PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Recovering from an enterprise data breach means more than restoring files or restarting servers. First establish what was compromised and contain it; then remove attacker persistence, rebuild trusted systems and identity services, restore verified data in a controlled order, and close the security gaps the incident exposed. The right sequence depends on whether the event involved data exposure, ransomware or destructive activity, or compromised identity infrastructure.
Start with scope, command, and evidence
Activate the organization’s approved incident response plan and establish secure communications for the response team. Assign owners, record decisions and timestamps, and keep a shared incident record of findings, status, and outstanding actions. NIST’s SP 1800-29, published February 23, 2024, frames data-breach guidance around detecting, responding to, and recovering from data confidentiality attacks. It is a guide and example implementation, not a universal playbook.
Build an initial picture of affected users, devices, applications, data, and access paths. Identify likely initial access and determine whether the incident involves unauthorized access or disclosure, encryption, destructive activity, or a combination. Preserve relevant logs and, when appropriate, system images and memory. Prioritize evidence that may be lost through short retention periods or routine system changes.
Containment should be based on the scope, risk of spread, critical operations, and incident responders’ assessment. Isolate confirmed compromised endpoints and servers, but do not assume that disconnecting every system is always the safest move; it can disrupt essential operations or complicate investigation.
#1 Best Overall
Contain access and protect identity infrastructure
Assess how the intruder could enter or move through the environment. Review VPN and other remote access, single sign-on, cloud assets, privileged accounts, and identity services for abuse. CISA’s #StopRansomware Guide advises identifying the systems and accounts involved in the initial breach and describes disabling remote access pathways where warranted. Apply those steps to the incident at hand rather than treating them as automatic actions.
Identity deserves special attention because it can control access to the systems being restored. If directory services or administrator credentials may be compromised, a normal disaster-recovery restore does not by itself establish that the environment is trustworthy. Microsoft’s Planning for compromise guidance is particularly relevant to organizations using Active Directory Domain Services (AD DS): identify and preserve known-good domain controllers, and plan compromise recovery if AD DS may have been affected.
Rank #2
Eradicate attacker access before rebuilding
Investigate persistence and lateral movement before declaring systems clean. A machine that appears to work normally may still contain an attacker’s foothold, and rebuilding only the most visibly affected device can leave access elsewhere in the environment. Coordinate the investigation and remediation with incident responders, especially when the affected systems support critical services or identity.
Free tools Windows power users keep installed
One-click scans. No signup required.
Prioritize services according to business and operational needs. Rebuild affected systems from known-good standard images where suitable; cloud teams may use trusted infrastructure-as-code templates to create consistent replacements. Apply relevant patches and address security or visibility gaps found during the incident. Establish and document the criteria responders will use to declare the incident contained and the environment ready for recovery.
Rank #3
Restore verified data in a controlled order
Before restoring, check the recovery environment: only clean systems should join it, and restored systems should not reconnect to infrastructure that remains untrusted. Validate backup integrity and restoration procedures, then use protected backups—including offline backups where available—to recover services according to their priority. Microsoft’s ransomware incident response guidance recommends checking whether tested backups cover application, configuration, and data needs.
Restore and reconnect in a controlled sequence. Monitor for renewed suspicious activity as services return, and pause or reassess if signs of compromise reappear. Recovery is not complete merely because a backup has been copied back: the systems, configurations, identities, and access paths supporting the service must also be sufficiently trusted.
Rank #4
Remediate identities and credentials after cleanup
Inventory affected accounts and credentials, including privileged identities and accounts used for remote or cloud access. Remove malicious persistence and unauthorized access, clean or rebuild affected systems, and coordinate the timing and order of credential resets with incident responders. Resetting credentials too early—before the foothold or persistence is removed—can give an attacker an opportunity to regain access. Update customer-managed encryption keys where relevant.
For future protection, expand multifactor authentication coverage and prioritize phishing-resistant MFA for high-impact services such as email, VPN, and critical systems. CISA’s guide includes cryptographic keys among examples of phishing-resistant factors; it does not endorse a particular product or establish compatibility for a specific organization. Strengthen privileged access practices and monitoring around the attack paths confirmed in the incident.
Best Value
Harden the environment and update response plans
Use the incident’s confirmed causes and access paths to guide improvements rather than applying an unrelated checklist indiscriminately. Review patching, asset visibility, segmentation, privileged access, authentication, and monitoring. Test restoration procedures against the applications, configurations, and data that services actually require. NIST’s SP 1800-26, finalized December 8, 2020, provides an additional enterprise perspective on detecting and responding to data-integrity attacks, including ransomware and other destructive events.
Record lessons learned, update the incident response plan and communications plan, and exercise them. CISA’s joint guide with MS-ISAC, NSA, and FBI recommends organizations “Create, maintain, and regularly exercise a basic cyber incident response plan (IRP) and associated communications plan.”
Match the guidance to the incident
| Incident context | Primary recovery emphasis | How to use the guidance |
|---|---|---|
| Data confidentiality breach | Detecting, responding to, and recovering from unauthorized access to or disclosure of data | NIST SP 1800-29 is directly focused on data breaches, but is a guide and example implementation rather than a universal response playbook. |
| Ransomware or data extortion | Containment, evidence preservation, eradication, rebuilding, protected backup recovery, and post-incident work | CISA’s #StopRansomware Guide is specifically focused on ransomware and data extortion; adapt its checklist to the event and business needs. |
| Identity or control-plane compromise | Establishing known-good identity services and planning recovery of affected directory infrastructure | Microsoft’s compromise-recovery guidance is vendor-specific and particularly relevant to AD DS environments. |
Handle notifications through the approved plan
Use the organization’s approved communications and notification plan. Notification obligations can depend on jurisdiction, data type, contracts, and sector; the guidance cited here does not establish a deadline for a particular organization. Have the appropriate legal, privacy, security, and communications owners determine what applies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

