ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Hypothetical Ransomware Recovery: What Restoring a Firm Takes

A hypothetical walk through restoring a small law firm after ransomware, showing why backups, documentation and a rehearsed plan decide the outcome.

3 min readBy Counsel Cyber Team

Ransomware stories usually end at the ransom note. The harder and more instructive part is what happens next: the days of rebuilding. This post walks through a hypothetical scenario to show what recovery involves and where preparation changes the result. The firm, people and timeline are invented for illustration. They reflect the general pattern described in CISA and FBI guidance on ransomware, not any real incident.

The hypothetical firm

Consider a hypothetical 15-attorney firm with a cloud document management system, Microsoft 365 for email and an on-premises file server holding legacy matter files and scanned documents. They use an outside IT provider and have a nightly backup of the server to a device in the same rack, plus a cloud copy.

Friday, 6:40 p.m.: discovery

An attorney working late sees files with strange extensions and a text file demanding payment. The attacker had been in the network for days, using a stolen password on a remote access service that lacked MFA, and had quietly spread to the server and the backup device.

Hour one: contain

The first priority is stopping the spread, not investigating.

  1. The attorney calls the number on the incident card taped inside the office manager's door, not email.
  2. The IT provider isolates affected machines and disables compromised accounts.
  3. The firm notifies its cyber insurer, which connects it with a breach attorney and forensic team.
  4. Nobody powers machines off without guidance and nobody deletes anything.

Saturday: scope and decision-making

Forensic analysts determine which systems were affected, and whether data was copied before encryption, which many ransomware groups now do. That finding triggers questions about client notification, discussed with counsel in light of ABA Formal Opinion 483, Model Rule 1.4 and state breach laws.

The firm discovers a hard truth: the on-site backup device was encrypted too. The cloud backup is intact but its most recent complete copy was made five days earlier, and restoring a large file server over the internet will take a long time.

Why the backup design decides the week

The firm's recovery time depends on three things.

  • Isolation. Because one copy was immutable in the cloud, the firm has something to restore. Without it, the choices narrow sharply.
  • Speed. Restoring terabytes from the cloud takes days unless there is a local copy or a prioritization plan.
  • Order. Systems must return in a sensible sequence, with identity services first.

Sunday to Wednesday: rebuilding

The recovery is not a matter of pressing restore. It looks more like this:

  1. Rebuild a clean network and identity environment, resetting every password and revoking every session.
  2. Wipe and reimage infected computers rather than trusting them to be cleaned.
  3. Restore the file server to a clean system, starting with the matters that have the nearest court deadlines.
  4. Verify restored data for integrity and check that permissions are intact.
  5. Re-enable email and cloud systems after confirming the attacker's access is gone, including any malicious mailbox rules or app permissions.
  6. Close the entry point by enforcing MFA on remote access.

Meanwhile, attorneys work from phones and personal devices only where policy allows, the court is notified about a deadline conflict where appropriate and a partner handles client communication.

What cost the most time

In this hypothetical, the delays came from predictable places.

  • No up-to-date network documentation, so the rebuild required rediscovery.
  • Uncertainty about which matters were on the file server.
  • Backup credentials stored on the same domain as everything else.
  • No rehearsed plan: roles were decided on the fly.

What preparation would have changed

  1. MFA on remote access would likely have stopped the initial entry.
  2. Immutable, recent offsite backups would have shortened restoration.
  3. A prioritized restore list, agreed in advance, would have saved decisions.
  4. A written incident plan with phone numbers and roles would have saved hours.
  5. Tabletop practice would have exposed the documentation gaps.

Should the firm pay?

The FBI generally discourages paying ransoms, noting that payment does not guarantee recovery and can encourage further attacks. Insurers, counsel and law enforcement should be involved before any such decision, and sanctions considerations can apply. Reliable backups remove the dilemma entirely.

Lessons to apply this month

  • Verify that every remote access path requires MFA.
  • Confirm you have an offline or immutable backup copy.
  • Time a restore of one representative system.
  • Print an incident card with key phone numbers.
  • Schedule a tabletop exercise.

How Counsel Cyber can help

Counsel Cyber builds backup and recovery plans for law firms, including immutable copies and prioritized restoration, and helps run tabletop exercises. If you would like to test your own readiness, we are glad to help.