Isolated and immutable copies
Recovery rests on a copy that cannot be deleted and is reached independently of production identity. If a production administrator's credentials can reach that copy, so can an attacker.
- The copy is reached through a separate identity and path
- Deletion and encryption attempts are technically refused
- Copy integrity is verified on a schedule
- Retention exceeds the time an intrusion takes to surface
A clean recovery environment
Restoring into an encrypted network invites the attacker back in. Recovery starts in a separate, clean environment, and systems return to production only after verification.
- The clean environment is prepared in advance, not during the crisis
- Identity infrastructure is rebuilt first and clean
- A restored system is not attached to the network unverified
- Return to production waits until persistence checks complete
Restore order
Which service comes back first is far too important to debate during an attack. The order is set in advance against business impact, and identity and network layers sit at the head of nearly every chain.
- The order is written before the attack and proven in rehearsal
- Partial service beats waiting for full service
- The data loss window is expressed to the business as a number
- A manual workaround plan covers the interim
Decision chain and communication
Whether to pay is not an IT decision. Decision owners, legal and communication roles are defined in advance, and notification duties and their deadlines belong in the plan.
- The chain is reachable outside working hours
- A notification clock starts when the incident is confirmed, not when it ends
- Staff receive an internal message before customers do
- Wiping a machine can destroy the evidence a claim depends on