By Shaun Stockman, Senior Director of Business Development, Americas at Ontrack.
I’ve been on many calls, talking to insurance carriers and incident response teams about the data recovery side of ransomware cases. This is what I see happening, case after case.
I want to be direct about this up front. When ransomware hits, the instinct is to start asking how fast the data comes back. That question matters, but it's not the first one. The first hours are about figuring out what's actually happened, stopping it from getting worse, and getting the right people on the phone. Recovery comes after that, once you know what you're dealing with.
I've watched this play out with insurance adjusters, with DFIR teams, with IT directors who found the ransom note at 6am. The pattern is pretty consistent, even though every case has its own wrinkles.
Someone notices something is wrong. Maybe it's a locked screen, maybe it's a flood of file extensions nobody recognizes, maybe it's a call from an employee who can't open a shared drive. Whatever the trigger, the IT team's job in that first hour is containment. That means isolating affected systems from the network, disabling switch ports or VPN access where needed, and not touching anything more than necessary.
I know the instinct is to start clicking around and trying to fix things. I'd say resist that. Rash moves in the first hour can destroy evidence a forensic team needs later, and they can also spread the infection further. If Active Directory looks compromised, a full credential reset usually follows. It's an uncomfortable call to make at 7am, but it has to happen.
I'd also add that someone needs to start documenting everything from this point forward. Screenshots of the ransom note, timestamps of when systems went down, a list of who was notified and when. I know it feels like paperwork at the worst possible moment. But insurers and forensic teams both ask for this later, and reconstructing it after the fact is harder than just keeping a running log as you go.
Within the first day, the phone calls start. If there's a cyber insurance policy in place, the carrier usually wants to know quickly, often within the timeframes spelled out in the policy itself. Most policies also come with a panel of approved vendors, so calling in your own forensic team before checking with the insurer can create coverage headaches later.
From there, a digital forensics and incident response firm typically steps in to scope the breach: how the attacker got in, what they touched, whether data was exfiltrated before it was encrypted. That last part matters more than it used to. A lot of ransomware groups steal data first and encrypt second. The disclosure and legal obligations that come with stolen data can end up mattering as much as getting systems back online. We've written before about what this looks like on the ground, and it's worth a read if you haven't seen it: dealing with a ransomware attack.
For insurance carriers reading this, the claim itself usually needs a documented forensic report before it moves forward. Ransom demands, recovery invoices, business interruption estimates, all of it gets attached to the claim file. I've noticed the claims that move fastest are the ones where the forensic and recovery vendors were engaged early and kept clear records from day one.
This is the question everyone wants an answer to, and I don't think there's a clean one. In my experience, paying is usually discouraged , since it funds the next attack and there's no guarantee the decryption key actually works. I've seen cases where the ransom was paid and the data still didn't come back cleanly.
At the same time, I understand why some organizations pay anyway. If backups are gone, if the data is truly irreplaceable, or if the business simply can't survive the downtime, the ransom can start to look like the lesser cost. We covered this tension in more depth in an earlier piece: should we pay the ransom? My honest take is that paying should be the last option considered, not the first, and it should only happen after a recovery specialist has looked at what's actually recoverable without it.
This is where the work gets technical, and it's the part I know best. The first move is always to check backups. If clean backups exist and weren't hit by the malware, recovery is usually a matter of restoring them, though that process still takes verification and testing before anything goes back into production.
Backups get hit more often than people expect. I've seen attackers specifically target backup tapes and snapshot volumes, knowing that's the fastest way to force a payment. Even then, a data recovery specialist can sometimes still pull usable data from damaged tape libraries, corrupted volumes, or partially encrypted storage arrays. I've seen recoveries built from erased backup tapes and from RAID arrays that had to be virtually rebuilt shelf by shelf, one drive at a time. It's slow, detailed work, but it's often possible even when a company assumes the data is gone for good. On some storage platforms, engineers can use consistency points in the file system to walk back in time and merge unencrypted copies of the data, which is a step people don't realize exists until they're in the middle of a case. We've documented a few of these cases here: recovering data from ransomware attacks.
If you're an IT professional reading this hoping for a checklist, here's the short version. Isolate first, investigate second, and don't make ransom decisions before a forensic and data recovery assessment is complete. If you work with insurance claims or DFIR engagements, build a relationship with a data recovery partner before an incident happens, not during one. It saves time when time is the thing you have the least of.
How long does ransomware recovery usually take?
It depends heavily on backup quality and the scope of encryption, but full recovery often takes anywhere from a few days to several weeks. Simple cases with clean backups move faster. Cases involving destroyed backups or large storage environments take longer.
Do I have to report a ransomware attack?
In many cases, yes, especially if personal data was exposed. Reporting obligations vary by industry and jurisdiction,: so loop in legal counsel and your cyber insurer early, rather than waiting until later.
Can data be recovered without paying the ransom?
Often, yes. Backups, forensic imaging, and specialized recovery techniques can restore a meaningful amount of data in many cases without ever engaging the attacker. It's worth getting that assessment before assuming payment is the only path.
What's the biggest mistake companies make after an attack?
I'd say it's moving too fast in the wrong direction, restarting systems, wiping drives, or paying the ransom, before anyone has actually assessed what's recoverable. Slowing down for a day to get the right people involved almost always pays off.
The attacks keep coming, and the tactics change faster than most response plans get updated. What I've noticed is that the organizations that come out the other side in the best shape are the ones that treat the first hours as an investigation, not a scramble. Get that first stretch right, and the rest of the recovery tends to move faster.