Ransomware Data Recovery: How to Save Your Data

Ransomware Data Recovery

A ransomware attack uses malware to encrypt systems and data, for the purpose of demanding ransom for decrypting the files. In a ransomware attack, cybercriminals hold your data and systems hostage. If you don’t have data protection strategies in place, a ransomware attack can result in a catastrophic data breach and disrupt business continuity. Read on to learn how to create a ransomware data recovery strategy, including five methods for recovering ransomware encrypted files.

This is part of an extensive series of guides about network security.

In this article, you will learn:

What Is a Ransomware Attack?

A ransomware attack is an attack carried out with malware that encrypts your systems and data. Attackers demand a ransom to decrypt your data, allowing you to access it again. Often, attackers ask for payment in cryptocurrency since it is anonymous and less traceable. The ransoms demanded can be minor or can be for large sums of money.

ransomware protection ebook
DOWNLOAD THE RANSOMWARE PROTECTION BUYER’S GUIDE

How to Prevent Ransomware: Building Your Ransomware Data Recovery Strategy

The most effective way to protect against ransomware is to prevent attackers from gaining access in the first place. However, modern ransomware is no longer only about encrypting files. Many ransomware groups now use double extortion, where they steal sensitive data before encrypting systems and then threaten to leak or sell it if the victim does not pay. Some attacks may focus mainly on data theft and extortion, even without widespread encryption.

This means a ransomware recovery strategy must do more than restore files from backup. It should also help you understand what data was accessed, what may have been stolen, which systems can be trusted, and how quickly critical operations can be restored.

To build a strong ransomware data recovery strategy, start with your data, identities, systems, and backups.

Inventory and Classify Your Data

Create an inventory of your data so you know what information you have, where it is stored, who can access it, and how sensitive it is. Categories may include business-critical, regulated, confidential, proprietary, customer data, employee data, financial records, intellectual property, and operational data.

This step is especially important because of double extortion and leakware. If attackers steal data, recovery is not only a technical issue. You may also need to assess legal, regulatory, contractual, and reputational risks. A clear data inventory helps you quickly determine what may have been exposed and what response steps are required.

Your data inventory should cover:

  • On-premises file servers and databases
  • Cloud storage platforms
  • SaaS applications
  • Email and collaboration tools
  • Endpoint devices
  • Backup repositories
  • Third-party systems that store or process your data

Once your data is classified, apply stronger controls to the most sensitive and business-critical information.

Identify and Prioritize Your Endpoints and Systems

You need a complete inventory of endpoints, servers, cloud workloads, identities, and business applications. Ransomware often begins with a compromised endpoint, stolen credentials, exposed remote access service, phishing email, unpatched system, or vulnerable internet-facing application.

Categorize systems by their importance to business operations. For example, domain controllers, backup servers, file servers, databases, email systems, identity providers, remote access tools, and security platforms should be treated as high-priority assets.

For each critical asset, define:

  • Who owns it
  • What data it stores or accesses
  • Which users and systems depend on it
  • How it is backed up
  • How it can be rebuilt
  • What recovery time is acceptable
  • What security controls protect it

This helps you prioritize protection and recovery based on business impact rather than treating every system the same.

Reduce the Attack Surface

A recovery strategy should include prevention controls that make ransomware harder to deploy. Attackers commonly use phishing, stolen credentials, remote desktop services, VPNs, unpatched software, and misconfigured cloud services to gain access.

Important controls include:

  • Multi-factor authentication for email, VPN, remote access, administrator accounts, and cloud services
  • Strong password policies and password reuse prevention
  • Regular patching for operating systems, applications, VPNs, firewalls, and internet-facing systems
  • Endpoint detection and response tools
  • Email security controls and phishing protection
  • Disabling unused remote access services
  • Restricting Remote Desktop Protocol access
  • Least-privilege access for users and administrators
  • Network segmentation to limit lateral movement
  • Application allowlisting for critical systems
  • Centralized logging and monitoring

These controls reduce the chance that an attacker can move from one compromised account or device to the rest of the environment.

