Ransomware recovery steps: what to do in the first 72 hours after an attack, and in what order
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- CISA’s #StopRansomware Guide starts with isolating the affected systems, at the switch level if several subnets are hit, and powers devices down only when they cannot be disconnected, because shutting down loses evidence held in memory
- The NCSC’s recovery guidance of July 2026 puts the investigation before restoration where possible, because its findings inform regulatory reporting and rebuild decisions, and tells teams to assume the backups may have been targeted
- The restore point has to predate the intrusion, not only the encryption: Mandiant’s global median dwell time across its 2025 investigations was 14 days, and NIST SP 1800-11 restores from backup once logs and corruption testing have identified the last known good state
- Broadcom’s documentation for VMware Live Recovery Cloud calls its isolated recovery environment a cyber recovery “clean room”: disconnected from production, reached through one controlled access point, with a copy of production DNS recovered before other workloads
- Passwords for all affected systems are reset once the environment is cleaned and rebuilt, and the reporting clocks run alongside: a NIS2 early warning within 24 hours of becoming aware of a significant incident, a GDPR notification of a personal data breach within 72 hours where feasible
Eurokommerz × Vixen.UNO: Cyber Resilience Talk to an expert →
Ransomware recovery steps in the order they run
After a ransomware attack, isolate the affected systems without powering them off, preserve evidence and find out how the attackers got in, then restore from a point that predates the intrusion into an isolated recovery environment. Directory and management systems come back first and business services follow by priority, while the NIS2 and GDPR reporting clocks run from the first day. This guide sets out that order for the first 72 hours, and the UK National Cyber Security Centre (NCSC) warns that “Recovery from a disruptive cyber incident often takes longer than leaders initially expect.”
| PHASE | PLANNING WINDOW | ACTIONS | WHO DECIDES | OUTPUT |
|---|---|---|---|---|
| Contain | first hours | isolate affected systems, at the switch if subnets are hit; cut remote access; use out-of-band channels | incident lead | spread stopped, decision record opened |
| Preserve and scope | first 24 hours | memory and disk images of sample systems, logs, entry point, accounts used, state of each backup | incident lead with investigators | scope, entry point, backups rated |
| Report | within 24 and 72 hours of awareness | NIS2 early warning and notification where they apply; GDPR notification where required | management, legal department, data protection officer | reports sent or reasons recorded |
| Choose restore points | days 1 to 2 | last clean point per system, scanned before use | system owners with investigators | a dated restore point per system |
| Build the clean room | days 1 to 2 | isolated hosts and networks, one controlled access point | infrastructure lead | a place to restore into |
| Identity and management | days 2 to 3 | new backup server, then DNS, domain controllers and vCenter | incident command | trusted sign-in and management |
| Services by tier | from day 3 | critical services first, owner sign-off, password resets, monitoring | incident command, business owners | services back in agreed order |
Phases after the #StopRansomware Guide of CISA, FBI, NSA and MS-ISAC (September 2023), NIST SP 800-61 Rev. 3 and the NCSC’s recovery guidance (28 July 2026); deadlines from NIS2 Article 23(4) and GDPR Article 33(1). Other windows, roles and outputs are our planning suggestion for a prepared organisation, not a forecast.
Contain the attack without destroying evidence
CISA’s response checklist begins with “Determine which systems were impacted, and immediately isolate them.” If several systems or subnets appear affected, take the network offline at the switch level; to stop continued access with stolen credentials, the guide also lists disabling VPNs, remote access servers, single sign-on resources and public-facing assets. Devices are powered down only if they cannot be disconnected, because that loses “potential evidence stored in volatile memory”. Isolate in a coordinated way and move to “out-of-band communication methods such as phone calls”, as CISA advises, so that the attackers are not tipped off. In the NCSC’s guidance the CEO normally leads the response, for example through an incident command structure, with a central record of “decisions taken, by whom, and why”.
CISA notes that emerging ransomware strategies “have begun targeting VMware ESXi servers, hypervisors, and other centralized tools and systems”. Cut the management network off from user networks, and isolate VMs by disconnecting their virtual network adapters. A snapshot with memory captures a running VM’s memory, and a VM that has to stop can be suspended instead of powered off; the vmss2core tool in Broadcom’s KB 323788 converts either file set into a memory dump. How attackers reach ESXi is shown in our guide to ESXi ransomware hardening.
