How to Recover from a Ransomware Attack: An SMB Playbook

Usman Malik

Chief Executive Officer

September 27, 2026

AI-powered tools enhancing workplace productivity for businesses in Calgary with automation and smart analytics – CloudOrbis.

Only 25% of Canadian organizations attacked by ransomware fully restored their data, while ransom payments represented just 18% of total incident costs. Recovery therefore has to centre on validated backups, downtime control, and compliance, not on paying criminals and hoping for a working key.

That distinction matters for every medium-sized Canadian business. Ransomware recovery isn't a single restoration step. It's a controlled sequence that protects evidence, limits spread, meets reporting obligations, restores trustworthy systems, and closes the entry point before the attacker returns.

The Canadian Centre for Cyber Security's ransomware guidance says reported ransomware incidents involving Canadian victims rose by an average of 26% each year between 2021 and 2024. Your recovery plan should assume repeat exposure, not treat the attack as a freak event.

Why Recovery Is Harder Than the Headlines Suggest

Paying a ransom feels like a decision that ends the crisis. It doesn't. Canadian survey data found that 94% of respondents felt confident they could recover from ransomware, yet only 25% of attacked organizations fully restored their data, while 3% recovered none at all. Those figures expose the gap between confidence and recoverability. (SecurityBrief Canada)

The larger cost usually comes after the encryption. Your team still has to investigate the intrusion, preserve evidence, determine whether data was stolen, brief legal counsel, assess notification duties, rebuild compromised systems, validate restored data, and keep the business operating while systems remain offline. Canadian cyber incident recovery costs doubled to CAD 1.2 billion in 2023, according to Statistics Canada data cited by the Cyber Centre. (Canadian Cyber Centre ransomware threat outlook)

An infographic showing that only 25 percent of ransomware victims fully recover their data after paying.

The seven phases of disciplined recovery

A useful ransomware recovery playbook follows this order:

  1. Isolate affected devices, servers, network segments, and backup connections.
  2. Preserve volatile evidence, logs, ransom notes, and forensic images.
  3. Assess the strain, scope, intrusion path, encryption status, and possible exfiltration.
  4. Notify leadership, insurers, law enforcement, regulators, and affected parties as required.
  5. Choose a restoration path based on evidence, not panic.
  6. Rebuild and reconnect systems in controlled segments after credential resets, patching, and integrity checks.
  7. Harden the environment and convert lessons from the incident into operating controls.

That sequence is deliberately slower than clicking “restore all.” It is also faster than restoring contaminated backups, reconnecting an unpatched server, and starting the attack again.

Practical rule: Treat every restored system as untrusted until someone verifies its image, credentials, logs, patches, and data integrity.

Contain the Damage and Preserve Evidence

The first hours determine whether a ransomware incident remains contained or becomes an enterprise-wide outage. Start by isolating affected devices and network segments from internal and internet connections. Disconnect VPN access where necessary, stop replication that could copy encrypted data into clean recovery environments, and isolate backup infrastructure.

Don't immediately power off an infected machine. The Cyber Centre warns that shutting down an isolated device can destroy forensic evidence and complicate recovery. Preserve memory and active sessions for the incident response team, while preventing further network communication. Don't connect USB drives or external storage to collect files casually, because removable media can spread malware or alter evidence.

An infographic titled The First 24 Hours listing recommended actions and prohibitions following a cyber attack.

The first 24 hours

Use a named incident lead and record each decision, timestamp, and person responsible.

  • Isolate deliberately: Disconnect affected segments and devices, but don't reboot or shut down systems before forensic direction.
  • Protect backups: Take backup repositories offline and prevent compromised credentials from accessing them.
  • Preserve records: Save ransom notes, chat logs, relevant event logs, disk images, and memory captures. Teams unfamiliar with chain of custody should review practical guidance on preserving digital records for litigation.
  • Scope the event: Identify encrypted systems, suspicious administrator activity, lateral movement, persistence mechanisms, and evidence of data exfiltration.
  • Report early: Contact local police, the Canadian Anti-Fraud Centre, and the Canadian Centre for Cyber Security. Keep the endpoint detection and response overview available when assessing what telemetry remains.

