← All insights

Ransomware, backup, and business continuity

Ransomware Recovery Begins Before the First Encrypted File

Why Central Florida businesses should define restoration priorities, isolate backups, and rehearse decisions before a ransomware or data-extortion event.

Business continuity planning materials beside a secure backup storage concept in an office

The recovery question is bigger than ransom

Ransomware can prevent access to files, applications, and systems. Data extortion can create a second problem even when systems are restored: sensitive information may have been copied and threatened for release. The FBI’s 2025 IC3 report recorded more than 3,600 ransomware complaints and more than $32 million in reported losses, while noting that reported figures do not include every cost or every incident. These figures describe complaints received by the FBI, not the probability that a particular Central Florida business will be attacked.

The useful management question is not “Would we pay?” It is “How would we continue essential work, investigate, communicate, and restore operations?”

Define critical services

Make a short list of functions that must be restored first:

  • Receiving calls and scheduling work.
  • Accessing customer, patient, or client information.
  • Processing payroll and payments.
  • Producing invoices and collecting revenue.
  • Operating physical access, point-of-sale, or specialized equipment.
  • Communicating with employees, customers, insurers, and regulators.

For each function, define a recovery time objective: how long the business can operate without it. Also define a recovery point objective: how much recent data the business can afford to lose. These are business decisions, not technical guesses.

Build backups that ransomware cannot easily reach

CISA recommends maintaining offline, encrypted backups of critical data and regularly testing their availability and integrity. A backup connected continuously with the same administrative credentials as production systems may be deleted or encrypted during an attack.

A sensible small-business design may include:

  • Frequent backups for actively changing data.
  • A protected copy separated from ordinary user and administrator accounts.
  • Encryption in storage and during transfer.
  • Retention that reflects legal, operational, and recovery needs.
  • Versioning or immutability where correctly configured.
  • A second recovery path for critical systems or cloud data.

No single backup label guarantees recoverability. Test by restoring representative files and, for critical applications, by rebuilding or accessing a clean environment. Record the result, not just the backup-job status.

Protect the recovery path

The recovery account can be more important than the production account. Restrict who can delete backups, change retention, alter recovery settings, or create new administrator access. Require MFA and maintain emergency procedures that do not depend on the compromised environment.

Keep an offline copy of essential contacts, system priorities, vendor information, insurance details, and manual operating procedures. During an outage, the normal password manager, email account, and shared drive may be unavailable.

Prepare for the first hour

If ransomware is suspected:

  • Stop using affected systems unless necessary for safe shutdown or evidence collection.
  • Isolate affected devices as directed by qualified responders.
  • Do not wipe systems or restore blindly before evidence and scope are assessed.
  • Contact the IT provider, cyber insurer, legal counsel, and law enforcement contacts.
  • Protect backups from further access.
  • Record times, symptoms, messages, and actions taken.
  • Use a single communications lead to reduce conflicting instructions.

CISA’s response guidance emphasizes preparation, containment, recovery, and lessons learned. The correct technical action depends on the environment, so a generic internet instruction should not replace incident-response expertise.

Decide what “continuity” means

Continuity may involve temporary paper forms, alternate email or phone methods, a secondary location, manual payment procedures, or prioritized customer communication. Document how long each workaround can function and who approves it.

For a medical or professional office, continuity planning should address privacy during manual processing. For a contractor or field-service business, it may focus on dispatch, job records, and customer communications. For a retailer, it may include point-of-sale downtime and inventory records. The plan should reflect actual work, not an abstract IT diagram.

After restoration

Do not assume restored files mean the incident is over. Confirm that affected credentials were reset, persistence mechanisms were removed, systems were patched, backups were protected, and monitoring is active. Review what failed and update the plan.

Report appropriate information to the FBI or IC3 and evaluate legal, contractual, regulatory, and insurance notification duties with qualified advisers. Reporting, recovery, and notification are related but separate decisions.

Every article remains a human-reviewed draft. This article is educational and does not replace legal, regulatory, insurance, or technical advice.

Sources