Find out whether the firm can restore its critical systems, how long recovery may take, and who makes the decisions during a ransomware incident.
The difficult questions usually appear after systems are already down: Is the backup clean? Can the attacker delete it? How long will the restore take? Does the practice-management system work before identity and networking are restored? Who can authorize the firm to reconnect?
We answer those questions in advance. The plan identifies protected copies, secures compromised accounts, puts systems in a sensible restore order, and names the people who can make each decision. Then we test the parts that matter.
The decisions to make before systems go down. How much downtime and data loss the firm can accept. We set realistic targets for critical systems based on deadlines, client work, payroll, billing, and how long the firm can operate without each service. A backup the attacker cannot easily take with them. We separate backup administration from the live environment and add protected copies, suitable retention, monitoring, and deletion safeguards. A restore test that reflects real work. We test whether the data is intact, the dependencies work, the timing is realistic, and staff can actually use the restored system. Problems are recorded and corrected. Compromised access secured before reconnection. Accounts, sessions, tokens, administrator roles, and trusted applications are addressed before restored systems return to the network. A recovery order based on dependencies. Identity, networking, core platforms, data, applications, integrations, and user access are restored in an order that reflects how the firm actually operates. Named decision makers. Technical authority, legal and insurer contacts, communications, incident records, and approval to restore are assigned in advance. The middle of an incident is the wrong time to debate who can decide.
What your team has in hand when recovery begins. A record of the restore test. Dates, scope, timing, failures, owners, and corrective work show what was tested and whether it met the firm’s needs. A map of what depends on what. The team can see which identity, network, data, and integration services each critical system needs before it will work. A recovery runbook. Containment, clean-copy selection, restore order, validation, communication, and approval to return are written down before the firm needs them. A clear view of backup protection. The record shows retention, protected copies, administrative separation, alerting, and whether every critical system is covered.
A good fit for firms that have backup but cannot demonstrate a complete recovery from it; are preparing for an insurance renewal, client review, or business-continuity exercise; depend on Microsoft 365 or Google Workspace plus practice-management, accounting, or other cloud applications.
Important limits. A readiness review cannot guarantee the same recovery time in every incident. Legal, privacy, contract, insurance, and client-notification decisions remain with your advisers and leadership. If ransomware is active now, start incident response. A readiness exercise is for the work done before or after an event.