Ransomware recovery has a strange property: almost every decision that matters gets made before the attack. During the incident you're sleep-deprived, your files are encrypted, and someone is charging you by the hour to help. Decisions made in that state are expensive. So make them now, while it's hypothetical. Prevention is covered in the five defense layers; this guide is about the day the layers lose.
Decision one: backups the attacker can't reach
Modern ransomware crews get admin access first, find your backups, and delete or encrypt them before triggering anything. A backup on a connected NAS or a logged-in cloud console is reachable, which means it's part of the blast radius. The pre-decision: at least one backup copy that's immutable (the storage refuses deletion for a set window; most business backup platforms sell this as an option) or genuinely offline. This single choice is the difference between a bad week and an existential bill. If you change nothing else after reading this, change this.
Decision two: who you call, in order
Tape this list inside the plan: your cyber insurer's incident hotline first, because most policies require using their approved responders and calling your own IT crew first can jeopardize coverage. Then your IT provider, then legal counsel if client data may be involved. Know your policy's notification deadline before you need it. No cyber policy? That's its own pre-decision to revisit, and your contact tree should reflect whichever answer you choose.
Decision three: the pay-or-rebuild stance
Nobody can fully pre-make this one, but you can pre-decide the framework. Facts worth knowing calmly: paying is legally murky (payments to sanctioned entities carry OFAC liability, one of many reasons counsel is on the call list), decryptors delivered after payment are slow and partial more often than the negotiation implies, and paying marks you as a payer. Recovery from clean backups is almost always the better path when the backups survived, which is why decision one is decision one. The honest framework: with immutable backups, your stance is "we rebuild," and you can say it out loud in the tabletop drill. Without them, your stance is being chosen for you.
Decision four: the restore order
Recovery isn't restore-everything-at-once; it's a queue under pressure, and machines restored onto a still-compromised network get re-encrypted. The pre-written order: contain first (isolate, per the first 24 hours), verify the environment is clean, then restore by the priority list in your continuity plan: coordination tools, then the money systems, then the rest. Rebuilding identity, meaning the domain controller or your Microsoft 365 admin structure, comes before the file shares everyone will be shouting about, because everything else authenticates against it.
What this costs to set up
Immutable backup storage: often $50 to $200 a month over what you pay now. An incident-response contact sheet: free. A tabletop run of this exact scenario: one hour. Cyber insurance: a few thousand a year for meaningful small-business coverage. The version of you living through the encrypted Tuesday would sign for all of it without reading the invoice.
Want this handled instead of homeworked? That's the job.
Email us →