Organisations that recover well from ransomware are not lucky. They made a specific set of preparations, and those preparations are unglamorous enough that they rarely get funded until after the first incident.
Backups that survive the attacker
Modern ransomware crews hunt backups first, because an organisation that can restore does not pay. A backup reachable with the domain administrator credentials the attacker now holds is not a backup.
- Offline or immutable copies. Something the attacker cannot delete or encrypt even with full administrative access.
- Separate credentials. The backup system must not authenticate against the directory you are protecting.
- Tested restores. Not "the job completed" — an actual restore of an actual critical system, timed, at least twice a year.
- Known recovery time. If you do not know how long a full restore takes, you cannot make an informed decision about paying.
Limit how far it spreads
Ransomware encrypts what it can reach. Most environments let it reach nearly everything.
- Network segmentation, so one compromised workstation does not see every server.
- Least privilege — most users do not need write access to most shares.
- Tiered administration, so a workstation compromise does not yield domain administrator.
- Disabled legacy protocols and unnecessary remote management paths.
Detect the hours before encryption
Encryption is the last step. Before it, the attacker spent days or weeks gaining access, escalating, moving laterally and staging exfiltration. Every one of those stages is detectable:
- Credential dumping tools on endpoints.
- Unusual administrative logins outside working hours.
- Mass file reads, or large outbound transfers to unfamiliar destinations.
- Shadow copy deletion and backup service tampering — often the final warning.
- Security tooling being disabled on multiple hosts.
Decide about payment before you need to
Payment is a business decision with legal, regulatory and ethical dimensions, and it is a terrible decision to take for the first time under pressure at midnight. Establish in advance who decides, what the organisation's position is, whether insurance covers it and what the insurer requires, and what your legal obligations are.
Worth knowing: payment does not reliably return your data. Decryptors are frequently slow or incomplete, exfiltrated data is rarely deleted as promised, and organisations that pay are disproportionately targeted again.
If it happens
Do not immediately wipe and rebuild. Preserve evidence first — you will need it to establish what was taken, to meet notification obligations, and to understand how they got in so it does not happen again. Isolate rather than power off where possible, since memory contains evidence that is lost on shutdown.
Then call someone who does this regularly. The first few hours shape everything that follows.
