Restore a school’s systems only after responders have contained the incident, assessed what was affected, and prepared a clean recovery environment. Bring services back in an order based on student and staff safety, essential school operations, and the dependencies each service needs—not simply which systems are easiest to restore.
What should happen before a school restores systems?
Recovery is part of incident response, not a standalone IT task. Follow the school or district’s incident-response plan, assign clear roles, and coordinate technical decisions with school leadership and the people handling communications. CISA’s January 2023 K-12 cybersecurity report recommends a written, exercised incident-response plan with assigned roles and senior-leader approval.
Contain the incident
Identify affected devices, accounts, servers, and network areas, then isolate what is compromised or at risk. If evidence suggests the attack has spread across a wider area, responders may need to isolate a network segment rather than handle devices one at a time. Avoid reconnecting affected systems just to make services available sooner.
Establish scope and preserve evidence
Use available endpoint and network evidence, along with relevant logs, to understand what was accessed or changed and whether the compromise extends beyond the systems first noticed. Preserve useful and, where possible, volatile evidence before rebuilding or wiping devices. Coordinate with experienced incident responders or law enforcement when appropriate; recovery actions should not unnecessarily destroy evidence that may help determine the scope of the incident.
Recommended Free Tools
#1 Best Overall
Which school systems should be restored first?
Use the school’s critical-asset list to rank services by their importance to health and safety, core operations, and other critical services. Then map the dependencies each service requires. For example, a school application may rely on identity, network, or data services; restoring the application alone will not make it safely usable if a required dependency remains compromised or unavailable.
CISA’s #StopRansomware Guide recommends prioritizing recovery based on critical services and dependencies. Make the resulting order explicit, share it with the incident coordinator and school leaders, and adjust it as responders learn more about the incident.
Rank #2
- Used Book in Good Condition
How can a school tell whether its backups are safe to use?
A backup is useful only if it is available, intact, and suitable for a clean recovery. CISA recommends keeping backups of critical data offline and encrypted, and regularly testing their availability and integrity in a disaster-recovery scenario. Its K-12 report also recommends testing both partial and full data restoration and documenting offline backups in a written plan.
- Keep backup copies disconnected from the network when they are not actively being used for backup or recovery.
- Use encryption and restrict access to backup data.
- Test that copies can be accessed and that restored data is usable, including through partial and full restoration exercises.
- Maintain current golden images for critical systems where appropriate, so systems can be rebuilt from known configurations.
- Include critical data, system images, and the dependencies needed to operate restored services in recovery planning.
A removable external drive can be one way to hold an offline copy, but it is not a recovery plan by itself. CISA advises disconnecting an external drive when it is not actively being used for backup because an attacker may be able to access, delete, or corrupt connected data. The cited CISA guidance does not rank backup products or specify a preferred brand, storage medium, or cloud vendor.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
How should systems be rebuilt and restored?
Prepare a clean recovery environment that is separated from potentially compromised systems. Keep affected systems out of that environment, and scan or otherwise validate backup data where possible before using it. Rebuild systems from maintained golden images where appropriate, then restore the data and services needed for the prioritized recovery plan.
CISA’s #StopRansomware Guide (September 2023) puts the order plainly: “Reconnect systems and restore data from offline, encrypted backups based on a prioritization of critical services.” The sequence matters: verify the recovery source and environment, then restore according to service priority and dependencies.
Rank #4
- SECURITY & SD-WAN PERFORMANCE: Meraki MX75-HW cloud-managed appliance delivers up to 1 Gbps firewall throughput and 500 Mbps VPN throughput, supporting small branch deployments with up to 200 users.
- ADVANCED THREAT PROTECTION: Integrated intrusion prevention, advanced malware protection, and content filtering safeguard your network against evolving cyber threats.
- CLOUD-MANAGED SIMPLICITY: Zero-touch provisioning and centralized management via the Meraki Dashboard for seamless configuration, monitoring, and troubleshooting.
- APPLICATION-AWARE CONTROL: Layer 7 traffic shaping prioritizes critical applications like voice and video while optimizing overall network performance.
- BUILT-IN SD-WAN & VPN: Simplifies multi-site connectivity with intelligent path control, automatic failover, and secure site-to-site VPN.
When is it safe to reconnect restored systems?
Reconnect deliberately rather than bringing the entire network back at once. Add only systems that have been checked and prepared for recovery, then monitor them as they return to service. Watch for signs of renewed suspicious activity and be ready to isolate a system again if needed. CISA specifically warns organizations to avoid reinfecting clean systems during recovery.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should the school handle communication and follow-up?
Keep leadership informed about service status, recovery priorities, and material changes in the incident’s scope. Coordinate accurate updates for staff, families, and other affected groups. Cyber incidents can interrupt learning, including remote learning, and attackers may steal and threaten to disclose confidential student data, as CISA’s school ransomware and remote-learning resource warns.
Best Value
- SonicWALL TZ500 Network Security/Firewall Appliance
- Intrusion Prevention, Malware Protection, Application Control, Content Filtering, Spyware Protection, URL Filtering, Denial of Service (DoS), Stateful Packet Filtering, Signature-based Intrusion Prevention, Distributed Denial of Service (DDoS) - 8 Port - 10/100/1000Base-T Gigabit Ethernet - DES, 3DES, MD5, SHA-1, AES (128-bit), AES (192-bit), AES (256-bit) - USB - 8 x RJ-45 - Manageable - Power Supply - Desktop
- TZ500 Network Security FirewallExpand, control and protect your network.A fast connection to your business, school, remote office or retail site is only half the story; you also need to be able to securely manage it. The TZ500 and TZ600 give you enterprise-grade protection to stop cyberattacks as you expand and control your network.
- TZ500 TotalSecure 1YRDell SonicWALL TZ500 Appliance with 1 year of Comprehensive Gateway Security Suite and 24x7 Support
- SonicWALL 01-SSC-0445
Follow the school’s applicable breach-notification procedures and requirements. Those duties vary by jurisdiction and circumstances, so this guidance does not establish which notifications are required or when they are due. After services are restored, document what happened and use the lessons to update the incident-response plan and future exercises.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

