Cybersecurity

Ransomware Recovery: What Your Backup Plan Must Prove

August 28, 20268 min read
RansomwareBackup and RecoveryIncident Response

A backup job showing success is not the same as a recovery plan. Ransomware can disrupt devices, accounts, servers, cloud data, applications, and the tools used to manage backups. A business needs evidence that protected copies exist, that attackers cannot easily destroy them, and that clean operations can be restored in the order the business needs.

Begin with the operations that must return first

List the business services that cannot remain unavailable for long: communication, scheduling, customer records, billing, payroll, production, document access, remote work, or industry-specific applications. Put them in recovery order and identify the data, identities, devices, networks, and vendors each one requires.

Set practical recovery objectives for each critical service. How much recent data could the business recreate, and how long can the service remain unavailable before the impact becomes unacceptable? These decisions guide backup frequency, retention, architecture, and testing.

Do not assume the most technically complex system should recover first. The right sequence follows business dependencies. Restoring an application is not useful if identity, networking, data, or a required vendor connection is still unavailable.

Know exactly what is protected

Create a backup inventory that names every protected system, data source, schedule, retention period, storage location, encryption method, owner, and last successful restore test. Include cloud platforms and software-as-a-service data where the provider's native retention does not meet the business need.

Check for overlooked configuration and identity data. Firewall rules, application settings, encryption keys, administrative records, automation workflows, and cloud configurations may be necessary to rebuild operations even when the main files are intact.

Identify gaps between what the dashboard reports and what the business expects. A job can succeed while excluding a new folder, inactive mailbox, recently added server, or application database that was never placed in scope.

Separate recovery copies from the environment they protect

CISA recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity. The practical goal is to prevent one compromised account, management tool, or network path from deleting both production data and every recovery copy.

Use separate backup administration, strong authentication, limited privileges, protected deletion settings, and copies that are offline or otherwise isolated according to the technology in use. Document any delay or approval required to alter protected copies.

Review how backup alerts are delivered. If alerts only go to the same email environment affected by an incident, responders may lose visibility when they need it most.

Test restoration, not just backup completion

A meaningful restore test starts with a recovery objective and ends with business validation. Restore selected files and a representative critical system into a safe environment. Confirm that the data opens, the application functions, permissions are correct, and users can complete the intended work.

Measure how long each step takes, including locating credentials, contacting vendors, provisioning clean infrastructure, transferring data, checking security, and receiving business approval. The restore itself may be only one part of the elapsed recovery time.

Record the test date, scope, result, problems, corrective actions, and next test. If a backup has never been restored, treat its recoverability as unproven.

Plan for a clean recovery environment

Restoring data into an environment that still contains attacker access can restart the incident. Recovery planning must connect to incident response so the business can identify affected accounts and systems, contain access, preserve needed evidence, and establish a trusted place to restore.

Define who decides that an environment is ready, how administrator credentials will be reset, how clean devices are obtained, which security tools must be active, and what validation happens before normal connections resume.

CISA's ransomware guidance warns organizations to carefully scope affected systems and avoid reinfection during restoration. The exact process depends on the incident, which is why backup operations and incident leadership must be planned together.

Prepare communications and outside dependencies

Keep current contact and escalation information for backup providers, cloud platforms, application vendors, managed IT, incident response, cyber insurance, legal counsel, and business leaders. Store a protected copy where it remains available if primary systems are down.

Document who can authorize emergency purchases, system shutdowns, credential resets, customer communications, and restoration priorities. A technically recoverable system can still remain offline while the business waits for a decision nobody knew they owned.

Review vendor recovery commitments and your own responsibilities. A provider may restore its platform while the business remains responsible for data, configuration, endpoints, user access, or integration failures.

Build a repeatable recovery test schedule

Test frequency should reflect how critical the system is and how quickly it changes. Use smaller file and configuration restores regularly, then schedule broader application or environment exercises that prove dependencies and decision-making.

Repeat tests after major migrations, application changes, backup redesigns, vendor changes, and shifts in business operations. Update runbooks when the evidence shows a step, contact, credential, or recovery estimate is wrong.

The goal is not a perfect document. It is a recovery capability the business has practiced, measured, and improved before a real incident forces the test.

Sources and further reading

Ready to put this to work?

F09 Tech helps Savannah and Coastal Georgia businesses turn ideas like these into a working plan. Start with a free Business Technology & AI Assessment.

Start Your Assessment