← BUSINESS CONTINUITY GUIDE
BUSINESS CONTINUITY GUIDE

Ransomware recovery: decisions to make before the bad day

Ransomware recovery has a strange property: almost every decision that matters gets made before the attack. During the incident you're sleep-deprived, your files are encrypted, and someone is charging you by the hour to help. Decisions made in that state are expensive. So make them now, while it's hypothetical. Prevention is covered in the five defense layers; this guide is about the day the layers lose.

Decision one: backups the attacker can't reach

Modern ransomware crews get admin access first, find your backups, and delete or encrypt them before triggering anything. A backup on a connected NAS or a logged-in cloud console is reachable, which means it's part of the blast radius. The pre-decision: at least one backup copy that's immutable (the storage refuses deletion for a set window; most business backup platforms sell this as an option) or genuinely offline. This single choice is the difference between a bad week and an existential bill. If you change nothing else after reading this, change this.

Decision two: who you call, in order

Tape this list inside the plan: your cyber insurer's incident hotline first, because most policies require using their approved responders and calling your own IT crew first can jeopardize coverage. Then your IT provider, then legal counsel if client data may be involved. Know your policy's notification deadline before you need it. No cyber policy? That's its own pre-decision to revisit, and your contact tree should reflect whichever answer you choose.

Decision three: the pay-or-rebuild stance

Nobody can fully pre-make this one, but you can pre-decide the framework. Facts worth knowing calmly: paying is legally murky (payments to sanctioned entities carry OFAC liability, one of many reasons counsel is on the call list), decryptors delivered after payment are slow and partial more often than the negotiation implies, and paying marks you as a payer. Recovery from clean backups is almost always the better path when the backups survived, which is why decision one is decision one. The honest framework: with immutable backups, your stance is "we rebuild," and you can say it out loud in the tabletop drill. Without them, your stance is being chosen for you.

Decision four: the restore order

Recovery isn't restore-everything-at-once; it's a queue under pressure, and machines restored onto a still-compromised network get re-encrypted. The pre-written order: contain first (isolate, per the first 24 hours), verify the environment is clean, then restore by the priority list in your continuity plan: coordination tools, then the money systems, then the rest. Rebuilding identity, meaning the domain controller or your Microsoft 365 admin structure, comes before the file shares everyone will be shouting about, because everything else authenticates against it.

What this costs to set up

Immutable backup storage: often $50 to $200 a month over what you pay now. An incident-response contact sheet: free. A tabletop run of this exact scenario: one hour. Cyber insurance: a few thousand a year for meaningful small-business coverage. The version of you living through the encrypted Tuesday would sign for all of it without reading the invoice.

Want this handled instead of homeworked? That's the job.

Email us →
RELATED READING
A backup strategy for everything, not just the server Business Continuity →
Test the plan: tabletop drills and restore days Business Continuity →
Backup is a copy. Disaster recovery is a plan. Business Continuity →
The whole Business Continuity guide Pillar →

From the blog

ALL POSTS →
NO FORMS. JUST EMAIL.
mason@hurbs.io
or (832) 457-4317, LA and Houston