
What this article covers
Ransomware preparedness must address business interruption and possible data theft. Recovering files is only part of the response. The aim is to know what to protect first, how to limit spread and how to restore a service safely.
1. Identify the services that cannot stop
List critical processes and their dependencies: identity, networking, applications, databases and service providers. Agree with business owners how much downtime and data loss each process could tolerate. Those objectives guide recovery design and testing.
Choose one service for the first exercise. A short list with confirmed owners and dependencies is more useful than a large inventory nobody maintains.
2. Reduce entry paths and privileges
The #StopRansomware guide from CISA and its partners covers prevention and response to digital extortion, including credentials, vulnerabilities and recovery. Implementation should reflect the company’s actual exposure.
- Review published services and remote access; remove what is unnecessary.
- Prioritize fixes for exposed systems and exploited vulnerabilities.
- Use multifactor authentication and separate administrative accounts.
- Restrict movement between segments and test relevant alerts.
3. Prove that backups can be restored
Protect backup copies and credentials from modification by the same accounts that administer production. Assess isolated or immutable copies for your architecture. Check the configurations, keys and instructions required to restore the service as well.
Restore into a separate environment. Record duration, data integrity, missing dependencies and business validation. A successful backup job does not prove that the application will work again.
4. Rehearse the first decisions
Simulate an encryption alert and an outage. Confirm who can isolate machines, preserve evidence and engage specialists. Keep contacts and alternative communication channels accessible outside potentially affected systems.
During a real incident, avoid improvised actions that destroy evidence. The response team should coordinate containment, investigation and recovery; notification to customers, authorities or individuals depends on the facts and applicable obligations.
5. Close the gaps the exercise reveals
Turn findings into assigned tasks with deadlines and a repeat test. Document criteria for releasing the restored service, such as a clean environment, reviewed credentials and active monitoring. Backups do not prevent extortion through data exposure.
Use the incident response resource to begin discussing the plan and explore our security services for support.
