Home›Guides›DRP and BCP

DRP and BCP

How do you restart your IT systems after ransomware?

You restart an information system after ransomware by restoring a copy made before the intrusion onto new or rebuilt machines, after removing the attacker’s access. You do not decrypt in place to save time while the network and accounts have not been cleaned up: the goal is a clean service, not the fastest return to the infected state.

Updated October 20263 min read5 sources cited

Key points

  • Change privileged passwords from a clean machine, before switching anything back on.
  • Choose a copy older than the first sign of intrusion; if in doubt, older still.
  • Order: administration network, identity, backups, data and applications, workstations, email, users.
  • The ANSSI, France’s national cybersecurity agency, warns that a poorly rebuilt core of trust (directory) leads to a compromise cycle that can last for months.
  • The standby environment is only disconnected after a successful backup of the new state.

Before switching anything back on

  • The compromised production network stays isolated.
  • Passwords for privileged accounts, VPNs, email, backup and firewalls are changed from a clean machine, not from a workstation that is still suspect.
  • Identify the likely date when the abnormal activity began (accounts created, scheduled tasks, encryption volume). The copy to restore is older than that date. If in doubt, go further back, even if it means losing more data entry.
  • Confirm that this copy opens: one file, then one database, before launching the full restore.
  • The complaint is filed with the Cybercrime Unit of the Mauritius Police Force before the machines are reinstalled: CERT-MU recommends taking a forensic image of the affected systems before restoring them, so that the technical evidence remains available.

Paying the ransom to obtain a decryptor does not exempt you from any of these steps. The decryptor, when it works, does not remove the access left behind by the attacker.

The four stages of remediation

The ANSSI, France’s national cybersecurity agency, divides the way out of a crisis into four phases, summarised in French by the acronym “E3R”:

PhaseObjectiveExample action
ContainmentStop the spreadCut Internet access, isolate the affected segments
EvictionRemove the attackerRevoke accounts and sessions, change all secrets
EradicationRemove their tools and backdoorsReinstall rather than clean
RebuildingBring a clean information system back into serviceRestore the data onto a clean base

Restoring backups belongs to the last phase. Doing it earlier often means restoring for the attacker.

The rebuilding order

  1. A new administration network, separate, from which the work is done.
  2. Identity: directory or local accounts rebuilt, not a copy of the directory as is if it may contain accounts created by the attacker. This is a decision to make with the incident response provider. The ANSSI stresses that failing to rebuild this core of trust leads to a cycle of compromise and remediation that can stretch over months.
  3. The backups themselves: check that they are still out of reach of former accounts.
  4. Data and business applications, in order of dependencies (database before application). The ANSSI asks for this restore order to be defined in advance, taking into account infrastructure services (DNS, NTP, directory) and how critical each application is.
  5. Workstations, reinstalled rather than “cleaned” when there is no certainty. Reconnecting a workstation that is still infected restarts the attack.
  6. Email, often handled separately (Microsoft 365 or Google Workspace). For a compromised account, Microsoft recommends resetting the password, revoking all open sessions, removing suspicious mailbox rules and forwarding, then enforcing multi-factor authentication.
  7. Users coming back, in groups, with a business check. Services are brought back gradually, under monitoring, with security updates applied before reconnection.

Where to restart

Three options, from the slowest to the best prepared:

  • reinstall new servers on the premises, then restore the copies: long RTO, depends on hardware;
  • start standby instances from the backed-up images (DRP): you work off site while rebuilding, on a chosen version;
  • fail over to a BCP that is already running: only if that standby environment has not replicated the encryption. If it has, you go back to the DRP and an older version.

Returning to normal

When the premises are ready, the data is moved back from the standby environment to production, including whatever was entered during the standby period. A backup cycle is resumed the same day. The standby environment is only disconnected after a successful backup of the new state. Then the entry point is fixed and a new restore test is carried out: see How do you protect your backups against ransomware?.

At WeDoBack

The DRP is designed for exactly this restart: choice of version, restart of servers on standby instances, public IP addresses (€0.54 excl. VAT per address per month) if services must be reachable from outside, and activation during a disaster billed per day. The restore can cover the complete server, from a system image, or the files only. The encryption key is held by the customer and must be available: without it, the copies remain unreadable, immutable or not. The IMMUTABLE offer guarantees that the chosen version still exists. It does not decide, on the team’s behalf, which date predates the intrusion. Support can be reached on +33 9 72 50 78 28, from 9:00 to 13:00 and 14:00 to 17:30 (Paris time, i.e. 11:00 to 15:00 and 16:00 to 19:30 in Mauritius during European summer time, one hour later in winter).

Frequently asked questions

Can we simply restore yesterday’s backup?

Rarely. An intrusion often precedes encryption by several days or weeks. Yesterday’s backup may contain the accounts, scheduled tasks or tools left behind by the attacker. You first need to date the start of the abnormal activity, then restore an earlier copy onto a cleaned-up environment.

Should Active Directory be restored from backup?

This is a decision to make with the incident response provider. A copy of the directory may contain accounts or permissions created by the attacker. The ANSSI, France’s national cybersecurity agency, devotes an entire guide to rebuilding this “core of trust”, because failing to do so restarts the compromise.

How long does a full restart take?

Critical services can be back up within a few days on a clean or standby environment. According to the ANSSI, full remediation can extend over several weeks or even several months after a major incident. The plan must therefore provide for a lasting degraded mode.

Sources

Documents consulted in October 2026.

  1. Cyberattacks and remediation: keys to decision-making (v1.0, December 2023) — ANSSI, France’s national cybersecurity agency
  2. Guideline on Incident Handling (v1.1) — CERT-MU
  3. Information system backup: the fundamentals (ANSSI-BP-100, v1.1, 27 November 2025) — ANSSI, France’s national cybersecurity agency
  4. Respond to a compromised cloud email account — Microsoft Learn
  5. DRP offer: recovery after a disaster — WeDoBack

Planning a backup, DRP or BCP project?

More than 20 years of experience protecting business data.

Request a quote+33 9 72 50 78 28

Protect your data with WeDoBack

Encrypted offsite backup, immutable storage, DRP and BCP: tell us about your servers and we will recommend the right combination.