A ransomware attack forces a firm into decisions it would rather make in advance: Who is in charge? Can we restore? Whom must we notify? Should we pay? Firms that have thought through those questions before the incident tend to have a calmer and shorter experience than firms that discover their answers while files are encrypted.
Paying a ransom is never guaranteed to restore your data, can expose a firm to further attacks, and may raise legal and sanctions issues. Law enforcement agencies, including the FBI and CISA, have generally discouraged paying. Treat payment as a decision for counsel and your insurer, and build your plan so you do not need to make it.
What recovery really depends on
Clean, reachable backups
The single most important factor is whether you have backups that the attacker could not reach. Modern ransomware commonly hunts for backup servers and cloud backup consoles first. You want:
- At least one copy that is offline or immutable
- Backup administration protected with separate credentials and MFA
- Recent restore tests so you know recovery time
- A documented order of restoration, such as identity, email, document management, then everything else
Knowing your environment
You cannot rebuild what you have not documented. Keep an up-to-date record of servers, applications, licenses, network settings, and dependencies, stored somewhere that will not be encrypted along with everything else, even a printed binder.
Practicing the response
Run a tabletop exercise at least once a year. Gather a partner, the administrator, IT, and someone responsible for client communications. Walk through a scenario: it is Friday at 4 p.m., files are locked, and a note demands payment. Who does what in the first hour?
First 24 hours: a checklist
- Isolate. Disconnect affected devices from the network. Do not simply power off if your responders advise otherwise, because memory can hold evidence.
- Activate the plan. Call the incident lead, then your insurer's breach hotline, which often engages breach counsel and forensic responders.
- Preserve evidence. Do not wipe machines before forensics have captured what they need.
- Scope the damage. Determine which systems were hit and whether data was copied out, since many attacks now involve both encryption and theft.
- Secure identity. Reset privileged credentials and check for the attacker's persistence.
- Use out-of-band communication. If email is down or compromised, use phone numbers and a pre-arranged alternate channel.
- Engage counsel on notification obligations to clients and regulators, which vary by state and by the data involved.
The ethics layer
ABA Formal Opinion 483 discusses lawyers' obligations when a breach occurs, including investigating, stopping the breach, and communicating with affected clients. Model Rule 1.4 on communication and Rule 1.6(c) on safeguarding client information are relevant. Because state rules differ, confirm specifics with your state bar and breach counsel.
Restoration in practice
Rebuild in a clean environment
Restoring backups onto infected systems invites reinfection. Responders typically rebuild or verify clean systems first, restore data, and monitor closely afterward.
Prioritize by business need
Decide in advance which matters have imminent deadlines. Consider requests for extensions or continuances if the outage threatens a filing, and have counsel handle those communications.
Expect it to take time
Even with good backups, recovery usually takes days. Set honest expectations with partners and clients.
Communications
Prepare templates ahead of time:
- A short internal notice to staff with instructions to stay offline until cleared
- A client notice that is honest, factual, and does not speculate
- A holding statement for any inquiries
Have counsel review them before use. Avoid blaming anyone publicly or guessing at the cause.
After the incident
- Complete a root-cause review: how did they get in, and why were they not detected?
- Close the entry point, whether an unpatched VPN, a phished password without MFA, or an exposed remote desktop.
- Update the plan with what you learned.
- Brief your insurer and update your questionnaire answers accurately.
Prevention still matters
The cheapest ransomware recovery is the one that never happens. MFA, patching, endpoint detection with monitoring, email filtering, and staff training address most common entry paths.
Working with us
Counsel Cyber helps firms build and test ransomware readiness plans, including backup design, response runbooks, and tabletop exercises. If you would like to know how recoverable your firm is today, we can walk through it together.