A backup is not the same as recovery
Many offices know that backups exist. Fewer can answer how long recovery will take, who can authorize it, which systems return first, or whether a clean copy can actually be used.
CISA’s StopRansomware guidance recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity. It also emphasizes that ransomware may attempt to delete or encrypt backups that remain accessible from the network.
A tabletop exercise turns those recommendations into a business decision. No files need to be encrypted. The team simply works through a realistic scenario and records where uncertainty appears.
The scenario
At 8:30 a.m., an employee reports that several shared folders cannot be opened. A second workstation displays an unfamiliar message. The office’s file server is slow, and the backup dashboard shows a successful job from the previous night. A vendor who normally helps remotely is not immediately available.
The exercise should not assume that the event is definitely ransomware. It should ask what the office would do if ransomware, credential compromise, or a system failure were all plausible explanations.
Invite the owner, office manager, technology provider, finance lead, and one person responsible for the most important business process. If the office handles regulated information, include qualified privacy or legal counsel in the planning process.
First 30 minutes: contain and communicate
Ask the team:
- Who is authorized to tell staff to disconnect devices?
- How will affected systems be isolated without destroying useful evidence?
- What communication channel is safe if email may be compromised?
- Who contacts the bank, insurer, technology provider, and law enforcement?
- Who decides whether the office closes, switches to paper, or moves to an alternate process?
CISA recommends isolating impacted systems and, where appropriate, using out-of-band communication. The objective is to prevent spread while preserving information needed for investigation.
Do not allow well-intentioned staff to wipe devices, reinstall systems, or delete suspicious messages before the response team decides what evidence is needed.
The recovery priority list
Create a list of services in business order, not technology order. For example:
- Telephone and primary communication.
- Scheduling or dispatch.
- Payment processing.
- Accounting and payroll.
- Customer or patient records.
- File storage and document production.
- Secondary applications and archives.
For each service, record the acceptable downtime, data-loss tolerance, system dependencies, vendor contact, and recovery method. Restoring a file server may not restore the business if identity, licensing, line-of-business software, or internet connectivity is still unavailable.
Test the backup claim
Select several representative files and one important workflow. Ask the backup administrator to demonstrate:
- Where the backups are stored.
- Which copies are offline, immutable, or otherwise protected from ordinary access.
- How the team authenticates to the backup platform.
- How a file is restored.
- How a complete system or application would be rebuilt.
- How the team confirms that restored data is clean.
- How long the process takes.
CISA also recommends maintaining system images or templates for critical systems and protecting the information needed to rebuild them. A cloud backup may protect files but not automatically restore permissions, applications, configurations, or identity services.
The uncomfortable questions
The exercise should ask questions that normal status reports may hide:
- Is the backup account separate from normal administrator accounts?
- Can an attacker who compromises Microsoft 365 also delete cloud backup data?
- Are backup alerts reviewed by a person?
- Are encryption keys or recovery codes available if the usual administrator is unavailable?
- Can the office operate if email is down for two days?
- Are paper procedures current enough to use?
- Does the cyber insurance policy require specific controls or notification steps?
A “yes” should be supported by evidence. If the answer is “we think so,” record it as an action item.
Reporting and legal decisions
Ransomware may involve data theft, not only encryption. CISA notes that attackers may exfiltrate data and threaten to release it. Therefore, recovery planning must include questions about what information may have been accessed and how evidence will be preserved.
Contact law enforcement and qualified professionals promptly. The decision whether to notify customers, regulators, employees, insurers, or contractual partners depends on the facts and applicable requirements.
After the exercise
Rank findings by business impact and time to fix. Typical actions may include adding an offline backup, changing backup administration, documenting recovery credentials, creating a clean-system build procedure, or updating the contact tree.
Repeat the exercise after major changes and at a reasonable interval. The goal is not a dramatic simulation. It is a smaller, more confident response when the office faces a real interruption.
Confirmed versus uncertain
It is confirmed that offline backups, restoration testing, incident planning, and prioritized recovery are core recommendations in CISA’s ransomware guidance. It is uncertain whether any office’s particular backup is recoverable until a restoration test demonstrates it.
The most valuable result of the exercise is often not a new product. It is a short list of assumptions that must become documented, tested capabilities.

