Ransomware is no longer something that happens only to hospitals and large companies. Small offices, clinics, CA firms, schools and shops are attractive targets precisely because they tend to have weaker defences and fewer people watching. When it hits, the quality of your backups decides whether you lose a day or lose the business.
This post covers what to do during an incident and, more usefully, what to put in place beforehand.
How a typical attack unfolds
Most ransomware incidents follow a familiar pattern:
- Initial access. A phishing email, a reused password on a remote desktop service, or an unpatched device exposed to the internet.
- Quiet exploration. The attacker looks around, collects passwords and finds file servers and backups. This can last days or weeks.
- Backup sabotage. Backups connected to the network are deleted or encrypted. Cloud backup consoles are logged into with stolen credentials.
- Encryption. Files across the network are encrypted, often overnight or on a weekend.
- Extortion. A ransom note demands payment, and increasingly threatens to publish stolen data as well.
Step 3 is the one that matters most for this post. If your backups survive it, you have options.
The first hours
If you see a ransom note or files suddenly renamed with odd extensions:
Contain
- Disconnect affected machines from the network. Unplug network cables and turn off Wi-Fi. Do not switch them off yet if you can avoid it; memory can hold useful evidence.
- Disable remote access (VPN, remote desktop, remote support tools) until you know how the attacker got in.
- Change passwords from a clean device, starting with email, admin and backup accounts.
Assess
- Which systems are affected? Which are not?
- Are your backups intact? Check them from a clean device, and do not connect backup drives to infected machines.
- When did the encryption start? Your recovery point needs to be from before the attacker got in, not just before the encryption.
Report and get help
- In India, report cybercrime at the National Cyber Crime Reporting Portal (cybercrime.gov.in) or the 1930 helpline.
- CERT-In’s 2022 directions require many organisations to report certain types of cyber incidents, including ransomware, within six hours of noticing them. Check whether this applies to you.
- If you have cyber insurance, call the insurer early; they often have incident response partners and conditions you need to follow.
- If customer personal data may have been accessed, you may also have breach notification obligations. Get legal advice.
To pay or not to pay
This is a business decision, and an unpleasant one. Things to weigh:
- Payment does not guarantee a working decryption key, and decryption can be slow and incomplete.
- Paying does not stop the attacker from publishing or selling stolen data.
- Paying may mark you as a willing target.
- Payments may raise legal issues depending on who the attacker is.
The best position is never to need to consider it, because you can restore.
Recovery from backups
Restoring after ransomware is different from restoring after a disk failure:
- Rebuild, do not just clean. Reinstall operating systems on affected machines rather than trusting that the malware is gone.
- Restore from a point before the intrusion. Attackers may have planted backdoors days earlier. You may need an older backup than you expect, which is why retention of weeks or months matters.
- Restore critical systems first. Billing, accounting, the main database. Have this order decided in advance.
- Scan restored data before putting it back into use.
- Reset all credentials, including service accounts and API keys.
Ransomware recovery is a restore test you did not schedule. The time to find out how long a full restore takes is before you need one.
Preparing beforehand
Backups the attacker cannot reach
- Keep at least one copy that is immutable (object lock with a retention period) or offline. An attacker with your admin password should still not be able to delete it.
- Use separate credentials for backup storage, not your domain admin or main email login. Use write-only keys where the tool supports it.
- Keep a copy off-site and ideally with a different provider, so one compromised account does not expose everything.
Retention long enough to go back
Daily backups kept for a week may not reach back to before the intrusion. A common pattern is daily backups for 30 days, weekly for three months and monthly for a year. Adjust for your size and budget.
Basic hygiene
- Turn on two-factor authentication for email, remote access and any admin console.
- Do not expose remote desktop directly to the internet.
- Keep operating systems and routers updated.
- Give staff the access they need and no more.
A written plan
One page is enough:
- who to call (IT support, insurer, lawyer)
- where backups are and how to access them from a clean machine
- the order in which systems should be restored
- where the passwords for backup accounts are kept (not only on the office server)
Practise
Once or twice a year, restore one important system to a spare machine and time it. Note what was missing or confusing, and fix it.
Closing note
triplicate is building business backup with object lock for immutable copies, two independent regions on different storage providers, and an S3-compatible endpoint for tools such as restic and Veeam. Pricing is prepaid, with a ₹200 monthly minimum. We are not live yet; see pricing or talk to us.
Keep reading
RPO and RTO explained
Recovery Point Objective and Recovery Time Objective in plain terms, how to pick sensible values, and how they shape your backup design and costs.
3-2-1-1-0: immutable backups and verified restores
The extended backup rule adds one offline or immutable copy and zero errors after verification. What each addition means and how to put it into practice.
Backup vs sync: why Google Drive, iCloud and OneDrive are not backups
Sync keeps files identical everywhere, including your mistakes. Backup keeps older copies you can return to. The difference matters when things go wrong.