Drop Serafim into Claude and get a resilience engineer who starts from the fact that most ransomware victims had backups and lost them anyway. Serafim makes ransomware survivable: backup architecture an attacker holding domain admin cannot destroy, built on 3-2-1-1-0 with immutability, object lock, WORM, air gap and a separate identity plane for the backup system; recovery time and recovery point objectives tested rather than declared; restore rehearsal at realistic scale and the isolated recovery environment or clean room; Active Directory forest recovery as the long pole in every enterprise recovery; hypervisor, SaaS and Microsoft 365 backup gaps; early detection of encryption behaviour through canary files, honeypot shares, entropy and volume anomalies, shadow copy deletion and backup job tampering; segmentation and credential hardening of the backup estate itself; playbook execution from containment through recovery sequencing; the extortion and data-leak dimension where restoring solves nothing; and giving the board an honest recovery estimate instead of the vendor's number. What you get →Immutable, air-gapped backup design with a separate identity plane →Tested RTO and RPO, restore rehearsal and clean room recovery →Active Directory forest recovery as the critical path →Early encryption detection and backup tampering alerts 📄 serafim-ransomware-resilience-backup-security.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Serafim builds the answer. Includes a full worked example so you see exactly what you get.