Wethaq ICT | وثاق
Get a Quote
Insights

Business continuity and disaster recovery that survives ransomware

GovernmentPrivate sectorBanks & finance

Many organisations have a disaster recovery plan written for fires, floods and power failures. Ransomware is a different kind of disaster: the attacker is inside your network, often for days, and deliberately seeks out your backups, your hypervisors and your directory service before encrypting anything. A plan that assumes the backups will simply be there may fail exactly when it is needed.

Start with business continuity, not technology

ISO 22301 frames continuity as a management system, beginning with a business impact analysis (BIA). The BIA asks which services matter most, what depends on them and how long the organisation can tolerate their loss. From this you derive two numbers for each service:

  • RTO (Recovery Time Objective): how quickly the service must be restored.
  • RPO (Recovery Point Objective): how much data loss, measured in time, is acceptable.

A payment switch, a citizen-registry database and an internal wiki will rightly have very different values. Business owners should set these targets, and IT should then prove it can meet them. Also map dependencies: DNS, Active Directory, licensing, network and identity services must come back before the applications that rely on them.

Design backups for an attacker who is looking for them

The 3-2-1 rule, three copies on two media types with one offsite, has evolved into 3-2-1-1-0 to answer ransomware:

  • 3 copies of the data.
  • 2 different storage types.
  • 1 copy offsite.
  • 1 copy offline, air-gapped or immutable, so it cannot be altered or deleted even by an administrator account.
  • 0 errors, meaning backups are verified and restore tests succeed.

Practical measures include immutable storage with enforced retention, backup infrastructure in a separate administrative domain with its own credentials and MFA, no standing domain-admin access to the backup console, and alerts on deletion of backup jobs or sudden changes in retention. Remember that backups must also cover configuration data, such as firewall and switch configurations, hypervisor settings and identity systems, not only databases and files.

Plan for recovery without trusting the old environment

Restoring encrypted systems straight back onto the same network can reintroduce the attacker. An isolated recovery environment, sometimes called a clean room, gives you a separated space to restore, scan and validate systems before reconnecting them. Include in the plan:

  • A restore order based on dependencies and business priority.
  • Malware scanning and integrity checks of restored data, to avoid restoring a compromised or already encrypted copy.
  • Rebuilding, not merely restoring, the identity infrastructure and resetting privileged and service credentials.
  • Out-of-band communication, since email and chat may be unavailable or monitored by the attacker, and printed contact lists and procedures kept offline.

Test until it is boring

An untested plan is a hypothesis. Combine several kinds of exercise: a tabletop for executives and communications staff, technical restore tests of individual systems, and periodically a full scenario that simulates loss of the primary site or of the directory service. Measure actual recovery times against your RTO and RPO, record the gaps, and fix them. Keep a record of each test, as auditors and regulators in finance and government will expect evidence, not just documents.

Link recovery to incident response

Continuity and incident response must work together. NIST SP 800-61 describes how to contain, eradicate and recover from an incident, and NIST CSF 2.0 includes Respond and Recover as core functions alongside Govern. Decide in advance who can declare a disaster, who talks to regulators, customers and the press, and what criteria apply to decisions such as isolating the network. Decisions about ransom payment are legal, ethical and operational matters that should be considered by leadership before a crisis, not during one.

How Wethaq ICT helps

Wethaq ICT helps you run a business impact analysis, define realistic RTO and RPO targets, design ransomware-resilient backup and recovery architecture, and conduct tabletop and technical recovery tests. We also support incident response, so that when an event occurs your team can follow a rehearsed path back to normal operations.

Back to insights

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.