← All insights

Ransomware, backup, and business continuity

The Ransomware Recovery Runbook: Decisions to Make Before an Office Goes Offline

A pre-incident runbook that helps small offices coordinate containment, communications, restoration, and business continuity during a ransomware disruption.

Small-office response team reviewing a printed ransomware recovery runbook and continuity priorities

Recovery starts with decisions

Ransomware response becomes slower when an office must decide basic questions during the first stressful hours: who can disconnect systems, who can authorize restoration, where emergency contacts are stored, and which business services matter most.

CISA and the FBI recommend preparation, reporting, and coordinated response. Their guidance does not guarantee recovery or determine whether a company should pay a demand. That decision requires qualified legal, insurance, executive, and investigative input based on the specific circumstances.

Define the first-hour actions

Create a short response card for suspected ransomware:

  • Stop using affected devices unless directed by the response lead.
  • Disconnect an affected device from networks when safe and authorized.
  • Do not delete files, wipe systems, or repeatedly log in to investigate.
  • Contact the designated IT or incident-response provider through a known alternative channel.
  • Preserve ransom notes, timestamps, alerts, suspicious messages, and relevant system information.
  • Notify the owner or executive decision-maker.
  • Engage cyber insurance, counsel, and law enforcement according to prearranged procedures.

The exact technical steps depend on the environment. A small office should not improvise forensic work based on a social-media post.

Separate containment from restoration

Containment seeks to stop spread and preserve information. Restoration seeks to return systems to a trusted operating state. Mixing the two can reintroduce an attacker or destroy evidence.

Before restoring, responders should determine which accounts, endpoints, servers, cloud services, and backups may have been affected. Credentials may need to be reset from a clean device. Administrator access should be reviewed. Backups should be evaluated for integrity and isolation rather than immediately connected to production.

Prioritize business services

List the minimum services needed to operate for one day, one week, and one month. Examples may include telephones, scheduling, payment collection, payroll, customer contact, document access, and safety-related systems.

For each service, record:

  • The owner and technical dependency.
  • The acceptable outage duration.
  • A manual workaround.
  • The information required to continue.
  • The restoration order.
  • The person authorized to declare it operational.

This creates a business continuity sequence rather than a technology-only recovery plan.

Make backup claims testable

A backup program should answer five practical questions: what is protected, how often it is copied, how long it is retained, who can delete or alter it, and how restoration is tested. CISA’s ransomware guidance emphasizes offline or otherwise protected backups and regular testing.

Test a representative file restoration first, then test a larger system or application when appropriate. Record elapsed time, dependencies, permissions, configuration issues, and whether the restored data was usable by the business. A successful backup job does not necessarily prove that the application, permissions, or workflow can be recovered.

Protect backup administration separately from ordinary user access. If an attacker can control both production systems and backups through the same compromised administrator account, the recovery strategy may fail at the moment it is needed.

Communicate carefully

Prepare holding statements for employees, customers, vendors, and professional advisers. Do not speculate about the cause, scope, or affected records before investigation supports those statements. Avoid promising that no data was accessed simply because systems are unavailable.

Legal and regulatory notification duties vary according to jurisdiction, industry, contract, data type, and facts established during the investigation. A runbook should direct managers to counsel and relevant authorities rather than attempting to encode every possible requirement.

Run a tabletop exercise

Use a scenario such as: an employee reports that shared files are encrypted, the finance mailbox is inaccessible, and the backup console shows a recent administrative login. Ask participants what they will do in the next 15 minutes, two hours, and two days.

Capture disagreements. If nobody knows who can suspend accounts or where the emergency contact sheet is stored, the exercise has identified a real gap.

What is confirmed versus uncertain

Confirmed: preparation, protected backups, tested restoration, and coordinated reporting improve readiness. Uncertain: the speed and completeness of any recovery, because those depend on the attacker’s access, backup condition, vendor dependencies, evidence, and business decisions.

The practical objective is not to promise a painless recovery. It is to make the first decisions clear, protect the ability to investigate, and restore the most important business functions in a controlled order.

This article is a human-reviewed draft and is not incident-response, legal, insurance, or forensic advice.

Sources