triplicate

Blog

Ransomware recovery for small businesses

Files padlocked by ransomware, with a clean copy restored from backup

Ransomware is no longer something that happens only to hospitals and large companies. Small offices, clinics, CA firms, schools and shops are attractive targets precisely because they tend to have weaker defences and fewer people watching. When it hits, the quality of your backups decides whether you lose a day or lose the business.

This post covers what to do during an incident and, more usefully, what to put in place beforehand.

How a typical attack unfolds

Most ransomware incidents follow a familiar pattern:

  1. Initial access. A phishing email, a reused password on a remote desktop service, or an unpatched device exposed to the internet.
  2. Quiet exploration. The attacker looks around, collects passwords and finds file servers and backups. This can last days or weeks.
  3. Backup sabotage. Backups connected to the network are deleted or encrypted. Cloud backup consoles are logged into with stolen credentials.
  4. Encryption. Files across the network are encrypted, often overnight or on a weekend.
  5. Extortion. A ransom note demands payment, and increasingly threatens to publish stolen data as well.

Step 3 is the one that matters most for this post. If your backups survive it, you have options.

The first hours

If you see a ransom note or files suddenly renamed with odd extensions:

Contain

  • Disconnect affected machines from the network. Unplug network cables and turn off Wi-Fi. Do not switch them off yet if you can avoid it; memory can hold useful evidence.
  • Disable remote access (VPN, remote desktop, remote support tools) until you know how the attacker got in.
  • Change passwords from a clean device, starting with email, admin and backup accounts.

Assess

  • Which systems are affected? Which are not?
  • Are your backups intact? Check them from a clean device, and do not connect backup drives to infected machines.
  • When did the encryption start? Your recovery point needs to be from before the attacker got in, not just before the encryption.

Report and get help

  • In India, report cybercrime at the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline.
  • CERT-In’s 2022 directions require many organisations to report certain types of cyber incidents, including ransomware, within six hours of noticing them. Check whether this applies to you.
  • If you have cyber insurance, call the insurer early; they often have incident response partners and conditions you need to follow.
  • If customer personal data may have been accessed, you may also have breach notification obligations. Get legal advice.

To pay or not to pay

This is a business decision, and an unpleasant one. Things to weigh:

  • Payment does not guarantee a working decryption key, and decryption can be slow and incomplete.
  • Paying does not stop the attacker from publishing or selling stolen data.
  • Paying may mark you as a willing target.
  • Payments may raise legal issues depending on who the attacker is.

The best position is never to need to consider it, because you can restore.

Recovery from backups

Restoring after ransomware is different from restoring after a disk failure:

  1. Rebuild, do not just clean. Reinstall operating systems on affected machines rather than trusting that the malware is gone.
  2. Restore from a point before the intrusion. Attackers may have planted backdoors days earlier. You may need an older backup than you expect, which is why retention of weeks or months matters.
  3. Restore critical systems first. Billing, accounting, the main database. Have this order decided in advance.
  4. Scan restored data before putting it back into use.
  5. Reset all credentials, including service accounts and API keys.

Ransomware recovery is a restore test you did not schedule. The time to find out how long a full restore takes is before you need one.

Preparing beforehand

Backups the attacker cannot reach

  • Keep at least one copy that is immutable (object lock with a retention period) or offline. An attacker with your admin password should still not be able to delete it.
  • Use separate credentials for backup storage, not your domain admin or main email login. Use write-only keys where the tool supports it.
  • Keep a copy off-site and ideally with a different provider, so one compromised account does not expose everything.

Retention long enough to go back

Daily backups kept for a week may not reach back to before the intrusion. A common pattern is daily backups for 30 days, weekly for three months and monthly for a year. Adjust for your size and budget.

Basic hygiene

  • Turn on two-factor authentication for email, remote access and any admin console.
  • Do not expose remote desktop directly to the internet.
  • Keep operating systems and routers updated.
  • Give staff the access they need and no more.

A written plan

One page is enough:

  • who to call (IT support, insurer, lawyer)
  • where backups are and how to access them from a clean machine
  • the order in which systems should be restored
  • where the passwords for backup accounts are kept (not only on the office server)

Practise

Once or twice a year, restore one important system to a spare machine and time it. Note what was missing or confusing, and fix it.

Closing note

triplicate is building business backup with object lock for immutable copies, two independent regions on different storage providers, and an S3-compatible endpoint for tools such as restic and Veeam. Pricing is prepaid, with a ₹200 monthly minimum. We are not live yet; see pricing or talk to us.

Keep reading