The strain matters, but don't let strain identification delay containment. Collect ransom-note text, file extensions, sample encrypted files, and indicators from endpoint and identity systems. Double-extortion groups may threaten to publish stolen information even when some files remain accessible, so data theft requires its own investigation.

Paying shouldn't be the default. It may encourage repeat attacks, won't guarantee usable decryption, and can create sanctions and insurance issues. Before any negotiation or payment discussion, hand control to legal counsel, the insurer, and law enforcement. External statements should also wait until legal and communications owners approve the facts.

Notify the Right People and Meet Canadian Compliance

Ransomware creates two separate communication problems. The first is regulatory and law-enforcement reporting. The second is explaining operational disruption and potential data exposure to customers, employees, vendors, and partners. Don't combine them into one hurried email.

Under PIPEDA, an organization must report a breach to the Office of the Privacy Commissioner of Canada when it poses a real risk of significant harm, and it must notify affected individuals. Records of every breach must also be maintained. Quebec organizations need to assess obligations under Law 25 and coordinate with the Commission d'accès à l'information. Use the Canadian data privacy laws guide to identify the privacy regimes that apply to your operations, then have counsel confirm the response.

Canadian ransomware notification matrix for SMBs

RecipientTriggerNotification WindowOwner
Board, owner, or executive teamConfirmed ransomware, material outage, or possible data exposureImmediately after initial containmentIncident lead and vCIO
Cyber insurer and brokerSuspected or confirmed cyber incidentImmediately, before hiring vendors outside the policy processExecutive sponsor
Canadian Centre for Cyber SecurityRansomware affecting Canadian operations or requiring federal assistanceAs soon as practicalIncident lead
Local police, RCMP contact, and Canadian Anti-Fraud CentreExtortion, fraud, criminal intrusion, or ransom demandAs soon as practicalLegal counsel and incident lead
Office of the Privacy Commissioner of CanadaPIPEDA breach presenting a real risk of significant harmWithin the applicable PIPEDA reporting window, including the 72-hour trigger where applicablePrivacy officer and counsel
Commission d'accès à l'informationQuebec privacy incident requiring notificationWithin the applicable Law 25 process and any required follow-up or supplementation windowQuebec privacy lead and counsel
Customers, employees, or partnersConfirmed impact or credible risk requiring communicationAfter facts, scope, and legal wording are approvedLegal and communications

PIPEDA's 72-hour breach notification trigger applies when the organization determines that a breach presents a real risk of significant harm. Quebec Law 25 can also require an organization to confirm or supplement information after notifying the relevant privacy authority. Your counsel should calculate the exact deadline from the facts, not from the date an attacker first appeared in a log.

Don't let IT publish a technical incident report before legal and communications review it. A precise internal timeline can help investigators, while an improvised external statement can expose confidential details, create inconsistent commitments, or undermine an ongoing investigation.

Ransom decisions require a documented risk assessment. Screen the actor and payment route for sanctions exposure, involve the insurer, and record why the organization chose to pay or not pay. A ransom transaction isn't a shortcut around reporting duties.

Choose Your Restoration Path

Once containment and evidence collection are underway, the recovery team should choose a restoration path quickly. Waiting for perfect certainty can prolong downtime, but restoring the wrong system can restart the incident. The decision belongs to IT, legal, the insurer where applicable, and a vCIO or equivalent executive advisor.

Path one, restore validated backups

Use offline or immutable backups when they were isolated from the compromised environment, remain accessible, and pass malware and integrity analysis. Restore the most recent known-clean version into a segregated recovery environment first. Verify applications, permissions, databases, file relationships, and business workflows before production reconnection.

