Most ransomware recoveries are decided before the attack, by whether a clean copy of your data still exists. This checklist covers what to set up now, what to do in the first hour, and how to restore without bringing the infection back.
Before an attack
- Keep at least one copy that cannot be deleted. Lock recent backups for a set period, or keep one copy disconnected. Attackers look for backups first.
- Keep backup access separate. Use a different login for your backup console than for your servers, with multi-factor sign-in, so one stolen password does not open both.
- Know what you would restore first. Write down the three or four machines and folders the business cannot run without, in order.
- Test a restore. Restore a real folder to a different location and open the files. Do it once a quarter.
- Print a contact list. Your IT support, your backup provider, your bank and your insurer. If the network is down, a list on a computer does not help.
In the first hour
- Disconnect, do not wipe. Unplug affected machines from the network and turn off their Wi-Fi. Do not reinstall or wipe anything yet: you may need it to work out how the attack got in.
- Check your backups are intact. Sign in to your backup console from a clean device and confirm your recent copies are still there. If you can, look at its audit trail for changes you did not make.
- Report it. Under CERT-In's 2022 directions, companies in India must report cyber security incidents to CERT-In within six hours of noticing them. CERT-In's website explains how. If personal data was affected, the DPDP Rules add a duty to tell the Data Protection Board and the people affected, from 13 May 2027.
- Change passwords from a clean device. Start with email, the backup console and any administrator accounts.
- Get advice before paying anything. Paying does not guarantee you get your data back, and it may not be lawful in every case.
Restoring
- Pick the last clean copy, not the latest one. Ransomware often sits quietly for days before it encrypts anything. Choose a copy from before the first sign of trouble.
- Restore onto clean machines. Restore onto rebuilt or new machines, not onto the infected ones, or the infection can come straight back.
- Work down your list. Restore what the business needs first, check the files open, then move to the next.
- Reconnect last. Bring machines back onto the network only once they are clean.
Afterwards
- Find out how the attack got in, and close that route.
- Check whether your locked period was long enough. If the attackers were inside for longer than it, lengthen it.
- Write down what happened and what you changed. It will help the next time someone asks.
Where Satkosh fits
Satkosh does not detect or block ransomware. That is the job of antivirus and endpoint security. What it does is make sure a clean copy survives: backups are encrypted before they leave the machine, recent copies can be locked so nobody can delete them, even with your passwords, and you can restore onto a brand new machine when the old one cannot be trusted. Logins, restores and changes are recorded in an audit trail.
Sources: the CERT-In directions of 28 April 2022 under section 70B(6) of the IT Act, and Trilegal's summary of them. This is not legal advice.