Practical guide ·
We have backups. Can we actually recover the business after ransomware?
A completed backup job does not establish that a business service can be restored. Check whether the copies remain accessible after account compromise, whether the recovery environment is usable and whether dependencies are included. The decisive test is an agreed business operation completed safely with recoverable data.
What are we trying to recover?
Start with a business operation: accepting orders, paying suppliers or accessing clinical records. Identify the applications, identity services, network connections, external feeds and people it needs. Restoring a server without those dependencies can create a misleading impression of progress.
Agree tolerable downtime and data loss with the business owner. These are different decisions. A system restored quickly with missing transactions may still fail the intended outcome.
Could an attacker reach the recovery capability?
CISA recommends protected backups and regular restoration testing. Consider what happens if the production administrator account is compromised. Can that same account delete copies, change retention or prevent access to the backup service?
Check the separation of administration and recovery credentials, the protection of copies and the availability of recovery instructions. A plan stored only on an unavailable corporate drive will be difficult to use. Keep authorised emergency access controlled, documented and tested.
| Question | Evidence to seek | Failure implication |
|---|---|---|
| Can we access the copies? | Tested recovery access | Copies may exist but be unusable |
| Can we restore dependencies? | Dependency map and test result | Application may start without its service |
| Is the data usable? | Integrity and transaction checks | Fast recovery may still lose business value |
| Who accepts the result? | Named business owner and criteria | Technical success may be mistaken for recovery |
What does a useful test include?
In an illustrative exercise, restore a selected application into an agreed isolated environment. Verify the integrity of the selected data and execute a representative business transaction. Record actual time, missing dependencies and any manual steps. Have the business owner confirm acceptance.
The test must have an approved scope so it does not itself interrupt production. Agree who can stop it, how data is protected and how the environment is cleaned up. Use results to correct the plan and repeat the affected part.
What do backups leave unresolved?
Recovery does not answer whether data was stolen, whether an attacker retains access or which notifications are required. These questions run alongside restoration and need their own owners. A rushed return to service can reintroduce an unresolved compromise.
The ransomware publication listed in our research section provides background on attack patterns. This guide focuses on the business recovery decision. When reporting readiness, state what has been tested, what remains assumed and which risk the responsible manager has accepted.
Explore in detail: Ransomware in 2026: how they get in and what actually stops it.
How Dyasol can help
Dyasol can help review recovery arrangements and plan improvements within an agreed scope. Recovery testing and technical changes are separately agreed; this page is not an emergency response channel.
Sources and context
Examples are illustrative. Practical recommendations should be adapted to the organisation.