Recovery is an operating requirement
A backup plan is not complete because a provider sends a successful-job notification. The business must know what data is protected, how quickly it can be restored, who can authorize recovery, and whether an attacker could delete the backups as part of the same incident.
Ransomware is one reason recovery matters, but it is not the only one. Accidental deletion, compromised accounts, failed equipment, severe weather, water damage, theft, and vendor outages can also interrupt operations. Central Florida businesses should consider continuity for both cyber events and physical disruptions.
CISA and StopRansomware.gov recommend planning, protecting backups, and testing recovery. The details should be adapted to the business’s systems and priorities.
Define recovery priorities
List the processes that keep the business functioning. Examples include:
- Receiving and responding to customer requests.
- Scheduling and dispatch.
- Payroll and employee communication.
- Invoicing and payment collection.
- Access to contracts and active work files.
- Patient, client, or matter records.
- Telephone and internet service.
For each process, define a realistic recovery time objective: how long the business can operate without it. Define a recovery point objective: how much recent data the business can afford to lose.
Avoid copying generic numbers from a template. A small office may tolerate a day without an archive but only an hour without scheduling or payment processing.
Protect backups from the same compromise
Backups should be separated from ordinary user access. Consider a combination of:
- Versioned cloud backups.
- Offline or otherwise disconnected copies.
- Separate administrative credentials.
- Multifactor authentication for backup consoles.
- Immutable or deletion-protected retention where supported.
- Monitoring for unusual deletion, encryption, or mass-change activity.
- A documented process for emergency restoration.
The exact design depends on the platform and data. A cloud synchronization folder is not automatically a backup. If an encrypted file synchronizes everywhere, the business may have replicated the problem rather than preserved a clean recovery point.
Test the restore, not just the backup
At least quarterly, restore representative data. Include a file, a folder, a database export, and a complete workstation or application recovery when practical.
Record:
- What was restored.
- From which recovery point.
- How long the restoration took.
- Who performed and approved it.
- Whether permissions and file versions were correct.
- What failed or required manual work.
- What will be changed before the next test.
For critical systems, perform a scenario exercise that assumes the primary environment is unavailable. Determine how employees will communicate, how customers will be served, and how transactions will be recorded manually.
Plan for identity recovery
Ransomware and account compromise often overlap. If the administrator account is controlled by an attacker, restoring files may not be enough. Include identity recovery in the plan.
- Maintain protected emergency accounts.
- Document tenant, domain, registrar, and backup-provider ownership.
- Store recovery codes and critical contacts securely offline.
- Keep a list of authorized administrators.
- Know how to revoke sessions and authentication methods.
- Confirm who can contact vendors and law enforcement.
Do not place the only copy of recovery instructions in the system that may be inaccessible.
Establish an incident decision process
Employees should know what to do if files suddenly become unreadable, a ransom message appears, or a suspicious administrator action is detected.
- Stop using affected systems when safe to do so.
- Disconnect affected devices from networks without destroying evidence.
- Contact the incident-response and technology contacts.
- Do not negotiate, wipe systems, or restore over evidence without guidance.
- Notify the bank immediately if payment fraud may have occurred.
- Contact the insurer according to the policy’s instructions.
- Consider reporting to law enforcement and the FBI’s Internet Crime Complaint Center.
Legal, insurance, regulatory, and contractual requirements depend on the facts. A technical recovery decision should not be treated as a substitute for legal advice.
Confirmed versus uncertain
Confirmed: CISA recommends planning and protected, tested backups as part of ransomware resilience. Confirmed: a backup system may be reachable by the same credentials used elsewhere if it is poorly configured. Uncertain: the appropriate retention, recovery time, and notification steps until the business maps its systems, data, contracts, and obligations.
Recovery is a business capability. Management should review backup reports, restoration tests, recovery priorities, and open failures as regularly as it reviews cash flow or insurance coverage. The goal is not merely to possess copies of data. It is to keep the business capable of making informed decisions during a bad week.
