Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Close-up of two monitors showing log lines and coloured terminal output

After an attack you do not rebuild on the same machines

On the day after a ransomware attack the question is not whether the backup exists but what you restore it onto. The existing environment is evidence and suspect at the same time; restoring onto it is the mistake that causes the second outage. This page is about the equipment you need then and how quickly it can be standing there.

Why it is needed

Four reasons not to restore onto the existing environment

All four have at some point been the reason a recovery had to be done twice.

  • The environment is evidenceFor the investigation into what happened, and for your insurer and regulator, the affected systems have to stay as they are. Overwriting them with a restore erases the answer to how entry was gained.
  • The attacker may still be insideAn attack begins weeks before the moment you notice it. Restoring onto the same machines, with the same administrative accounts, is restoring into an environment somebody else also holds the key to.
  • You do not yet know what was touchedIn the first days the extent is not known. Clean equipment is the only place where you can be certain that what you build starts clean.
  • The clock is runningWaiting for new hardware to be delivered is days to weeks, and that is exactly the time you do not have. This is why it belongs arranged in advance and not on the day itself.
What happens then

From report to a clean environment

Four steps. The first is not technical and it shapes the rest.

Isolate and record

The affected environment comes off the network and stays as it is. What we do from that moment on is recorded, because that becomes the file for the insurer and the notification.

Stand up clean equipment

Servers, storage and workplaces that never touched the environment, built on a separate network. That is where the recovery starts.

Restore and verify

From a copy established to predate the compromise, system by system, with verification before anything touches the network.

Migrate and clear up

Once the environment runs and has been released, the temporary equipment goes back or stays on as the new basis. The old equipment is only wiped once the investigation allows it.

Beforehand

Three things that turn this from days into hours

None of the three costs much, and none can be arranged afterwards.

  • Knowing your minimumWhich systems have to come back first and what that asks for in machines. That is a half-page list you can write now and cannot write on the day.
  • A copy that cannot be alteredA backup reachable from the affected environment was, at that moment, affected too. Without an immutable copy, clean equipment is an empty box.
  • Delivery agreed in advanceWho supplies what, within what timeframe and on what terms. Negotiating that on the day costs the hours you could have spent recovering.

What goes with this

Emergency hardware is the last step of a plan that has to exist earlier.

Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

How fast can equipment be there?

That depends entirely on what was arranged in advance. With an agreement on paper and a list of your minimum, it is a matter of hours to a day. Without those two it starts with taking stock and negotiating, and then you are talking days.

Why can we not just restore onto our own servers?

For two reasons at once. The affected environment is evidence for the investigation, your insurer and the notification, and overwriting erases that. And the attacker may still be inside: an attack begins weeks before you notice it.

Do you carry out the investigation as well?

No, forensic investigation is a trade of its own and we work alongside it. What we do is isolate the environment without damaging the evidence, stand up clean equipment and run the recovery, so you can keep working while the investigation runs.

Arrange this before you need it

Tell us which systems have to come back first and where your copies sit. You get a list of the equipment that then has to be there and the timeframe in which it can be.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. Privacy policy.

Request a quote Call