Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recover in a controlled sequence: contain affected systems, decide which business services matter most, investigate and remove the attacker’s access, rebuild clean systems, then restore and verify data from known-good backups. Reconnect systems only when they are clean and ready to support prioritized services. Follow your incident response plan and involve qualified responders; restoring too soon can spread the compromise again.

What should you do first after a ransomware attack?

Activate your organization’s incident response plan and bring together the people authorized to make operational and technical decisions. Use that plan to coordinate IT and security teams, leadership, service providers, and communications staff.

  1. Identify and isolate affected systems. Disconnect impacted devices or systems from the network to limit spread. If several systems or subnets appear affected and individual disconnection is not practical, CISA advises taking the affected network offline at the switch level. Follow responders’ advice about the scope of isolation.
  2. Preserve evidence as directed. Work with incident responders to retain relevant logs and other evidence. CISA describes collecting items such as system images, memory, logs, and malware samples when immediate mitigation is not possible; evidence handling should be coordinated with qualified professionals.
  3. Do not reconnect systems just because encryption has stopped. An encryption screen disappearing does not establish that an attacker has lost access or that a system is safe to use.

See the recovery and response guidance in CISA’s #StopRansomware Guide, revised October 19, 2023. Its publication record provides the revision date and publication context.

Which business operations should you restore first?

Prioritize services by business impact and by the dependencies required to run them. CISA identifies health and safety, revenue generation, other critical services, and the systems those services depend on as restoration priorities. There is no universal order: a service’s priority depends on your organization’s obligations, operations, and available workarounds.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
  • Bundle: 4 locks + 1 key.
  • Easy to Use: It can be installed by hand.
  • All-Purpose Key: A common key can be used to unlock 9 different products within the Essential series.
  • List disrupted business services and name their owners.
  • Assess impact on safety, legal or contractual obligations, revenue, and customers.
  • Map the identity, network, data, applications, and other services each priority operation needs.
  • Record available workarounds and use them to help manage operations while systems are unavailable.

Use this dependency view to avoid restoring a business application before a prerequisite identity, network, or data service is trustworthy and available.

How do you determine whether the attacker is still in the environment?

Before rebuilding or restoring, work with qualified incident responders to establish the extent of the compromise. CISA cautions that ransomware can follow an earlier, unresolved intrusion, so removing the visible malware alone may not remove the attacker’s access.

  • Review available endpoint, network, identity, and security logs.
  • Investigate how the attacker entered and look for persistence, stolen credentials, and other affected systems.
  • Coordinate evidence collection with responders while limiting further damage.

Use the findings to decide what must be contained, rebuilt, or secured before restoration proceeds. The aim is to avoid bringing compromised systems or access paths back into service.

How should you rebuild systems and restore data?

Build a clean foundation first, then restore in an order that supports the services you prioritized. CISA recommends using preconfigured standard images where possible, reconnecting systems according to critical-service priorities, and avoiding the addition of anything but clean systems to a recovery network.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Prepare the recovery environment. Rebuild systems using known-good standard images or infrastructure-as-code templates where available. Validate identity services, administrative accounts, network controls, endpoint protection, and access to backups before reconnecting restored workloads.
  2. Select known-good backups. Choose backups believed to predate the compromise and verify their integrity. CISA recommends offline, encrypted backups; keep recovery copies isolated from ransomware spread.
  3. Restore by service priority and dependency. Restore the systems and data needed for priority services, rather than reconnecting everything at once. NIST recommends planning, implementing, and regularly testing restoration.
  4. Test actual business use. Check that restored data is complete and usable, the application works, and business owners can carry out representative workflows before declaring the service operational. Define checks appropriate to each system; there is no single validation checklist for every organization.

CISA’s recovery guidance says to “Reconnect systems and restore data from offline, encrypted backups based on a prioritization of critical services.” Read the NIST Tips and Tactics: Preparing Your Organization for Ransomware Attacks for additional recovery-planning and backup-testing guidance.

How should you resume operations and communicate?

Bring services back in controlled stages, monitoring for renewed suspicious activity as restored systems reconnect. Keep a record of decisions and recovery milestones. Follow the organization’s incident response and communications plans to share service status, limitations, and workarounds with employees, customers, and partners as appropriate.

Involve leadership, IT, service providers, insurers, law enforcement, and relevant government response resources as appropriate to the incident. If personal or other protected data was breached, follow applicable notification requirements. Those requirements vary by jurisdiction and sector; general incident guidance is not a substitute for legal advice tailored to your organization.

Use your organization’s established criteria to decide when the incident is over, with IT and security authority and external responders involved as appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should you review after recovery?

Document what happened, how recovery decisions were made, which dependencies delayed restoration, and whether backups could be restored successfully. Use those findings to update incident response, continuity, backup, communications, and vendor-contact plans, then exercise the revised procedures. NIST advises organizations to develop an incident recovery plan with defined roles and decision-making strategies and to exercise it regularly.

How can you prepare for a more dependable recovery?

  • Keep an up-to-date inventory of critical physical and logical assets, their owners, and their dependencies.
  • Maintain offline, encrypted backups of critical data, and regularly test their availability and integrity in a disaster recovery scenario.
  • Maintain tested system images and recovery templates, with access to required software, licenses, and hardware where appropriate.
  • Define recovery roles, approval authority, communications responsibilities, and escalation contacts.
  • Keep incident contacts current, including internal leadership, IT, managed security providers, insurers, law enforcement, and relevant government support.
  • Exercise a ransomware scenario and test actual restoration, not just whether a backup job completed.

NIST’s Ransomware Protection and Response publications index was updated June 11, 2026, and lists NIST IR 8374 Rev. 1 as final, released June 11, 2026. Consult the official index for publication status and newer guidance.

Quick Recap

Bestseller No. 1
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key
Bundle: 4 locks + 1 key.; Easy to Use: It can be installed by hand.
$34.82

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.