Scenario

The scenario that makes a backup useless.

Modern ransomware does not encrypt first. It takes administrative rights, hunts for the backups, deletes or encrypts them, and only then triggers. The question is not whether you back up, but whether your backups survive someone holding your own rights.

The situation

The most common case in mid-sized firms: backups sit on a network share or on the same hypervisor, reachable with the domain administrator account. The setup is sound against hardware failure and useless against an attack.

The second case: backups are properly separated, but nobody has ever checked that the restart order is known. The application is restored before the authentication service, it does not start, and hours go into working out why while the business is down.

The third, and the most expensive: the decisions were not made in calm conditions. Who decides to disconnect the network, who talks to clients, who calls the insurer, from what point you declare. Those calls made in a panic cost more than the technical work.

What has to be prepared beforehand

None of these items can be put in place during an incident.

  • A copy administration cannot reach

    Outside the domain, with separate credentials, ideally non-rewritable for a fixed period. This is the one genuinely non-negotiable point.

  • A tested restart order

    Dependencies between services established and verified during a drill, not inferred from an architecture diagram.

  • Located emergency access

    The credentials needed for recovery, kept outside the system they serve to restore, with an access procedure known to more than one person.

  • A written decision chain

    Who decides what, in what order, and who notifies the insurer and the competent authorities. Established calmly and known to the people concerned.

  • An available restore environment

    Enough capacity to restore without reusing the compromised infrastructure, which you do not yet know to be clean.

Our position on paying a ransom

We do not advise on paying a ransom, do not act as an intermediary and take no part in a negotiation. Those questions belong to your management, your insurer, legal counsel and the competent authorities. Our work is to make sure the question comes up as rarely as possible.

Request an assessment

Start by knowing where you stand

Tell us which applications you cannot lose, how long you could hold out without them, and when a restore was last actually tested. We reply within two working days.

  • Swiss engineering
  • Reply within two working days

Email Contivaro

Tell us when a restore was last tested. If the answer is “never”, let’s start there.

Email Contivaro