Digital Equipment Ltd.
Cybersecurity 5 min read

Ransomware recovery: the 72-hour playbook

By DEL Security Practice 18 May 2026 Last updated: 18 May 2026

The difference between a 3-day and a 3-week ransomware recovery is almost never the backup product. It is whether the organisation had rehearsed the sequence: isolate, decide, restore, communicate.

Circuit board in close-up — ransomware incident responseCybersecurityMay 2026

Hours 0–4: isolate and preserve

The first play is containment with evidence intact — disconnect affected segments, snapshot infected systems before cleaning, and preserve logs. Teams that wipe first lose the indicators that tell them whether the attacker still holds access, and re-infection during recovery is the most common cause of a second, worse incident.

Hours 4–24: decide with the business, not for it

Restoring everything is rarely right; restoring too little is fatal. Rank systems by business impact, restore the minimum viable set — identity, DNS, comms, then the revenue path — and time each stage against the documented RTO. This ranking must be agreed before the incident, in an afternoon workshop, not improvised at 2 a.m.

Hours 24–72: restore, verify, communicate

Restore from the newest clean point, verify with the application owners (not just the infrastructure team), and communicate on a fixed cadence — every four hours internally, daily for customers. Silence breeds speculation, and speculation costs more trust than an honest “we restore at hour 40”.

Keep reading

Turn the theory into a plan.

Every article here comes from projects we delivered. If one matches your roadmap, our engineers will scope it with you — no obligation.

Keep reading

More insights

← All articles