Home  ›  Glossary  ›  Ransomware Recovery

What is ransomware recovery?

Ransomware recovery is the process of bringing systems, applications and data back to a working, trustworthy state after a ransomware attack without letting the attacker back in. It starts once the attack is contained and ends when the business runs on rebuilt systems with restored data.

Identity, network and the backup server before any application

A routine restore puts one file, database or virtual machine back onto infrastructure that is otherwise healthy. Recovery after ransomware puts back dozens or hundreds of systems at once, onto infrastructure that may itself be compromised, from backups that may carry the attacker's tools. The work therefore follows an order:

  1. Trusted foundation. Directory services, networking and the backup server are rebuilt or verified first, since a compromised directory or backup server hands access straight back.
  2. Restore point choice. Each system gets a restore point from before the attacker arrived, as far as the evidence shows; the ransomware kill chain entry covers how intrusion length and retention interact.
  3. Isolated checks. Data is restored into a separate environment and scanned for malware and unknown accounts, the approach called clean room recovery.
  4. Return in business order. Systems go back into production by priority, with payroll and order processing ahead of archives and new credentials issued throughout.
  5. Watching for a return. Restored systems are monitored for signs that the attacker kept a way in.

Dependencies set the real sequence inside each priority tier. An application restored before the database, DNS records or license server it relies on will not start, so recovery runbooks list systems by what they depend on as well as by business value. Gaps in that map surface as hours lost mid-recovery, while the restore queue waits on a system nobody listed.

Restore throughput and where restored systems land

Restore time is the volume restored divided by sustained restore throughput. Bringing back 100 TB at 1 GB/s takes 100,000 seconds, close to 28 hours, before scanning, application checks and rebuild work are counted; at 3 GB/s the same volume takes a little over nine hours. Restore tests usually cover one virtual machine at a time, so the rate a repository sustains with dozens of restore jobs reading in parallel often stays unknown until the day it sets the length of the outage. The network caps it as well: a repository reached over a single 10 Gb/s link cannot deliver much more than 1.25 GB/s, however fast its disks are.

Restored systems also need a destination. Original hosts may be held for forensic imaging or remain untrusted, so recovery commonly lands on spare hardware, a separate cluster or instant recovery, which runs virtual machines straight from backup storage and then carries production load for days. With Veeam, Commvault or similar software, recovery speed depends on the repository and the network as much as on the backup application itself.

ARTESCA and ransomware recovery

ARTESCA is the S3 repository a recovery reads from, so its restore rate and the network in front of it set part of the timeline. The ARTESCA Cyber Guarantee puts money behind the restore points still existing: a one-time payment of $100,000 if an external cyberattack encrypts or deletes data held on ARTESCA. Qualifying deployments have at least 50 TB licensed in production, run ARTESCA 4.1.3 or later on a supported release, follow the recommended security practices, store the data with S3 Object Lock in compliance mode and give written notice within 48 hours.

Exfiltration that neither encrypts nor deletes anything falls outside it, as do attacks using credentials compromised outside ARTESCA or shared between people, and unauthorized acts carried out by approved personnel.