Scope the attack before you restore anything
The NCSC recommends investigating first: “Where possible, investigation should take place before systems are restored, as findings will inform impact understanding, regulatory reporting requirements, and system rebuild and recovery decisions.” CISA’s checklist includes system images and memory captures of a sample of affected devices, virtual servers included, logs, and identifying the systems and accounts of the initial breach.
The scope answers what the recovery depends on: how the attackers got in and whether that path is still open, which accounts they used, whether data left the network, when the intrusion began and which backups they reached. The NCSC asks teams to “ascertain when your last backups were taken” and whether those backups are available and compromised, and CISA looks for “outside-in and inside-out persistence mechanisms”, which return with any restore that contains them.
Our cyber resilience service prepares incident response scenarios with roles and deadlines, and an active incident is handled separately. Write to us straight away with what is encrypted, what still runs and which backups you can reach.
Why replicas and online backups often fail
CISA’s guide asks for offline backups because “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups to make restoration impossible unless the ransom is paid.” In the vSphere campaign Mandiant described on 23 July 2025, the operators used their control of the directory to reach the backup server, and “Once in, they delete all backup jobs, snapshots, and repositories.”
Veeam’s Quick Start Guide for version 13 says replication keeps an exact copy of the VM “synchronized with the original VM”, so encrypted data reaches a replica at the next run. A replica whose restore points do not reach back past the intrusion holds no clean copy. The NCSC tells teams to “Assume backups may have been targeted by attackers and seek appropriate assurance that they are immutable and uncompromised.” Our article on immutable backup sets out what an immutable copy protects against and what it does not.
How to choose a clean restore point
The restore point has to predate the intrusion, not only the encryption. In NIST’s practice guide SP 1800-11 (September 2020), the backup is used “After the last known good is determined via the logs and corruption testing”. The NCSC’s malware and ransomware guidance warns that “Ransomware may have infiltrated your network over a period of time, and replicated to backups before being discovered.” Mandiant put the global median dwell time across all its 2025 investigations at 14 days, so a backup from the night before the encryption is likely to contain the intruder’s footholds.
NIST SP 800-61 Rev. 3 asks teams to weigh timeliness, precision and reliability in recovery actions, such as “restoring only the affected files versus restoring all files”. After ransomware, the system owner may prefer recent data restored into a system rebuilt from a clean image to a whole VM from before the intrusion.
NIST also lists “Check restoration assets for indicators of compromise, file corruption, and other integrity issues before use.” In Veeam Backup & Replication 13, Scan Backup can “Find the last clean restore point if the date of the malware attack is unknown”, and Secure Restore checks “restore points for malware activity before restoring the machine to the production environment”, with Veeam Threat Hunter, antivirus software or YARA rules. A signature scan finds known malware but not an account the intruder created, so scan results and the investigation’s timeline decide the restore point together.
Clean room recovery in an isolated recovery environment
Clean room recovery means restoring into an isolated recovery environment (IRE) rather than into the network the attacker used. Broadcom’s documentation for VMware Live Recovery Cloud describes the IRE, “also known as a cyber recovery ‘clean room’”, as “a network-restricted environment disconnected from the production data center” in which infected workloads are powered on, inspected and recovered (1 September 2026). CISA asks for critical systems to be restored “on a clean network” and, if a new VLAN is created for recovery, for only clean systems to join it.
Broadcom’s best practices for the IRE (17 June 2026) state that “The only way in or out of a clean room is through a controlled access point” and that VMs in the IRE “should never have direct access to the production environment”.
The clean room needs hosts, storage and networks the attacker never controlled. CISA’s preparation steps include “Retain backup hardware to rebuild systems if rebuilding the primary system is not preferred”, which also leaves the encrypted hosts to the investigators. Spare hosts on a separate segment, a recovery site or a cloud environment can serve if planned in advance.
Rebuild identity and management first, then services by tier
Most other systems authenticate against the directory and run on the hypervisors, so those come back first. Mandiant’s M-Trends 2026 reports that ransomware operators in 2025 “actively targeted backup infrastructure, identity services, and virtualization management planes”, and the NCSC states that “trusted identity is a critical dependency for recovery”. Broadcom’s IRE guidance recommends recovering a copy of production DNS in the clean room “before recovering other workloads”, and a temporary copy of a domain controller for systems that use domain credentials.