Protect Identities and Privileged Accounts

Modern ransomware attacks often target identity systems. If attackers compromise administrator accounts, domain controllers, or cloud identity platforms, they can disable security tools, delete backups, steal data, and deploy ransomware across many systems at once.

Protect privileged accounts with stronger controls, including:

  • Multi-factor authentication
  • Separate admin accounts for administrative work
  • Just-in-time or just-enough administrative access
  • Conditional access policies
  • Monitoring for unusual login activity
  • Blocking legacy authentication where possible
  • Regular review of privileged groups
  • Fast deactivation of unused or risky accounts

Your recovery plan should also include identity recovery. In a serious ransomware incident, you may need to reset passwords, revoke sessions, rotate keys, rebuild identity infrastructure, and verify that attackers no longer have access.

Plan for Data Theft, Not Just Encryption

Because ransomware groups may steal data before encryption, organizations should prepare for data exposure scenarios. This includes knowing how to investigate possible exfiltration, determine what data was accessed, and meet notification obligations.

Your plan should define how to:

  • Review logs for suspicious access and large data transfers
  • Identify affected users, systems, and data repositories
  • Determine whether regulated or customer data was involved
  • Preserve evidence for legal, insurance, and forensic review
  • Coordinate communications with legal, compliance, executives, customers, and regulators
  • Monitor for leaked data on extortion sites or other channels

Backups can help restore availability, but they cannot undo a data leak. For this reason, ransomware resilience must include data governance, access control, encryption, monitoring, and retention management.

Determine Your Recovery Plan

Create a ransomware recovery plan for all critical systems and data. The plan should define which systems must be restored first, how long recovery should take, and what minimum services are needed to resume operations.

For each critical system, document:

  • Recovery time objective
  • Recovery point objective
  • Backup location
  • Restore procedure
  • System owner
  • Required dependencies
  • Clean rebuild process
  • Validation steps
  • Communication process

A good recovery plan should assume that some systems may not be trustworthy after an attack. In many cases, the safest option is to rebuild systems from known-good images and restore clean data, rather than simply decrypting or repairing infected machines.

Protect Your Backups From Ransomware

Backups are only useful if they survive the attack. Many ransomware groups deliberately search for and destroy backups before encrypting systems. This means backups must be protected as critical infrastructure.

Use backup protections such as:

  • Offline backups
  • Immutable backups
  • Offsite backups
  • Separate backup credentials
  • Network segmentation for backup systems
  • MFA for backup administration
  • Backup encryption
  • Monitoring for backup deletion or modification
  • Regular restore testing

Avoid relying only on backups that are continuously connected to the production environment. If ransomware can access the backup system with the same credentials or network path, it may be able to encrypt or delete the backup as well.

5 Expert Tips that can help you better strengthen your Ransomware Data Recovery strategy

Jon Toor, CMO

With over 20 years of storage industry experience in a variety of companies including Xsigo Systems and OnStor, and with an MBA in Mechanical Engineering, Jon Toor is an expert and innovator in the ever growing storage space.

Use immutable backups with multi-layered security: Enhance backup security by combining immutable backups with advanced security measures like air-gapping. This ensures that even if ransomware attempts to encrypt backups, an untouchable version remains intact.

Regularly update and patch systems: Ransomware often exploits known vulnerabilities. Maintain a strict patch management process, ensuring all systems, including backup servers, are regularly updated to close security gaps.

Test recovery processes in a sandbox environment: Regularly test your ransomware recovery strategies in a controlled, sandbox environment. This ensures that your recovery process works effectively and that you can restore operations.

Encrypt backup data both at rest and in transit: Ensure that all backup data is encrypted, both when stored and during transfer. This adds an additional layer of protection in case backup media is intercepted or accessed by ransomware.

Create a detailed incident response plan: Develop a comprehensive ransomware-specific incident response plan. Include clear protocols for communication, containment, eradication, and recovery, ensuring that your team can respond swiftly and effectively under pressure.

How to Recover Ransomware Encrypted Files

If your files have already been encrypted by ransomware, do not rush to pay the ransom. Paying does not guarantee that you will receive a working decryption key, and it can also encourage further attacks. Instead, disconnect the infected device from the network, preserve the ransom note and a few encrypted file samples, and try the recovery methods below.

