Home›Guides›DRP and BCP

DRP and BCP

How do you restart your IT systems after ransomware?

IT systems are restarted after ransomware by restoring a copy predating the intrusion onto new or rebuilt machines, after removing the attacker’s access. Do not decrypt in place to save time while the network and accounts have not been cleaned up: the goal is a clean service, not the fastest return to the infected state.

Updated in October 20263 min read5 sources cited

Key points

  • Change privileged passwords from a clean machine before switching anything back on.
  • Choose a copy older than the first sign of intrusion; if in doubt, older still.
  • Order: administration network, identity, backups, data and applications, workstations, email, users.
  • The ANSSI, France’s national cybersecurity agency, warns that a poorly rebuilt core of trust (directory) leads to a cycle of compromise that can last for months.
  • The standby environment is only disconnected after a successful backup of the new state.

Before switching anything back on

  • The compromised production network remains isolated.
  • Passwords for privileged accounts, VPNs, email, backup and firewalls are changed from a clean machine, not from a workstation that is still questionable.
  • Identify the probable date on which abnormal activity began (accounts created, scheduled tasks, volume of encryption). The copy to restore is older than that date. If in doubt, choose an older one, even if it means losing more data entry.
  • Confirm that this copy opens: one file, then one database, before launching the full restore.
  • The complaint is filed with the police in your country before machines are reinstalled, so that the technical evidence remains available.

Paying the ransom to obtain a decryptor does not exempt you from any of these steps. Even when the decryptor works, it does not remove the access left behind by the attacker.

The four stages of remediation

The ANSSI divides crisis exit into four phases, summarised in French under the acronym “E3R”:

PhaseObjectiveExample action
ContainmentStop the spreadCut Internet access, isolate affected segments
EvictionRemove the attackerRevoke accounts and sessions, change all secrets
EradicationRemove their tools and backdoorsReinstall rather than clean
RebuildingBring a clean IT system back into serviceRestore data onto a clean base

Restoring backups belongs to the last phase. Doing it earlier often means restoring for the attacker.

The rebuild order

  1. A new administration network, separate, from which all work is done.
  2. Identity: directory or local accounts rebuilt, not a copy of the directory as is if it may contain accounts created by the attacker. This is a point to settle with the incident response provider. The ANSSI stresses that failing to rebuild this core of trust leads to a cycle of compromise and remediation that can stretch over months.
  3. The backups themselves: check that they are still inaccessible to old accounts.
  4. Data and business applications, in order of dependency (database before application). The ANSSI asks for this restore order to be defined in advance, taking into account infrastructure services (DNS, NTP, directory) and the criticality of applications.
  5. Workstations, reinstalled rather than “cleaned” when there is no certainty. Reconnecting a workstation that is still infected restarts the attack.
  6. Email, often handled separately (Microsoft 365 or Google Workspace). For a compromised account, Microsoft recommends resetting the password, revoking all open sessions, deleting suspicious mailbox rules and forwarding, then enforcing multi-factor authentication.
  7. The return of users, in groups, with a business check. A gradual return to service, under monitoring, is recommended, with security updates applied before reconnection.

Where to restart

Three options, from the slowest to the best prepared:

  • reinstall new servers on the premises, then restore the copies: long RTO, depends on hardware;
  • start standby instances from the backed-up images (DRP): work continues off-site while rebuilding, on a chosen version;
  • fail over to a BCP that is already running: only if that standby environment has not replicated the encryption. If it has, fall back on the DRP and an older version.

Getting back to normal

When the premises are ready, data is moved back from the standby environment to production, including whatever was entered during the standby period. A backup cycle is resumed the same day. The standby environment is only disconnected after a successful backup of the new state. Then the entry point is fixed and a new restore test is run: see How do you protect your backups against ransomware?.

At WeDoBack

The DRP is designed for exactly this restart: choice of version, restart of servers on standby instances, public IP addresses (0.54 € excl. VAT per address per month) if services must be reachable from outside, and activation during a disaster billed per day. The restore can cover the complete server, from a system image, or files only. The encryption key is held by the customer and must be available: without it, copies remain unreadable, whether immutable or not. The IMMUTABLE offer guarantees that the chosen version still exists. It does not decide, on the team’s behalf, which date predates the intrusion. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and from 14:00 to 17:30 (Paris time).

Frequently asked questions

Can we simply restore yesterday’s backup?

Rarely. An intrusion often precedes encryption by several days or weeks. Yesterday’s backup may contain the accounts, scheduled tasks or tools left behind by the attacker. First establish when the abnormal activity began, then restore an earlier copy onto a cleaned-up environment.

Should Active Directory be restored from backup?

This is a decision to be taken with the incident response provider. A copy of the directory may contain accounts or privileges created by the attacker. The ANSSI, France’s national cybersecurity agency, devotes an entire guide to rebuilding this “core of trust”, because failing to do so restarts the compromise.

How long does a full restart take?

Critical services can be back up within a few days on a clean or standby environment. According to the ANSSI, full remediation can take several weeks or even several months after a major incident. The plan must therefore provide for a sustained degraded mode.

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.