- Install clean hosts from the vendor’s ESXi image, build a new backup server in the clean room with credentials outside the production directory, and connect it to the repositories that hold the clean restore points.
- Restore DNS and a domain controller from the chosen clean point into the clean room, or rebuild the directory if no clean point exists. Reset privileged and service account passwords there, and the Kerberos ticket-granting account twice, at least 10 hours apart with default ticket lifetimes, as the directory vendor’s forest recovery guide describes.
- Deploy a new vCenter appliance and populate it from a file-based backup that predates the intrusion, as Broadcom’s restore procedure does, or configure it from scratch if no such backup exists.
- Restore business services tier by tier, databases before the applications that use them, from standard images where possible, with each owner confirming the service by a test transaction.
- Reset the passwords of all affected systems and accounts once the environment is cleaned and rebuilt and before users reconnect, the order in CISA’s checklist.
In the NCSC’s guidance, the investigators establish “whether the attacker has been evicted”, and Incident Command decides when the risk is low enough for recovery to proceed. On restored systems, watch for the signs CISA lists for threat hunting, such as new or newly privileged accounts, anomalous VPN logins and unexpected remote monitoring and management (RMM) software.
Reporting deadlines, law enforcement and the ransom demand
For an essential or important entity, Article 23(4) of NIS2, as transposed into national law, requires an early warning to the CSIRT or competent authority without undue delay and in any event “within 24 hours of becoming aware of the significant incident”, then an incident notification within 72 hours. If personal data was affected, Article 33 of the GDPR requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to people’s rights and freedoms. The EDPB’s Guidelines 01/2021 class ransomware as usually “a breach of availability, but often also a breach of confidentiality”. Whether NIS2 applies to your company is a legal assessment for your legal department, and our guide to NIS2 incident reporting covers each report.
Under Article 23(5), the CSIRT or competent authority answers an early warning with initial feedback, guidance on mitigation on request and, for a suspected criminal incident, guidance on reporting to law enforcement. No More Ransom, an initiative of the Netherlands police, Europol, Kaspersky and McAfee, publishes decryption tools for some ransomware families. On payment, the NCSC states that “Law enforcement do not encourage, endorse, nor condone the payment of ransom demands.”
Prepare the ransomware recovery plan before the next attack
NIST’s ransomware profile, IR 8374 Rev. 1 of June 2026, asks organisations to “Develop, implement, and regularly exercise an incident response and recovery plan with defined roles and strategies for decision making”, with an up-to-date list of internal and external contacts. The plan names who declares the incident and who decides on restore points and reconnection, keeps contacts readable with email down and lists critical assets with their dependencies, as CISA’s triage step expects. The technical side is an offline or immutable copy that production credentials cannot delete, standard images, a clean room designed in advance and timed test restores of domain controllers and vCenter. Our guides to the incident response plan and to disaster recovery testing cover the plan document and isolated tests.
Our cyber resilience service writes the incident response plan, with scenarios, roles, communication and regulatory reporting deadlines, and runs regular test restores. Describe how you would restore your domain controllers and vCenter today in the form below.
What we do
Under Cyber Resilience, our engineering partner Vixen.UNO sets up Veeam-based backup with a recovery site in Baltneta’s Tier-3 data centres in Lithuania, checks it by regular test restores and writes the incident response plan, with roles, actions and deadlines. Our disaster recovery service adds Veeam replication and scheduled failover tests in an isolated environment for systems that must run from a second site. Eurokommerz holds the contract; the first call is free of charge, and the price of the technical assessment is fixed before work begins. An active incident is handled separately; mention it when you write.
FAQ
What should you do first after a ransomware attack?
What are the steps to recover from ransomware?
What should a ransomware recovery plan include?
Should you restore from the latest backup after a ransomware attack?
What is clean room recovery?
Do you have to report a ransomware attack under NIS2 and the GDPR?
Send us how your backups are stored and who can delete them, how you would rebuild your domain controllers and vCenter, and the date of your last test restore. If an incident is under way, say so in the first line, as an active incident is handled separately. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day