Backups are only one part of continuity
Ransomware can make files, applications, and systems unavailable. For a small office, the disruption may affect scheduling, billing, payroll, client communication, patient service, manufacturing, or access to records.
CISA recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity. The FTC advises small businesses to have a plan for staying operational after ransomware and to share it with everyone who needs to know.
Those recommendations point to a larger question: can the office continue its most important work while technology is being investigated and restored?
The following tabletop exercise can be completed in about an hour. It does not involve encrypting systems or interrupting production. It tests decisions, responsibilities, assumptions, and recovery evidence.
Scenario: a normal morning becomes unavailable
At 8:30 a.m., several employees report that documents will not open. A shared folder contains unfamiliar file names. One employee received a message demanding payment. The accounting application is inaccessible, and the office manager cannot confirm whether backups are safe.
Ask participants to assume that the cause is not yet confirmed. That distinction matters. The first response should preserve evidence and limit harm without guessing about the attacker or promising a recovery time that has not been demonstrated.
First 15 minutes: stabilize
Ask:
- Who declares an incident?
- Who disconnects affected devices from the network?
- Who contacts the technology provider or incident-response team?
- Who protects unaffected systems from being connected to the suspected environment?
- Who informs leadership and staff?
- What communications channel works if email is unavailable?
The FTC advises disconnecting infected devices from the network without powering them down, while recognizing that technical responders may provide situation-specific direction. Staff should not delete suspicious files, reimage devices, or attempt random fixes before the response team determines what evidence is needed.
The office should maintain a current list of emergency contacts outside the affected systems. Include the technology provider, cyber-insurance carrier, bank fraud department, legal counsel, key vendors, and relevant reporting contacts.
First hour: determine what must continue
List the business services that cannot simply wait:
- Safety or patient-care functions.
- Client or customer communication.
- Scheduling and appointment management.
- Payment collection and payroll.
- Access to critical records.
- Regulatory or contractual notifications.
- Physical operations and facility access.
For each service, identify a temporary manual method. That may be paper forms, a clean spare device, a separate phone line, offline contact lists, preapproved payment procedures, or a temporary workspace. These are not permanent replacements. They are continuity bridges while the technology environment is assessed.
Document the maximum tolerable interruption for each service. “As soon as possible” is not a recovery target. Write a realistic time such as four hours, one business day, or three business days, then identify what that target depends on.
Test the backup assumptions
Ask the backup owner to demonstrate, without altering production:
- What data is included.
- When the last successful backup completed.
- Whether backups are isolated from ordinary network credentials.
- Whether backup administration requires separate authentication.
- How long retained copies remain available.
- Whether a clean restoration environment exists.
- Who can authorize restoration.
- How restored data will be checked for completeness and malware.
CISA warns that many ransomware variants attempt to find and delete or encrypt accessible backups. A backup that is continuously reachable from the same compromised administrator account may not provide the protection the business assumes.
A successful backup job is not the same as a successful recovery. Test restoration of a representative file, then test a complete application or system where practical. Record elapsed time, missing permissions, unavailable software, licensing problems, and dependencies that were not documented.
Restore in a deliberate order
CISA recommends prioritizing restoration based on critical systems and services, using a clean network and taking care not to reintroduce malware during recovery.
Create a recovery sequence before an incident:
- Identity and administrator access.
- Network and secure connectivity.
- Communications and essential email.
- Scheduling or practice-management systems.
- Financial and payment systems.
- Critical file repositories.
- Specialized applications.
- Lower-priority services.
The order will vary by business. A medical office, law firm, construction company, and accounting practice may have different dependencies. The important point is to document the logic and test it.
Decide what not to do
The exercise should also identify prohibited actions:
- Do not reconnect devices merely to see whether they work.
- Do not restore to an unverified environment.
- Do not let every employee contact the attacker.
- Do not pay without legal, insurance, executive, and law-enforcement considerations.
- Do not promise customers that no data was accessed before investigation.
- Do not destroy logs or suspicious messages.
CISA states that paying a ransom does not guarantee recovery and recommends contacting law enforcement. Whether a business considers payment is a fact-specific decision requiring qualified advice.
Measure the drill
Record:
- Time to identify the incident lead.
- Time to reach technical and legal contacts.
- Time to identify critical services.
- Time to locate an offline or isolated backup.
- Time to restore a representative file or system.
- Decisions that required unavailable information.
- Contacts, credentials, or procedures that failed.
Assign each gap an owner and due date. Repeat the exercise after major changes to systems, vendors, staffing, or office operations.
What is confirmed and what is uncertain
Confirmed: CISA and the FTC recommend tested backups, recovery planning, isolation, investigation, and continuity preparation. These practices improve readiness but cannot guarantee that every incident will be contained or that every backup will be usable.
Uncertain: Restoration time, data exposure, legal notification duties, insurance coverage, and ransom considerations depend on the incident and the business. Avoid giving definitive answers until qualified responders and advisors have investigated.
The result owners should want
A good drill does not end with “our backups work.” It ends with a dated record showing who makes decisions, what the office does first, which services matter most, how restoration is verified, and how work continues while systems are unavailable.