The Cyber Centre specifically warns against restoring backups without scanning and validating them. An offline copy isn't automatically clean.

Path two, wipe and rebuild

Choose a wipe-and-rebuild approach when backups are encrypted, suspect, contaminated, unavailable, or tied to credentials that attackers may have stolen. Safely wipe affected devices, reinstall operating systems from trusted gold images, rebuild applications from known-good sources, and restore data only after validation.

This approach takes more labour, but it gives you a defensible baseline. It also forces the team to remove persistence instead of hoping a decryptor removed every malicious component.

Path three, use a trusted decryptor

A decryption tool can be appropriate when the ransomware strain is confirmed, a reputable tool exists, and decryption is demonstrably faster or safer than rebuilding. Treat the output as recovered data, not as proof that the host is clean. Scan, validate, and migrate the data into a rebuilt environment.

PathBest WhenTypical Recovery TimeMain Cost DriverCompliance Risk
Validated offline or immutable backupBackups are isolated, clean, and restore-testedDepends on scope and dependenciesRestoration labour and validationUnverified data or incomplete audit trail
Wipe and rebuildSystems or backups are compromised or untrustedDepends on image, application, and data complexityRebuild labour and downtimeMissing evidence if wiping happens too early
Trusted vendor decryptorStrain is confirmed and a reputable decryptor existsDepends on encryption volume and validationDecryption, reconstruction, and testingIncomplete recovery or unsafe payment decision

A ransom payment is not a restoration path. It is a separate legal, financial, and operational decision, and Canadian recovery data shows it still doesn't guarantee full restoration. Review your data backup and recovery strategies before an incident so the team knows which path is viable.

A Realistic 72-Hour Recovery Budget

A representative scenario makes the economics clearer. Consider a 60-person Canadian professional services firm hit by a mid-tier ransomware strain. The business loses access to core systems, staff can't work normally, and leadership must make decisions while the facts are still incomplete.

The first block is mobilisation. During hours zero through eight, the firm brings in incident response specialists, contacts the Cyber Centre, preserves evidence, and activates managed IT support. The planning range supplied for this scenario is CAD 8,000 to CAD 15,000, depending on the response team and scope.

Hours eight through twenty-four add forensic imaging, legal analysis of possible PIPEDA obligations, insurer coordination, and communications preparation. That block can add CAD 12,000 to CAD 25,000. The firm isn't paying for paperwork. It's paying for decisions that prevent evidence loss, missed notification duties, and contradictory statements.

A 72-hour recovery budget infographic showing costs for a 60-person firm during a ransomware attack.

Hours 24 through 72 are where costs spread

The largest block usually combines lost billable work, overtime, temporary infrastructure, rebuild effort, and deferred revenue. For this representative firm, that block may reach CAD 60,000 to CAD 120,000, depending on the sector, systems affected, and ability to operate manually.

Recovery windowPrimary workRepresentative cost range
Hours 0 to 8Response mobilisation, containment, and initial evidence collectionCAD 8,000 to CAD 15,000
Hours 8 to 24Forensics, legal review, insurance, and communicationsCAD 12,000 to CAD 25,000
Hours 24 to 72Downtime, restoration labour, temporary infrastructure, and deferred revenueCAD 60,000 to CAD 120,000

These are planning ranges, not a quotation or a universal forecast. They show why a ransom can distract leadership from the actual budget. Canadian reporting found ransom payments accounted for 18% of total incident costs, while downtime, infrastructure repair, forensics, legal, regulatory, and public relations work accounted for 82%. (TELUS and IDC data cited by GRMCCallum)

A vCIO reduces waste by assigning decision rights, sequencing vendors, protecting the restore environment, and keeping executives from repeatedly revisiting settled questions. Your continuity plan should define acceptable downtime and recovery priorities, much like guidance on business continuity for Florida firms, even though the regulatory context here is Canadian. Set the recovery time objective for each critical service before an attack forces you to guess.

