A multi-site medical practice had been encrypted twice in three months. Their IT provider gave the same answer both times — restore and carry on — but couldn’t say how it got in, or whether patient data had left. They called us for a second look.
They had been encrypted twice in three months. The second time, their existing IT provider gave the same answer as the first: restore from backup and carry on. Nobody could tell them how it got in, whether patient data had left the building, or why it had happened again.
They called us after the second event. Days into the first discovery call, they asked for a second team to look at what was actually going on. That is usually the moment an owner stops asking “can you fix it” and starts asking “does anyone here know what they’re doing.”
Not the malware. The arrangement around it. Their backups were reachable using the same credentials as their live systems, so whoever held an administrator account held the backups too. Retention was short enough that by the time anyone noticed the encryption, the clean copies had already rotated out. And nobody had ever restored from them, so the recovery time they had been quoted was a guess.
None of that is unusual. It is what most small and mid-size organizations have — right up until the day it matters.
A recovered environment, and the thing their previous provider had never given them: a written backup, recovery and incident-management plan. Retention designed to outlast how long an attacker actually sits inside a network. At least one copy their production systems cannot reach. Restore testing on a schedule, against a separate system, with the recovery time measured rather than estimated.
And a named decision for the owner rather than a technical default — how often copies are taken, priced, so the business could choose how much work it was willing to lose. They moved their account to us.
A recovered environment, a recovery plan they can actually trust, and a clear answer to the one question that decides what an attack costs: when was the last successful full restore, and how long did it take.
Most ransomware conversations are about prevention, and prevention matters. But a determined attacker gets in eventually, and the thing that decides what it costs you is whether your recovery works.
If nobody at your organization can say when the last successful full restore was — and how long it took — that is the answer. The first call is free.
Book a free 15-minute callOr get the sample recovery plan — the redacted version of the document these clients get.
One email with the download. No spam.Published with the client’s identity withheld. No client name, patient data, or figures are disclosed.