DRP and BCP
How do you restart your IT systems after ransomware?
IT systems are restarted after ransomware by restoring a copy predating the intrusion onto new or rebuilt machines, after removing the attacker’s access. Do not decrypt in place to save time while the network and accounts have not been cleaned up: the goal is a clean service, not the fastest return to the infected state.
Updated in October 20263 min read5 sources cited
Key points
- Change privileged passwords from a clean machine before switching anything back on.
- Choose a copy older than the first sign of intrusion; if in doubt, older still.
- Order: administration network, identity, backups, data and applications, workstations, email, users.
- The ANSSI, France’s national cybersecurity agency, warns that a poorly rebuilt core of trust (directory) leads to a cycle of compromise that can last for months.
- The standby environment is only disconnected after a successful backup of the new state.
Before switching anything back on
- The compromised production network remains isolated.
- Passwords for privileged accounts, VPNs, email, backup and firewalls are changed from a clean machine, not from a workstation that is still questionable.
- Identify the probable date on which abnormal activity began (accounts created, scheduled tasks, volume of encryption). The copy to restore is older than that date. If in doubt, choose an older one, even if it means losing more data entry.
- Confirm that this copy opens: one file, then one database, before launching the full restore.
- The complaint is filed with the police in your country before machines are reinstalled, so that the technical evidence remains available.
Paying the ransom to obtain a decryptor does not exempt you from any of these steps. Even when the decryptor works, it does not remove the access left behind by the attacker.
The four stages of remediation
The ANSSI divides crisis exit into four phases, summarised in French under the acronym “E3R”:
| Phase | Objective | Example action |
|---|---|---|
| Containment | Stop the spread | Cut Internet access, isolate affected segments |
| Eviction | Remove the attacker | Revoke accounts and sessions, change all secrets |
| Eradication | Remove their tools and backdoors | Reinstall rather than clean |
| Rebuilding | Bring a clean IT system back into service | Restore data onto a clean base |
Restoring backups belongs to the last phase. Doing it earlier often means restoring for the attacker.
The rebuild order
- A new administration network, separate, from which all work is done.
- Identity: directory or local accounts rebuilt, not a copy of the directory as is if it may contain accounts created by the attacker. This is a point to settle with the incident response provider. The ANSSI stresses that failing to rebuild this core of trust leads to a cycle of compromise and remediation that can stretch over months.
- The backups themselves: check that they are still inaccessible to old accounts.
- Data and business applications, in order of dependency (database before application). The ANSSI asks for this restore order to be defined in advance, taking into account infrastructure services (DNS, NTP, directory) and the criticality of applications.
- Workstations, reinstalled rather than “cleaned” when there is no certainty. Reconnecting a workstation that is still infected restarts the attack.
- Email, often handled separately (Microsoft 365 or Google Workspace). For a compromised account, Microsoft recommends resetting the password, revoking all open sessions, deleting suspicious mailbox rules and forwarding, then enforcing multi-factor authentication.
- The return of users, in groups, with a business check. A gradual return to service, under monitoring, is recommended, with security updates applied before reconnection.
Where to restart
Three options, from the slowest to the best prepared:
- reinstall new servers on the premises, then restore the copies: long RTO, depends on hardware;
- start standby instances from the backed-up images (DRP): work continues off-site while rebuilding, on a chosen version;
- fail over to a BCP that is already running: only if that standby environment has not replicated the encryption. If it has, fall back on the DRP and an older version.
Getting back to normal
When the premises are ready, data is moved back from the standby environment to production, including whatever was entered during the standby period. A backup cycle is resumed the same day. The standby environment is only disconnected after a successful backup of the new state. Then the entry point is fixed and a new restore test is run: see How do you protect your backups against ransomware?.
At WeDoBack
The DRP is designed for exactly this restart: choice of version, restart of servers on standby instances, public IP addresses (0.54 € excl. VAT per address per month) if services must be reachable from outside, and activation during a disaster billed per day. The restore can cover the complete server, from a system image, or files only. The encryption key is held by the customer and must be available: without it, copies remain unreadable, whether immutable or not. The IMMUTABLE offer guarantees that the chosen version still exists. It does not decide, on the team’s behalf, which date predates the intrusion. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time).
Frequently asked questions
Can we simply restore yesterday’s backup?
Rarely. An intrusion often precedes encryption by several days or weeks. Yesterday’s backup may contain the accounts, scheduled tasks or tools left behind by the attacker. First establish when the abnormal activity began, then restore an earlier copy onto a cleaned-up environment.
Should Active Directory be restored from backup?
This is a decision to be taken with the incident response provider. A copy of the directory may contain accounts or privileges created by the attacker. The ANSSI, France’s national cybersecurity agency, devotes an entire guide to rebuilding this “core of trust”, because failing to do so restarts the compromise.
How long does a full restart take?
Critical services can be back up within a few days on a clean or standby environment. According to the ANSSI, full remediation can take several weeks or even several months after a major incident. The plan must therefore provide for a sustained degraded mode.
Sources
Documents consulted in October 2026.
- Cyberattacks and remediation: keys to decision-making (v1.0, December 2023) — ANSSI (French agency)
- No More Ransom: advice and tools against ransomware — Europol and partners
- Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI (French agency)
- Respond to a compromised cloud email account — Microsoft Learn
- DRP offer: recovery after a disaster — WeDoBack
Planning a backup, DRP or BCP project?
More than 20 years of experience protecting business data.
Request a quote+33 9 72 50 78 28Protect your data with WeDoBack
Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.