Rebuild, Patch, and Reconnect Systems Safely

A clean image isn't enough. The rebuilt environment must use fresh credentials, current patches, active monitoring, and a controlled reconnection sequence. Otherwise, you may restore availability while leaving the original attacker's access intact.

Reset identity before restoring trust

Reset credentials across every account touched by the incident:

  • Privileged accounts: Domain administrators, cloud administrators, local administrators, and emergency accounts.
  • Service identities: Backup, database, integration, scheduled-task, and application service accounts.
  • Remote access: VPN, remote desktop, virtual desktop, and remote support credentials.
  • Communication systems: Mailbox passwords, collaboration tools, and SaaS administrator sessions.
  • Endpoint-stored secrets: Credentials saved or used on compromised workstations, browsers, scripts, and management tools.

Don't reuse pre-incident passwords. Revoke active sessions and tokens where the platform supports it, rotate API keys, and document which identities were reset and when.

Patch the entry point before reconnecting

Use forensic findings to prioritise the vulnerability or exploit chain that enabled access. Apply emergency operating-system and application patches, update antivirus and antimalware tools, and confirm firewalls enforce the intended rules. If no public decryption tool exists, the Cyber Centre says the affected device should be safely wiped and its operating system reinstalled before reconnection. (Cyber Centre prevention and recovery guidance)

Before a system touches production, verify that its EDR agent, central logging, alerting, and time synchronisation are active. Test that alerts reach someone who can respond. MFA must protect remote access, administrator accounts, and SaaS consoles before those services return to normal use.

Reconnect by segment, not all at once. Restore identity and core data services only after integrity checks, then critical business applications, then internal tools and general workstations. Monitor each wave for suspicious authentication, encryption activity, unexpected processes, or outbound traffic.

Finish with a written sign-off. The vCIO or designated security lead should record that credentials were reset, systems were patched, monitoring was verified, backups were checked, segmentation was enforced, and the environment was ready for production.

Harden the Environment After Recovery

Recovery closes the outage. Hardening changes the conditions that allowed the outage to happen. Set owners and deadlines instead of leaving the post-incident report as a document nobody revisits.

First 30 days

Focus on access and visibility:

  • Enforce MFA across remote access, administrator accounts, and SaaS platforms.
  • Rotate user, service, application, and API credentials.
  • Patch the exploited vulnerability across the fleet.
  • Confirm EDR coverage on every endpoint and server that should be monitored.
  • Separate backup administration from everyday production administration.

Days 31 to 60

Make the environment harder to traverse and easier to restore. Place production, backup, and administrative planes on separate network segments. Deploy application allowlisting on servers where the workload supports it, and convert backups to immutable, offline-tested snapshots. Run a full restore test, not just a job-success review.

Review email authentication, privileged access, vendor connections, remote administration, and alert escalation. A control that exists only in a policy document won't protect the business during the next incident.

A 30-60-90 day timeline infographic illustrating steps to harden an environment after a ransomware recovery process.

Days 61 to 90

Test the original attack chain with a purple-team exercise. Update the incident response runbook with the decisions, delays, and missing contacts discovered during recovery. Review cyber insurance requirements and document the improved control posture before renewal.

For a 25-person IT team, this sequence can compete with every operational demand. A 24/7 managed service, managed backup and disaster recovery, and vCIO-led remediation program can provide the monitoring, testing, escalation, and accountability that internal staff can't sustain alone. CloudOrbis Inc. offers managed IT, cybersecurity, backup and disaster recovery, and vCIO services for Canadian SMBs, while a zero-trust security model provides a useful framework for limiting trust after an incident.

The durable truth is simple. Recovery is a project plan. Hardening is the operating model.


CloudOrbis Inc. can help you assess backup validity, define recovery priorities, coordinate incident response, and build a 30-60-90 day remediation plan before the next ransomware event. Visit CloudOrbis Inc. to discuss managed IT, cybersecurity, backup and disaster recovery, and vCIO support for your Canadian organization.