CTS - Computer Technology Specialists

Ransomware Recovery Playbook

When ransomware hits, the first 30 minutes are critical — the decisions made in that window determine whether the attack expands across the network or is contained to a recoverable scope.

Melbourne IT support with visible local credentials

CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.

Certifications, affiliations and technology partners

Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.

Step 1 — Detection and initial assessment

Ransomware is typically detected through one of three signals: an employee reports encrypted files and a ransom note, the monitoring platform alerts on unusual file activity or encryption behaviour, or the backup system reports unexpected failures. The first action is to determine the scope — which systems appear affected, whether network shares are showing mass encryption, and whether the attack is still in progress or has completed. This assessment must be done without using potentially infected systems as the investigation tool.

Step 2 — Isolation procedures

The objective of isolation is to stop ransomware from spreading to additional systems and, critically, to backup targets. Affected systems should be disconnected from the network immediately — physically unplug the network cable or disable the network interface, rather than relying on remote management tools that may themselves be compromised. If the attack appears to be spreading, shutting down network switches affecting infected segments may be necessary. Do not turn off infected servers before taking a forensic image if law enforcement involvement or insurance claims are anticipated — running memory may contain decryption keys or attacker tools.

Step 3 — Escalation and incident response

Notify the IT provider and incident response team immediately. If a cyber insurance policy is in place, call the insurer's incident response line — most policies include access to a forensics firm and legal counsel as part of the coverage. Do not pay a ransom without legal and insurance advice — ransom payments may violate sanctions obligations, and paying does not guarantee decryption. Preserve evidence: network logs, event logs, and any attacker communications. If client data may have been exfiltrated, consider obligations under the Notifiable Data Breaches scheme.

Step 4 — Backup assessment and clean restore

The most important question in a ransomware recovery is: do we have clean backups predating the infection? Verify that backup data is accessible and that the most recent clean backup predates the ransomware infection — some ransomware strains dwell in the network for weeks before triggering encryption, meaning recent backups may contain the malware. Immutable backups with long retention are critical here. If backups are confirmed clean, begin restore according to the documented recovery sequence — critical business systems first, then secondary systems.

Step 5 — Environment rebuild and validation

Restoring encrypted files is not the same as recovering the environment. The attacker's initial access vector must be identified and closed before systems are brought back online — otherwise recovery becomes a cycle. CTS recommends rebuilding to a new clean environment rather than restoring to the same infrastructure where possible. Validate each restored system for normal operation and confirm no residual malware presence before reconnecting to the network.

Step 6 — Post-incident review and hardening

After operations are restored, conduct a structured post-incident review. Document the attack timeline, initial access vector, lateral movement path, and recovery steps. Update the incident response plan with lessons learned. Implement any security controls that would have prevented or limited the attack. If the initial access was a phishing email, review email security policies. If it was an unpatched vulnerability, review patch management processes. Notify your insurer of the final outcome and provide the forensic report.

Frequently asked questions

Should we pay the ransom?

CTS's position is that ransom payment should not be the first response. Paying does not guarantee decryption, may expose you to sanctions liability if the attacker is a sanctioned entity, and does not address the underlying security gap. If you have tested backups, recovery without payment is typically faster and more reliable. If the data is truly unrecoverable and critical, get legal and insurance advice before making any payment decision.

How do we know if our backups are actually clean?

Backup validation requires checking the backup timestamps against the estimated infection date, confirming that backup storage was not accessible from infected systems (immutable or offsite backups), and performing a test restore to an isolated environment to verify the restored files are functional and not encrypted. This is why CTS recommends annual restore tests — confirming backup integrity before a crisis is significantly less stressful than discovering backup problems during one.

Related case studies

Related CTS services

Share this page