Assessing backups damaged by ransomware attacks

Having a backup does not by itself settle whether work can resume. We review what is available and what you need to restore, then define the appropriate testing scope.

Who is this service for?

For organisations and individuals who found that backups will not open, that the backup they need is unavailable, or that restoring did not give the expected result.

What do we examine?

The list of known backups, their dates, their locations, the systems they cover, and what happened when they were used. The team defines what the examination needs without assuming that the latest backup is the most suitable.

What do we need to know?

The backup software if known, the storage medium, the date you need to go back to, the last known successful restore test, and the services with priority.

How do we assess the result?

We explain the date the available data represents, the gap between it and the time of the incident, and what could be verified from the files or systems. Reading a backup successfully does not automatically mean the whole application was restored successfully.

Specific questions

Keep it separate from the suspected environment, and coordinate testing with whoever is responsible for response and recovery.

State the missing period and its operational importance. The scope of examination is defined on that basis, without assuming the gap can be filled.