Before restoring anything, make sure the ransomware is no longer active. If the malware remains on the device, it may encrypt recovered files again or spread to other systems. For business environments, involve your IT or incident response team before reconnecting systems or restoring backups.

1. Isolate the Infected Device First

The first recovery step is containment. Disconnect the affected computer, server, or storage device from Wi-Fi, Ethernet, VPN connections, shared drives, and external storage. This helps prevent the ransomware from spreading to other devices or encrypting network backups.

Do not delete the ransom note, encrypted files, or suspicious files immediately. These can help identify the ransomware strain and determine whether a free decryptor is available. If the attack affects a business, document what happened, which systems were affected, and when the encryption was first noticed.

2. Restore From Clean Backups

The most reliable way to recover ransomware encrypted files is to restore them from a clean backup created before the infection. This can include backups stored on an external hard drive, a network backup system, a cloud backup platform, or an enterprise backup and disaster recovery solution.

However, ransomware often tries to encrypt or delete backups that are connected to the infected system. For this reason, the safest backups are offline, immutable, or otherwise protected from being changed by malware. Before restoring, confirm that the backup was created before the ransomware infection and scan it for malware where possible.

A strong ransomware backup strategy should include:

  • Multiple backup copies
  • At least one offline or isolated copy
  • Regular restore testing
  • Versioned backups that allow rollback to a clean point in time
  • Immutable or write-protected backups for critical data

When restoring, prioritize the most important systems and files first. In business environments, restore to clean or rebuilt systems rather than placing recovered files back onto a device that may still be compromised.

Related Article: Ransomware Backup – How to Get Your Data Back

3. Use Windows File History and Previous Versions

Windows File History can help recover earlier versions of personal files and folders, but only if it was enabled before the ransomware attack. File History saves copies of selected files to another drive or network location, allowing you to restore a previous version after files are changed, deleted, or damaged.

To restore files with File History:

  1. Open Control Panel.
  2. Go to System and Security.
  3. Select File History.
  4. Choose Restore personal files.
  5. Browse to the folder or file you want to recover.
  6. Select a version from before the ransomware attack.
  7. Restore the file to a safe location.

You can also try restoring a previous version directly from File Explorer:

  1. Right-click the affected file or folder.
  2. Select Properties.
  3. Open the Previous Versions tab.
  4. Choose a version from before the attack.
  5. Select Open to verify it, Copy to save it elsewhere, or Restore to replace the encrypted version.

This method has limitations. It only works if File History, restore points, or another Windows backup feature had already created usable previous versions. Some ransomware also deletes Windows shadow copies to prevent this type of recovery.

4. Use Windows System Restore Carefully

Windows System Restore can roll back system files, registry settings, drivers, and installed programs to an earlier restore point. This may help if ransomware damaged Windows settings or made the system unstable.

However, System Restore is not a full file recovery method. It is mainly designed to recover system configuration, not personal documents, photos, databases, or business files. It may remove malicious system changes, but it usually will not decrypt files.

To use System Restore:

  1. Search for Recovery in the Windows Start menu.
  2. Open Recovery from Control Panel.
  3. Select Open System Restore.
  4. Choose a restore point created before the ransomware infection.
  5. Follow the prompts to restore the system.

If Windows will not boot, you may be able to access System Restore from the Windows Recovery Environment. After using System Restore, scan the device for malware before restoring files or reconnecting it to the network.

5. Recover Cloud Files With Version History

If your files were synced to a cloud service, check whether the service has version history or ransomware recovery features. This can be especially useful when ransomware encrypts local files and the encrypted versions sync to the cloud.

For example, OneDrive can help users restore earlier file versions, and Microsoft 365 may guide users through ransomware detection and recovery steps. Depending on your subscription and configuration, you may be able to restore individual files, roll back multiple files, or restore a OneDrive account to a previous point in time.

To recover cloud-synced files:

  1. Sign in to the cloud storage account from a clean device.
  2. Check version history for affected files.
  3. Restore versions created before the ransomware attack.
  4. Review deleted items or recycle bin folders.
  5. For business accounts, ask an administrator about bulk restore options.

