sample scoring 78 that still reads WOULD NOT RECOVER." width="760" loading="lazy" style="max-width:100%;height:auto;border-radius:16px"></a>
<p style="font:14px/1.5 system-ui,sans-serif"><a href="https://redhub.ai">RedHub AI</a> — the AI that tells you when to doubt it.</p>This is how Ransomware & AI-Outage Recovery Readiness Drill works. More diagrams in the Visual Field Guide.