Stopping what you can, recovering from what you cannot
Every figure below comes from a company that was already attacked, so none of them are about whether protection works. Once something gets through, the outcome turns on whether anybody has ever run a full restore end to end and clocked it.
0%
of ransomware attacks started with a compromised identity, not with malware forcing its way in. Stolen and abused logins are the front door now.
0%
still succeeded in encrypting data, up from 50% the year before. Good protection lowers the odds. Recovery covers what gets through.
0%
of organizations whose data was encrypted recovered from backups instead of paying.
$1.7M
average cost to recover from an incident, up 11% in a year, ransom paid or not.
Figures from Sophos, State of Ransomware 2026, a survey of 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit in the previous twelve months.
If it happens
Do the right steps, in the right order
Most of the avoidable damage comes from two mistakes. Powering the machines off wipes the memory that would have shown what happened and how. Restoring data before anybody has found the way in hands the attacker a clean environment to start again in.
Happening right now? Call before you touch anything else. What gets done in the first hour decides how much is recoverable.
Disconnect at the switch and the firewall. Working through machines one at a time is too slow, because encryption spreads faster than anyone can work down a device list. Leave the machines powered on. Pulling the plug wipes what is held in memory, and that memory often holds the evidence of how they got in.
2
Run your incident response plan and call your carrier
The plan exists so nobody has to invent the next hour. Your cyber carrier usually has to be told before you engage a forensics firm or a negotiator, or the cost may not be covered, so that call comes early. Counsel, affected clients and any regulator come next, each on the deadline their own rules set.
3
Establish what got in and when, and preserve the logs
The encryption comes last, after everything else has already happened. Attackers are typically inside for days or weeks beforehand, and the dates matter, because they decide which backups are safe to trust and which are already compromised. Preserve the logs before they roll over. A forensics team works from firewall, authentication, endpoint and email logs, and your carrier and law enforcement may both ask for them.
4
Decide about payment with facts in front of you
This is your decision, taken with your carrier and your counsel alongside you. It should not be taken under pressure. Our job is to establish what you can restore and how long that will take, so the choice is an informed one.
5
Keep a record while it is happening
Times, actions, decisions and who made them, written down as you go. That record supports the insurance claim, satisfies a regulator and answers a client months later. Nobody reconstructs it accurately from memory.
6
Rebuild clean, and do it last
Not before you know how they got in. Restoring into the environment that was breached puts you back where you started, sometimes within hours. New or rebuilt systems first, credentials rotated, the entry point closed, and only then the data goes back.
Before it happens
Six controls that decide how that week goes
Prevention has its own pages. What follows is the recovery half, and every item costs less now than improvised mid-incident. Your carrier asks about most of them at renewal.
Keeping it out
The layered work that stops most attempts before they reach anything worth encrypting.
Multifactor, endpoint detection with a person behind it, no standing local administrator rights, patching that includes the edge devices, a segmented network, and mail filtering with training that repeats. Six controls, and they prevent far more incidents than they help you recover from, which is why they are set out where they belong rather than summarized here.
What decides how fast you are running again, and what the downtime costs.
A restore you have timed, not a backup job that reports success
A completed test restore of real production data, with the elapsed time written down. Until you have done it once, your recovery time is a guess. This is also the control carriers ask about most sharply.
One copy that your own admin credentials cannot delete
Immutable or properly offline, so that an attacker holding domain administrator cannot reach the backups on the way through. Ransomware operators look for the backups first, because deleting them removes your choices.
Agreed limits on downtime and data loss, system by system
How long each system can be down (the RTO) and how much data you can afford to lose (the RPO). Those are business calls, and they differ wildly between your accounting system and your file server. Without them agreed, there is nothing to build the plan against.
A plan with names and numbers, reachable when email is down
Who declares an incident, who calls the carrier, who talks to clients, and how any of them reach each other when the systems are encrypted. The same page carries the outside numbers you will need: carrier claims line, broker, counsel, forensics. Sourcing a forensics firm during an incident costs days you do not have, and your carrier may require one from their panel anyway. Keep it printed, or stored somewhere off the network, because the copy on the file server will be encrypted too.
