Rate Us:
Home · Managed IT · Ransomware and Disaster Recovery

Ransomware Recovery, Incident Response and Business Continuity

Layered protection stops most attacks. Planning for the rest decides whether a business survives the week that follows.
Prevention, detection and recovery
Downtime and data loss limits, in writing
Incident response that keeps the claim intact
Why this matters

Stopping what you can, recovering from what you cannot

Every figure below comes from a company that was already attacked, so none of them are about whether protection works. Once something gets through, the outcome turns on whether anybody has ever run a full restore end to end and clocked it.
0%
of ransomware attacks started with a compromised identity, not with malware forcing its way in. Stolen and abused logins are the front door now.
0%
still succeeded in encrypting data, up from 50% the year before. Good protection lowers the odds. Recovery covers what gets through.
0%
of organizations whose data was encrypted recovered from backups instead of paying.
$1.7M
average cost to recover from an incident, up 11% in a year, ransom paid or not.
Figures from Sophos, State of Ransomware 2026, a survey of 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit in the previous twelve months.
If it happens

Do the right steps, in the right order

Most of the avoidable damage comes from two mistakes. Powering the machines off wipes the memory that would have shown what happened and how. Restoring data before anybody has found the way in hands the attacker a clean environment to start again in.

Happening right now? Call before you touch anything else. What gets done in the first hour decides how much is recoverable.
510 552 6896
1
Pull the network, leave the machines on
2
Run your incident response plan and call your carrier
3
Establish what got in and when, and preserve the logs
4
Decide about payment with facts in front of you
5
Keep a record while it is happening
6
Rebuild clean, and do it last
Before it happens

Six controls that decide how that week goes

Prevention has its own pages. What follows is the recovery half, and every item costs less now than improvised mid-incident. Your carrier asks about most of them at renewal.

Keeping it out
The layered work that stops most attempts before they reach anything worth encrypting.
Multifactor, endpoint detection with a person behind it, no standing local administrator rights, patching that includes the edge devices, a segmented network, and mail filtering with training that repeats. Six controls, and they prevent far more incidents than they help you recover from, which is why they are set out where they belong rather than summarized here.
Getting it back
What decides how fast you are running again, and what the downtime costs.
A restore you have timed, not a backup job that reports success
One copy that your own admin credentials cannot delete
Agreed limits on downtime and data loss, system by system
A plan with names and numbers, reachable when email is down
One rehearsal, before you need it
A way to keep working while the rebuild happens
The gap most firms have

Microsoft and Google do not back up your data for you

Both platforms replicate your data so the service survives their own hardware failing. That is not a backup of your business. Once something is deleted or encrypted you have weeks at the outside, and both say so in their documentation.

What Microsoft 365 actually keeps
What Google Workspace actually keeps

Third party backup for Microsoft 365 or Workspace closes that gap, and it is a question we now see on renewal applications. If your file server is backed up nightly and your tenant is not, that is the first thing to fix.

Sources: Microsoft Services Agreement. Microsoft, Data Retention, Deletion and Destruction in Microsoft 365. Google Workspace security whitepaper, data recovery. Checked September 2026.
Take it further

The same controls, asked about in three places

Multifactor everywhere, immutable backups, a tested restore and a written response plan. Your recovery depends on them, and so do the insurance application and the security exhibits clients now attach to contracts.
V&A Consulting Engineers went from eleven servers to two, with the files moved into Egnyte. Nine fewer machines is nine fewer things to back up, patch and restore, which is why consolidation usually shows up as a recovery improvement before it shows up as a saving.
Renewal coming up? That is cyber insurance readiness.
Want the monitoring that catches it earlier? That is proactive monitoring and threat detection.
Common questions
We have backups. Why is that not enough?
How fast can you get us back?
Should we pay the ransom?
Do we have to tell our insurer before we do anything?
What is the difference between RTO and RPO?
Can you help if we are in an incident right now and you are not our provider?
When did you last finish a restore?
If the answer is not a date, that is the place to start.

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.