Ransomware Recovery Order of Operations: What to Restore First

Restoring everything at once slows recovery. Use this order of operations to bring back identity, finance and field systems in the right sequence.

3 min readBy Ironfield Cyber Team

The first instinct after a ransomware attack is to restore everything as fast as possible. That instinct causes some of the worst recovery mistakes, including restoring infected systems, bringing back services in the wrong order, and reintroducing the attacker's access. A defined order of operations gets you running sooner and keeps you safer.

This guide assumes you have usable backups. If you are not sure that you do, test them before you need them. The sequence below is general guidance, and your environment may need adjustments.

Step zero: stop the spread and secure evidence

Before restoring anything, isolate affected systems from the network and from each other. Do not wipe machines yet. Preserve logs and, where practical, disk images, since your insurer, counsel or investigators may need them. Change credentials for administrators and service accounts from a clean device, not from a machine that might be compromised.

Restore in this order

1. A clean foundation: network and identity

Nothing else is trustworthy until your identity system is. If attackers controlled your directory or Microsoft 365 tenant, they can walk back in after you restore. Rebuild or verify:

  • Domain controllers or cloud identity, including privileged accounts
  • Firewall and router configurations, checked for unauthorized changes
  • MFA enrollment and conditional access policies
  • Remote access paths, which should stay closed until validated

2. Communication and coordination

Your team needs a way to talk that the attacker cannot read. Stand up a clean email path or an alternate channel first. Remember that attackers often monitor email during an incident. Share sensitive recovery details by phone or in a channel you know to be clean.

3. Financial and payroll systems

Payroll deadlines and vendor payments do not pause. Restoring the accounting platform, whether Sage, Viewpoint or another system, protects cash flow. Verify data integrity before resuming transactions, and watch for tampering with vendor banking details, which attackers sometimes alter during an intrusion.

4. Project and field systems

Next come project management, document storage and scheduling. Prioritize active jobs with imminent deadlines or safety implications. Field crews need tools to receive instructions, so restore mobile access and any drawing repositories they depend on.

5. Everything else

File shares, archives, internal tools, and low-priority workstations come last. Resist the urge to restore these early simply because they are easy.

Validate before you reconnect

Each restored system should pass checks before rejoining production:

  • Scan for malware using up-to-date tools
  • Confirm patches are current
  • Verify that backup data predates the intrusion, since attackers sometimes sit quietly for days or weeks
  • Rotate secrets and credentials tied to that system

If you restore from a backup that already contains the attacker's foothold, you will be attacked again.

Decisions to make in advance

You will not want to make these calls in the middle of a crisis:

  1. Who is the incident lead, and who has authority to approve spending?
  2. Which systems are on your priority list, in what order?
  3. Who calls the insurer, legal counsel and your IT provider?
  4. What are your recovery time targets for each system?
  5. Where are your recovery documents stored if your network is down? Keep a printed or offline copy.

A hypothetical example

Consider a hypothetical 80-person commercial contractor that restores its file server first because it holds the most data. The server comes back, reconnects to a directory the attacker still controls, and the encryption begins again. Starting with identity would have added a few hours and saved days.

What a good plan looks like

A solid plan names systems in priority order, assigns an owner to each, sets targets for how long each can be down, and is tested at least once a year through a tabletop or a restore drill. It also lists contacts, vendor support numbers and credentials stored offline.

Build the order before you need it

Ironfield Cyber helps contractors and energy companies write recovery runbooks, rank their systems by business impact and test their backups. If you have never written down your restore order, a short working session can give your team a plan to follow when it matters most.