Business Continuity · Guide

Ransomware Recovery: The First 48 Hours

The first 48 hours after a ransomware attack decide how long recovery takes and how much survives. The order of operations: isolate infected machines from the network without powering them off, preserve everything as evidence, notify your insurance carrier and get help assessing scope, verify what backups actually survived, and only then begin restoring — onto infrastructure verified clean, in business-priority order. What follows is the hour-by-hour playbook, written for the New Orleans business owner reading it at 2 a.m. If that's you right now: Nubinity's team is at +1 (833) 792-5683.

Hour zero: contain without destroying evidence

  1. Disconnect affected machines from the network — pull cables, disable Wi-Fi — but leave them powered on. RAM contains encryption keys and attacker artifacts that vanish at shutdown.
  2. Disconnect or power down backup systems and drives immediately if they aren't already encrypted — surviving backups are your recovery.
  3. Photograph ransom notes and screen states; note timestamps of when things were first noticed.
  4. Change credentials from a known-clean device (a phone on cellular counts) — start with email, banking, and admin accounts.
  5. Establish communications off the suspect network. Assume the attacker read what's on it.

The first day: insurers, assessment, and the honest inventory

Call your cyber-insurance carrier's incident line as early as possible — most policies require prompt notice, and many carriers bring breach counsel and response resources you're already paying for. Loop in your attorney; depending on what data was touched, Louisiana's notification obligations and industry rules may apply on a clock.

Then comes the unglamorous core of recovery: the honest inventory. What systems are encrypted? What data may have been exfiltrated? Which backups survived, from when, and are they clean? What's the true rebuild order — which system does the business need Monday morning versus next month? This assessment, not the ransom note, determines every decision that follows.

On paying: that decision belongs to leadership with counsel and carrier at the table. Payment doesn't guarantee working decryption, may carry legal exposure depending on the actor, and does nothing about how they got in. The assessment's job is to give you the factual basis: what's recoverable without paying, at what cost, in what time.

Day two and beyond: rebuild clean, in priority order

The cardinal recovery sin is restoring good data onto a compromised network — reinfection turns a bad week into a bad quarter. Rebuild targets must be verified clean or built fresh: new hosting for public-facing services, rebuilt or reimaged servers for internal ones, restored data validated before reconnection. Nubinity scopes recovery engagements that include clean rebuild targets on its own New Orleans-operated infrastructure when yours can't be trusted yet.

Recovery isn't finished when systems are back — it's finished when the entry point is closed and the pattern can't repeat: managed endpoint protection with anti-ransomware controls on every device, firewall policy that kills exposed remote access, MFA through single sign-on, and backups that are separated, offline or immutable, and actually test-restored.

Questions

Common follow-ups.

Should we call the police or FBI?

Report to the FBI's IC3 (ic3.gov) — federal reporting sometimes surfaces known decryptors for specific ransomware families, and your carrier or counsel may require it. Expect documentation value more than rescue; recovery remains your project either way.

Our backups were encrypted too. Is everything lost?

Not necessarily. Cloud service data (hosted email, SaaS applications) often survives independently; older offline copies may exist; some ransomware families have public decryptors; and some data can be rebuilt from counterparties — invoices from your accountant, statements from your bank. The assessment establishes what's genuinely gone before anyone declares defeat.

How do we know when it's safe to reconnect systems?

When the entry point is identified and closed, rebuilt systems are verified clean, credentials are rotated, and monitoring is watching for re-entry — not when things merely look quiet. Attackers routinely persist through sloppy recoveries; verification is a checklist, not a feeling.