When ransomware hits a contractor, the file server and email get the attention. But the systems that determine whether you can pay people and bill owners are the accounting and job cost databases. If payroll cannot run on Friday or pay applications cannot go out, cash flow suffers within days.
Accounting data recovery has its own challenges. Databases are more sensitive to how they are backed up and restored than ordinary files, and an incomplete restore may look fine while quietly missing transactions. Planning ahead makes the difference between a bad week and a bad quarter.
Know Where the Data Lives
Start with a simple map for your finance systems:
- The database server, and whether it is on premises, hosted, or in the cloud
- Application servers and any file shares with attachments, reports, and custom forms
- Integrations with payroll, banking, timekeeping, and project management
- Licensing, configuration files, and encryption keys
- Where scheduled jobs and custom reports are stored
If a vendor hosts the system, understand what the vendor backs up, how often, and how quickly they can restore. Ask for the answers in writing.
Back Up Databases Correctly
Copying database files while the system is running can produce unusable backups. Make sure your backup method is database-aware, using the vendor's recommended approach or tools that coordinate with the database engine. Include transaction logs if your system uses them, since they allow restoration to a specific point in time.
Verify that:
- Backups complete without errors and are not silently skipped
- The backup includes the application components, not only the data
- At least one copy is offline or immutable
- Retention covers month-end, quarter-end, and year-end points
- The backup account cannot be used to delete backups from a compromised domain
Decide Your Recovery Targets
Work with the controller to set targets in business terms:
- How long can payroll be delayed before it becomes a legal or morale problem?
- How many days of transaction loss could you reconstruct from paper, bank records, and email?
- When is the next major billing deadline?
These answers drive investment. If a day of lost entries is manageable but a week is not, your backups should run at least daily, and more often during heavy periods.
Practice the Restore
Do a full restore to an isolated test environment at least once a year, and verify the results with the finance team:
- Trial balance ties to a known report
- Open payables and receivables match records
- Payroll history appears complete
- Attachments, reports, and user logins work
- Integrations can be reconnected safely
Time the process and note surprises. Update your runbook.
After an Attack: Restore Safely
Resist the urge to restore immediately onto the same infected environment. Work with your response team to ensure the environment is clean before bringing back databases. Restoring onto compromised servers can lead to reinfection. Plan to rebuild servers or use clean infrastructure, then restore data.
Choose a restore point carefully. The latest backup may include attacker changes or encrypted files. Your responders can help identify the earliest sign of compromise so you can pick a clean point, then reconstruct transactions that occurred after it.
Validate Before Reopening
Before users return to the system:
- Check balances and totals against independent sources such as bank statements
- Review the audit log for suspicious changes, including new vendors or altered banking details
- Reset all passwords, including service and integration accounts
- Reissue API keys and revoke old tokens
- Review user roles for unexpected additions
Attackers who reached accounting systems may have changed payment details. Validating vendor records before any payment run is critical.
Have a Manual Fallback
If the system is down for days, how will you operate? Prepare a contingency:
- A process for paying critical vendors and subcontractors using verified information
- Payroll alternatives, possibly through your payroll provider's separate portal
- A way to track job costs on spreadsheets for a short period, then reconcile
- Communication templates for subs, suppliers, and owners explaining delays
Keep printed copies of key contact lists and vendor payment information in a secure location, protected appropriately.
Include Finance in Planning
Many recovery plans are written by IT alone. Ask your controller to review the plan and take part in a tabletop exercise. Finance staff know which deadlines are truly critical.
Reduce the Odds of Reaching Accounting
Segment the accounting system from general user networks, limit who can reach the database server, require multifactor authentication for remote access, and keep the software patched.
Ironfield Cyber helps contractors design and test backup and recovery for Sage, Viewpoint, and other accounting platforms. If you want to know how quickly your finance team could be back in business, we can run a recovery exercise with you.