Recovering Job Cost and Accounting Data After a Ransomware Attack

After ransomware, finance needs payroll, payables, and job cost back fast. Plan database recovery, validation, and a manual fallback before an attack happens.

3 min readBy Ironfield Cyber Team

When ransomware hits a contractor, the file server and email get the attention. But the systems that determine whether you can pay people and bill owners are the accounting and job cost databases. If payroll cannot run on Friday or pay applications cannot go out, cash flow suffers within days.

Accounting data recovery has its own challenges. Databases are more sensitive to how they are backed up and restored than ordinary files, and an incomplete restore may look fine while quietly missing transactions. Planning ahead makes the difference between a bad week and a bad quarter.

Know Where the Data Lives

Start with a simple map for your finance systems:

  • The database server, and whether it is on premises, hosted, or in the cloud
  • Application servers and any file shares with attachments, reports, and custom forms
  • Integrations with payroll, banking, timekeeping, and project management
  • Licensing, configuration files, and encryption keys
  • Where scheduled jobs and custom reports are stored

If a vendor hosts the system, understand what the vendor backs up, how often, and how quickly they can restore. Ask for the answers in writing.

Back Up Databases Correctly

Copying database files while the system is running can produce unusable backups. Make sure your backup method is database-aware, using the vendor's recommended approach or tools that coordinate with the database engine. Include transaction logs if your system uses them, since they allow restoration to a specific point in time.

Verify that:

  1. Backups complete without errors and are not silently skipped
  2. The backup includes the application components, not only the data
  3. At least one copy is offline or immutable
  4. Retention covers month-end, quarter-end, and year-end points
  5. The backup account cannot be used to delete backups from a compromised domain

Decide Your Recovery Targets

Work with the controller to set targets in business terms:

  • How long can payroll be delayed before it becomes a legal or morale problem?
  • How many days of transaction loss could you reconstruct from paper, bank records, and email?
  • When is the next major billing deadline?

These answers drive investment. If a day of lost entries is manageable but a week is not, your backups should run at least daily, and more often during heavy periods.

Practice the Restore

Do a full restore to an isolated test environment at least once a year, and verify the results with the finance team:

  • Trial balance ties to a known report
  • Open payables and receivables match records
  • Payroll history appears complete
  • Attachments, reports, and user logins work
  • Integrations can be reconnected safely

Time the process and note surprises. Update your runbook.

After an Attack: Restore Safely

Resist the urge to restore immediately onto the same infected environment. Work with your response team to ensure the environment is clean before bringing back databases. Restoring onto compromised servers can lead to reinfection. Plan to rebuild servers or use clean infrastructure, then restore data.

Choose a restore point carefully. The latest backup may include attacker changes or encrypted files. Your responders can help identify the earliest sign of compromise so you can pick a clean point, then reconstruct transactions that occurred after it.

Validate Before Reopening

Before users return to the system:

  1. Check balances and totals against independent sources such as bank statements
  2. Review the audit log for suspicious changes, including new vendors or altered banking details
  3. Reset all passwords, including service and integration accounts
  4. Reissue API keys and revoke old tokens
  5. Review user roles for unexpected additions

Attackers who reached accounting systems may have changed payment details. Validating vendor records before any payment run is critical.

Have a Manual Fallback

If the system is down for days, how will you operate? Prepare a contingency:

  • A process for paying critical vendors and subcontractors using verified information
  • Payroll alternatives, possibly through your payroll provider's separate portal
  • A way to track job costs on spreadsheets for a short period, then reconcile
  • Communication templates for subs, suppliers, and owners explaining delays

Keep printed copies of key contact lists and vendor payment information in a secure location, protected appropriately.

Include Finance in Planning

Many recovery plans are written by IT alone. Ask your controller to review the plan and take part in a tabletop exercise. Finance staff know which deadlines are truly critical.

Reduce the Odds of Reaching Accounting

Segment the accounting system from general user networks, limit who can reach the database server, require multifactor authentication for remote access, and keep the software patched.

Ironfield Cyber helps contractors design and test backup and recovery for Sage, Viewpoint, and other accounting platforms. If you want to know how quickly your finance team could be back in business, we can run a recovery exercise with you.