One rehearsal, before you need it
A tabletop exercise, two hours, with the people who would be in the room on the day. Every one we have run has found something the plan got wrong, and finding it in a rehearsal costs nothing.
A way to keep working while the rebuild happens
The rebuild can take a week, and the firm still has to operate through it. Decide in advance which people have to keep working, what they need to do it, and where that comes from: clean laptops, another way to send and receive email, and offline copies of whatever the current jobs depend on. For a design or construction firm that usually means the drawings and the schedule for whatever is on site right now.
The gap most firms have
Microsoft and Google do not back up your data for you
Both platforms replicate your data so the service survives their own hardware failing. That is not a backup of your business. Once something is deleted or encrypted you have weeks at the outside, and both say so in their documentation.
What Microsoft 365 actually keeps
The Microsoft Services Agreement, section 6.b: “We recommend that you regularly backup Your Content and Data that you store on the Services.” Microsoft’s own retention documentation puts deleted customer content at 30 days at most, after which it is, in Microsoft’s words, rendered commercially unrecoverable. That clock runs the same whether the mailbox was deleted by mistake, encrypted through a synced OneDrive folder, or removed along with somebody who left.
What Google Workspace actually keeps
Google’s own security documentation gives an administrator 20 days to restore a deleted user account and 25 days to restore Drive or Gmail data once it has left the trash. Past that, in Google’s words, the data cannot be restored even if you contact technical support. The same window covers a shared drive somebody cleared out and the Gmail of a person whose account was closed on their last day. Vault covers retention and eDiscovery, which is a different job from getting one file back on the day it is needed.
Third party backup for Microsoft 365 or Workspace closes that gap, and it is a question we now see on renewal applications. If your file server is backed up nightly and your tenant is not, that is the first thing to fix.
Sources: Microsoft Services Agreement. Microsoft, Data Retention, Deletion and Destruction in Microsoft 365. Google Workspace security whitepaper, data recovery. Checked September 2026.
Take it further
The same controls, asked about in three places
Multifactor everywhere, immutable backups, a tested restore and a written response plan. Your recovery depends on them, and so do the insurance application and the security exhibits clients now attach to contracts.
V&A Consulting Engineers went from eleven servers to two, with the files moved into Egnyte. Nine fewer machines is nine fewer things to back up, patch and restore, which is why consolidation usually shows up as a recovery improvement before it shows up as a saving.
Because backup jobs report success even when the data inside them cannot be restored, and ransomware operators target the backups deliberately. The test is whether you have completed a restore of real data, timed it, and kept at least one copy your own administrator credentials cannot delete.
How fast can you get us back?
That depends on your RTO, your data volume and whether the environment has to be rebuilt, so any provider quoting you a number without seeing your systems is guessing. We can tell you what your current setup would deliver, which is usually the more useful answer.
Should we pay the ransom?
That decision is yours to take with your insurer and your lawyer alongside you, and sanctions rules can make paying unlawful whatever the commercial argument says. Our part is establishing what can be restored and how long it would take, so the decision is an informed one. Firms that can restore rarely end up paying.
Do we have to tell our insurer before we do anything?
Yes, and it matters. Most cyber policies want to hear from you before you hire anybody to help, and money spent ahead of that call can end up uncovered. Read your policy before you need it, or let us read it with you.
What is the difference between RTO and RPO?
RTO is how long a system can be down before it hurts. RPO is how much recent work you are willing to redo. A file server might tolerate a day of downtime and an hour of lost work, while your accounting system tolerates neither. Setting them per system turns a backup product into a recovery plan.
Can you help if we are in an incident right now and you are not our provider?
Yes. Call the number on this page. We will tell you whether we are the right help or whether you need your carrier's panel forensics team first, and we will not waste your time either way.
When did you last finish a restore?
If the answer is not a date, that is the place to start.