A backup is a claim until restoration proves it
A dashboard showing successful backup jobs is useful, but it does not prove that a Central Florida business can resume operations after ransomware. Recovery may also require clean devices, working identities, application installers, license information, vendor support, network configuration, and a decision about which business process returns first.
CISA’s #StopRansomware Guide recommends offline, encrypted backups and regular testing of their availability and integrity. It also recommends understanding critical assets and interdependencies. A restore-day exercise turns that guidance into evidence.
Select one realistic scenario
Choose a scenario that matters to the organization: the shared file system is encrypted, Microsoft 365 data is deleted or altered, the line-of-business server is unavailable, or the primary office cannot be used after a storm. Define what is unavailable and what remains trusted.
Do not announce a full technical disaster with no boundaries. A useful exercise has a start time, responsible participants, defined systems, safety limits, and clear success criteria. Production systems should not be put at risk merely to make the test dramatic.
Identify the first business outcomes
Ask department leaders what must work in the first four, eight, and twenty-four hours. A medical office may prioritize patient schedules and communications. A construction firm may prioritize field coordination, drawings, payroll, and vendor contacts. A professional office may need email, document access, billing, and client deadlines.
Record dependencies. Restoring an application is not enough if no one can authenticate, its database is missing, or the office lacks the network route required to use it.
Validate that backups are separated
CISA notes that ransomware often attempts to delete or encrypt accessible backups. Confirm that ordinary user credentials and a compromised administrator cannot casually destroy every recovery copy. Review encryption, immutability or deletion protection where supported, retention, administrative separation, and alerts for unusual changes.
Cloud services also require a shared-responsibility review. Availability from the provider is not the same as protection from accidental deletion, malicious changes, compromised accounts, or retention limits.
Run the restore
Use a clean, isolated destination. Restore a representative application, folder set, configuration, or system image. Time each phase: authorization, vendor contact, media access, data transfer, rebuilding, validation, and return to use.
Check more than file count. Open representative records, verify dates and permissions, test application functions, scan for malware as appropriate, and ask a business user—not only the technician—to confirm usability. Preserve logs and note every workaround.
Test the people and paper plan
The exercise should confirm:
- Who can authorize restoration and emergency spending.
- How the organization communicates if normal email is unavailable.
- Where offline contact lists and recovery instructions are stored.
- Which vendors provide emergency support and during what hours.
- How cyber-insurance, legal counsel, and law enforcement contacts are reached when applicable.
- Who documents decisions and preserves evidence.
CISA advises contacting law enforcement after a ransomware incident and provides a response checklist. The exercise should identify reporting routes before an emergency, not improvise them during one.
Measure the result honestly
Record recovery time, recovery point, missing dependencies, failed credentials, outdated instructions, unexpected fees, unavailable personnel, and data that could not be validated. Distinguish a technical restore from business recovery.
Assign each corrective action an owner and due date. Retest failed or uncertain steps. A test that reveals gaps is valuable; a test reported as successful despite workarounds and missing evidence is not.
Include Florida disruption conditions
Consider a simultaneous power or internet outage, flooded or inaccessible office, damaged employee device, and delayed vendor response. Maintain essential contacts and instructions outside the systems they are meant to recover. Confirm that alternate work locations and remote access do not bypass security controls.
A practical quarterly evidence set
Keep the scenario, participants, systems tested, backup source, clean destination, timestamps, validation results, screenshots or logs where appropriate, exceptions, corrective actions, and management acknowledgement. Avoid storing sensitive credentials in the report.
The goal is not to promise immunity from ransomware. It is to know, through evidence, what the organization can restore, how long it takes, and what still prevents safe operations.
Human-reviewed draft. This article is general information, not incident-response, legal, insurance, or regulatory advice.

