Ransomware Recovery Order of Operations: What Comes Back First

When everything is down, the order you restore systems matters. Here is how contractors and energy firms can sequence recovery to restart the business faster.

3 min readBy Ironfield Cyber Team

When ransomware hits, the instinct is to restore everything at once. That instinct costs time. Backup storage and network bandwidth are finite, and restoring low-value systems first can delay the ones that actually let you pay people, bill customers and run crews.

The fix is to decide the order before the emergency. A written restore sequence turns a chaotic day into a checklist, and it forces leadership to agree on priorities while nobody is panicking.

Start With the Foundation, Not the Applications

Applications depend on identity, networking and name resolution. If you bring up your accounting server before the systems it relies on, it will start but nobody can log in. A sensible sequence has layers.

Layer 1: A clean place to restore into

Before restoring anything, confirm the attacker is out. Restoring into a compromised environment just feeds the infection. That usually means isolating the network, rebuilding or verifying the identity system, and resetting privileged credentials first.

Layer 2: Identity and core services

Your directory service, whether on-premises Active Directory or Microsoft Entra ID, plus DNS and DHCP, come next. Almost everything else needs them. Rotate every administrative password and any service account secrets at this stage, not later.

Layer 3: Communication

Email and a way to reach staff matter more than most owners expect. If your Microsoft 365 tenant was involved, you may need an out-of-band channel such as a text group or a personal-device chat while you rebuild trust in the main system.

Layer 4: Money and operations

Payroll, accounts payable, job cost and billing systems are next. For a contractor, that means your accounting platform, such as Sage or Viewpoint, and the files that support pay applications. Field crews still need to be paid, and subcontractors and suppliers will call quickly when payments stall.

Layer 5: Everything else

File shares, design workstations, archives and convenience systems come last. Historical project files from closed jobs can wait a week without hurting anyone.

How to Build Your Priority List

Ask each department head one question: what do you need running to avoid losing money or breaking a contract today, this week, and this month? Write the answers down and rank them.

  • Same day: identity, email access, payroll or a manual payroll workaround, dispatch or scheduling.
  • Within three days: accounting, project management data, estimating tools for active bids.
  • Within a week: file shares, secondary applications, reporting.
  • After that: archives, test systems, retired project data.

For each system, record who owns it, where its backup lives, how long a restore is expected to take, and what manual workaround exists in the meantime.

Plan for the Workarounds

Restoration is only half of recovery. Your people need to keep working while systems are rebuilt. Decide ahead of time:

  1. How payroll will run if the system is down for a cycle.
  2. How field crews will receive drawings and schedules, for example from a cloud platform that was not affected or printed sets.
  3. Who is authorized to approve payments manually, and how those approvals are verified by phone, since attackers sometimes watch email during an incident.
  4. How you will communicate with customers and owners about delays.

Test the Sequence

A restore order that has never been tried is a guess. Pick one system from each layer each quarter and restore it into an isolated test environment. Time it. You will almost always find a dependency nobody documented, such as a license server, a service account, or a certificate.

Record the actual times next to your estimates. Those numbers are the real recovery time objectives for your business, and they will show whether your backup storage and bandwidth are adequate.

Common Sequencing Mistakes

  • Restoring before confirming the intruder is gone, leading to reinfection.
  • Forgetting that backups themselves may have been targeted, so verifying that your backup copies are intact and offline or immutable comes first.
  • Restoring the largest file server first because it feels important, then waiting a day for the data to copy.
  • Leaving credential resets until after applications are up.
  • Not having a printed copy of the recovery plan. If your systems are down, so is the document that says what to do.

Getting a Plan on Paper

A restore sequence does not need to be long. One page listing systems in order, owners, backup locations and workarounds is more useful than a thick binder. Ironfield Cyber helps contractors and energy companies build and test these plans, and we are glad to walk through yours and run a restore drill so the first real test is not an actual attack.