SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

The real question in a ransomware attack is what you are returning to.

A ransomware attack begins as a security incident and continues as a continuity crisis. This page addresses the second half: how to come back cleanly once the estate is encrypted.

Having a backup is not enough. Attackers usually target backups first, and a recovery plan has to assume that from the outset.

Isolated and immutable copies

Recovery rests on a copy that cannot be deleted and is reached independently of production identity. If a production administrator's credentials can reach that copy, so can an attacker.

  • The copy is reached through a separate identity and path
  • Deletion and encryption attempts are technically refused
  • Copy integrity is verified on a schedule
  • Retention exceeds the time an intrusion takes to surface

A clean recovery environment

Restoring into an encrypted network invites the attacker back in. Recovery starts in a separate, clean environment, and systems return to production only after verification.

  • The clean environment is prepared in advance, not during the crisis
  • Identity infrastructure is rebuilt first and clean
  • A restored system is not attached to the network unverified
  • Return to production waits until persistence checks complete

Restore order

Which service comes back first is far too important to debate during an attack. The order is set in advance against business impact, and identity and network layers sit at the head of nearly every chain.

  • The order is written before the attack and proven in rehearsal
  • Partial service beats waiting for full service
  • The data loss window is expressed to the business as a number
  • A manual workaround plan covers the interim

Decision chain and communication

Whether to pay is not an IT decision. Decision owners, legal and communication roles are defined in advance, and notification duties and their deadlines belong in the plan.

  • The chain is reachable outside working hours
  • A notification clock starts when the incident is confirmed, not when it ends
  • Staff receive an internal message before customers do
  • Wiping a machine can destroy the evidence a claim depends on

How we work

  1. Establish the scope of isolated copies
  2. Prepare the clean recovery environment in advance
  3. Write the restore order against business impact
  4. Define the decision and notification chain
  5. Prove the scenario through rehearsal

How success is measured

  • Critical data has an isolated copy and it is verified
  • The clean environment exists and has been exercised
  • Restore order is confirmed by rehearsal
  • Notification duties are listed with their deadlines

Frequently asked questions

We have backups — isn't that enough?

Backups are necessary but not sufficient. What decides is whether they are isolated from the attacker, restorable into a clean environment, and whether the return order is known.

Should the ransom be paid?

That is a legal and executive decision, not one for a technical team. The plan's job is to make the decision easier: how realistic the option of recovering without paying actually is should already be measured.

Why is this separate from the security pages?

The security side covers preventing and detecting an attack. This page covers what follows one — clean return and the continuity decisions around it.

Do you know today what you would return to from an encrypted estate? Let's start with the scope of your isolated copies.

Review your isolated copies