Which Systems to Restore First After a Ransomware Attack

Restoring everything at once rarely works. Set recovery priorities in advance so a contractor or energy firm can bring back the systems that matter most first.

3 min readBy Ironfield Cyber Team

After a ransomware attack, the instinct is to restore everything as quickly as possible. In practice, recovery has limits: bandwidth, staff, and the need to confirm each system is clean before it reconnects. Restoring in the wrong order wastes time, and restoring a system that is still infected can restart the problem.

The answer is to decide priorities before an incident, when you can think clearly. This post explains how to build a recovery order for a contractor or energy company.

Start with business impact

List the systems your company relies on and ask, for each one, what happens if it is unavailable for a day, three days, or a week. Include the systems that people tend to overlook.

  • Identity and authentication, such as Active Directory or cloud identity
  • Email and collaboration
  • Accounting and job cost
  • Payroll and timekeeping
  • Project management and document control
  • Estimating and bidding
  • File servers and project documents
  • Phones and communications
  • Field connectivity and jobsite routers
  • Operational systems in energy settings

Rate each by criticality and by the maximum acceptable downtime. Involve operations and finance, not just IT.

Understand dependencies

Systems depend on one another, and that determines order. A typical chain:

  1. Network and internet connectivity
  2. Identity services, since almost everything requires logins
  3. Core infrastructure such as databases and virtualization hosts
  4. Applications that rely on them
  5. User devices and access

If identity services are down, restoring an application first may be pointless. Map each system's prerequisites.

A sample priority tiering

Every company differs, but a tiered approach helps.

Tier 1: Foundation and safety

  • Network, firewalls, and clean internet access
  • Identity and authentication
  • Systems tied to safety or regulatory requirements
  • Communications to coordinate the response

Tier 2: Revenue and payroll

  • Payroll and timekeeping, so employees are paid
  • Accounting and billing, so cash flow continues
  • Project management for active jobs
  • Email, once it is confirmed secure

Tier 3: Productivity

  • File shares and document libraries
  • Estimating and bidding systems
  • Specialty applications

Tier 4: Convenience

  • Archives and less-used systems
  • Test and development environments

Review this tiering with leadership so the order reflects business priorities, such as an upcoming pay date or bid deadline.

Do not skip the clean-up

Before restoring, you must understand how the attacker got in and confirm they are out. If you restore systems into an environment where the attacker still has access, you may be hit again. Typical steps include:

  • Resetting credentials, starting with administrator and service accounts
  • Closing the entry point, such as an exposed remote access service or a stolen account
  • Checking restore points for signs of compromise
  • Rebuilding critical servers from known good sources where practical
  • Restoring into an isolated network segment first and verifying

Your response provider can guide how much verification is appropriate.

Know your numbers

Two measures guide planning. Recovery time objective is how quickly a system must be back. Recovery point objective is how much data loss is tolerable. Check that backups actually meet those targets. If accounting must be restored in four hours but the restore takes two days, adjust either the expectation or the backup design.

Plan the workarounds

Some operations must continue even while systems are down. Decide in advance how you would handle payroll, material orders, and field communications manually for a few days. Keep printed copies of key contacts, schedules, and critical drawings for active projects.

Test the order

A priority list that has never been exercised is a theory. Run a tabletop exercise and, where practical, an actual restore of a Tier 1 or Tier 2 system. Record how long it took and what you learned.

A hypothetical example

Consider a hypothetical 100-person contractor hit on a Thursday before a Friday payroll. Because payroll was listed as a Tier 2 priority with documented steps, the team knew to prioritize restoring identity services and the payroll application, while holding file share restoration until the environment was verified clean. Preparation turned a panic into a sequence.

Where Ironfield Cyber helps

Ironfield Cyber helps contractors and energy companies define recovery priorities, test restores, and build incident response plans. If you do not know what you would bring back first, we can help you work through it before you need to.