This method depends on retention limits and whether the ransomware deleted, overwritten, or resynced the affected files. Act quickly, because older versions and deleted files may only be retained for a limited time.

6. Try Ransomware Decryption Tools

Ransomware decryption tools are free utilities designed to unlock files encrypted by specific ransomware families. They are usually created by cybersecurity companies, law enforcement partners, or malware researchers after a ransomware strain is cracked, keys are recovered, or a flaw is found in the encryption process.

Before downloading a decryptor, identify the ransomware strain. You can often do this by checking the ransom note, the encrypted file extension, the attacker’s email address, or the ransom payment page. You can also use an identification service such as ID Ransomware, which lets you upload a ransom note or encrypted file sample to help determine the ransomware family.

Trusted free ransomware decryption resources include:

  • No More Ransom – A public-private project supported by law enforcement and cybersecurity companies. It provides free decryptors for many ransomware families and is one of the best first places to check.
  • ID Ransomware – A free identification tool that helps determine which ransomware strain encrypted your files and whether a known decryptor may exist.
  • Emsisoft Free Ransomware Decryption Tools – A large collection of free decryptors for specific ransomware variants.
  • Avast Free Ransomware Decryption Tools – Free decryptors for selected ransomware families.
  • Kaspersky No Ransom – Free ransomware decryptors and ransomware recovery information from Kaspersky.
  • Bitdefender Free Tools – Free decryptors released for certain ransomware families, often in cooperation with law enforcement or security researchers.
  • Trend Micro Ransomware File Decryptor – A free tool designed to attempt decryption for supported ransomware families.

To use a ransomware decryptor safely:

  1. Identify the ransomware strain.
  2. Remove or isolate the malware first so it cannot re-encrypt files.
  3. Download decryptors only from reputable sources.
  4. Read the tool’s instructions and limitations.
  5. Test the decryptor on copies of encrypted files before running it broadly.
  6. Keep the original encrypted files until you confirm recovery worked.

Decryption tools are not available for every ransomware strain. Even when a tool exists, it may only work for specific versions of that ransomware. If no decryptor is currently available, keep a copy of the encrypted files and ransom note. A decryptor may become available later if law enforcement seizes keys or researchers find a weakness.

Ransomware Data Recovery With Cloudian

Cloudian® HyperStore® is a massive-capacity object storage device that can help you store data in a way that is resilient to Ransomware and recover more easily from attacks.

HyperStore can store up to 1.5 Petabytes in a 4U Chassis device, allowing you to store up to 18 Petabytes in a single data center rack. HyperStore comes with fully redundant power and cooling, and performance features including 1.92TB SSD drives for metadata, and 10Gb Ethernet ports for fast data transfer.

Cloudian storage devices can be deployed:

  • As a backup target for data protection applications including Rubrik, Commvault, and VERITAS.
  • As an enterprise synch-and-share solution allowing client systems to synchronize data and maintain a copy of critical files on a central repository.
  • As a file server used by client systems to directly save important files.

  • Write Once Read Many (WORM)—Cloudian ensures that data, once written, cannot be changed or deleted until a specified time has passed. Because the data cannot be modified, it cannot be encrypted rendering ransomware ineffective. WORM is available as a system-level function of Cloudian secure storage devices. Read more about Cloudian’s S3 Object Lock.
  • Data Versioning—Cloudian creates a new copy of the data when changes are made, while retaining the original copy for a specified period. If malware encrypts a file, a copy of the unencrypted file still exists.

Learn more about Cloudian’s ransomware backup solutions.

Learn More About Ransomware Data Recovery

Keeping Up with Data Protection Regulations

Data Availability: Ensuring the Continued Functioning of Business Operations

How You Can Maintain Secure Data Storage

Data Encryption: An Introduction

Continuous Data Protection

Data Protection in the Cloud: Challenges and Best Practices

See Additional Guides on Key Network Security Topics

Together with our content partners, we have authored in-depth guides on several other topics that can also be useful as you explore the world of network security.

DDoS protection

Authored by Imperva

Microsegmentation

Authored by Tigera

Event Log

Authored by Exabeam

Get Started With Cloudian Today

Cloudian
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.