Ransomware outcomes are decided before the encryption starts. The organisations that recover quickly have backups the attacker cannot reach, privileged access that resists credential theft, network segmentation that limits spread, and a recovery path they have actually tested. The ones that pay usually discover their backups were reachable from the same domain that was compromised.
The question is not whether you have backups. It is whether the attacker can reach them with the credentials they just stole.
What problem does this solve?
Backups are reachable by the attacker. Where backup infrastructure authenticates against the same directory as everything else, a domain compromise includes the backups, and that is the single most common reason organisations pay.
Privileged accounts are compromised early. Standing administrative rights and reused credentials turn a single foothold into estate-wide access within hours.
The network is flat. Without segmentation, encryption spreads across servers, file shares and backup targets at the speed of the network rather than being contained to one zone.
EDR exclusions undermine detection. Exclusions added years ago for performance, often covering exactly the directories attackers use, remain in place and unreviewed.
How the solution works
We test the recovery path rather than the backup job. A backup that completes but cannot be restored under incident conditions — with the domain compromised and staff unavailable — is not a control.
Containment capability is designed explicitly: who can isolate a host or a segment at 03:00, with what authority, and how long that decision actually takes.
- 1Ensure backups are immutable or offline and authenticate separately from the production directory.
- 2Remove standing administrative rights, introduce just-in-time elevation, and separate administrative identities.
- 3Contain spread between user networks, servers, backup infrastructure and OT.
- 4Audit exclusions, confirm agent coverage on servers, and verify detections actually fire.
- 5Restore critical systems in a test under realistic constraints and record how long it truly takes.
- 6Agree in advance who may isolate systems out of hours and under what conditions.
Key capabilities
Backup resilience review
Verification that backups are immutable or offline and unreachable from a compromised domain.
availablePrivileged access hardening
Removal of standing rights with just-in-time elevation and session recording.
availableSegmentation design
Containment boundaries between user, server, backup and OT environments.
availableEDR and detection review
Coverage and exclusion audit with validation that detections fire in practice.
availableRecovery rehearsal
Timed restoration exercise under realistic incident conditions.
availableIncident response retainer
Defined containment authority and response capability agreed before it is needed.
availableIndustry use cases
Government entities
Service continuity obligations where extended downtime has public consequences.
Logistics and manufacturing
Operations where downtime cost per hour exceeds any plausible data loss cost.
Healthcare
Clinical systems where recovery order is a patient-safety decision, not only a technical one.
Groups with shared infrastructure
Where one compromised entity can reach the others through shared directory or network.
UAE & GCC considerations
Regional entities frequently run shared services across multiple group companies with a single directory, which means a compromise in the least protected entity reaches the most critical one. Segmentation between group entities is often the highest-value control available. Reporting obligations to national authorities affect incident handling and evidence preservation, so the response plan should state who notifies whom and within what period. Recovery planning must account for the local working week and holiday periods, when staffing is thin and attackers are demonstrably more active. Where operational technology is present, recovery sequencing becomes a safety decision requiring engineering input, not only an IT one.
Implementation approach
- 1Backup resilience assessment Establish whether backups survive a full domain compromise; this is the first question, not the last.
- 2Privileged access remediation Remove standing rights and separate administrative identities from daily-use accounts.
- 3Segmentation of critical zones Contain backup infrastructure, servers and OT from the general user network.
- 4Detection validation Audit EDR coverage and exclusions, then confirm detections fire against realistic techniques.
- 5Recovery rehearsal Run a timed restore of critical systems and document the real recovery time objective.
- 6Response readiness Agree containment authority, notification duties and an out-of-hours contact path.
Security & deployment
The recovery plan itself is a target. Store it, along with credentials needed for recovery, somewhere that survives the compromise of the environment it describes — printed or in an isolated system, not only on the file share that will be encrypted. Break-glass credentials should be offline, sealed and monitored for use. Immutability is the property that matters for backups, not merely offsite storage: replicated backups reachable with stolen credentials are replicated targets. Test restoration under the assumption that the directory is unavailable, because that is the actual condition during an incident and it invalidates many recovery procedures that work fine in normal conditions.
Limitations & prerequisites
- No control set eliminates ransomware risk; the objective is to reduce likelihood and make recovery survivable without paying.
- Backup immutability protects the data but does not shorten recovery time, which is usually governed by rebuild sequence and available staff.
- Segmentation depends on knowing application dependencies; incomplete knowledge produces either outages or ineffective boundaries.
- EDR reduces but does not remove risk, and attackers actively attempt to disable or evade agents on servers.
- Recovery rehearsals consume real time from teams who are already busy, and untested plans are common precisely for that reason.
- Cyber insurance may require specific controls and specific handling during an incident; those obligations should be read before an incident, not during one.
What separates fast recovery from paying
The controls below are not exotic. The difference is whether they were verified before the incident.
| Factor | Recovers quickly | Usually pays |
|---|---|---|
| Backup reachability | Immutable or offline, separate authentication | Reachable with domain credentials |
| Privileged access | Just-in-time, separated identities | Standing rights, reused credentials |
| Network | Segmented by impact | Flat |
| Detection | Validated coverage, reviewed exclusions | Agent gaps, stale exclusions |
| Recovery | Rehearsed and timed | Assumed to work |
| Containment authority | Agreed in advance | Decided during the incident |
FAQ
Only if the attacker cannot reach them with the credentials they steal. If backup infrastructure authenticates against the same directory as production, assume a domain compromise includes the backups. Immutable or offline copies with separate authentication are what makes the difference.
Unknown until you rehearse it. Most organisations discover their real recovery time is several times the assumed figure, because rebuild order, credential availability and staffing under pressure are not captured in a backup report.
It is a business and legal decision rather than a technical one, and it should be considered in advance with legal counsel and any insurer. Payment does not guarantee usable decryption and does not remove the attacker's access, so recovery work follows either way.
No. EDR improves detection and response but attackers specifically target agent gaps and exclusions. It works as part of a set that includes protected backups, controlled privilege and segmentation — not as a substitute for them.
Backups the attacker cannot reach. It is the control that most directly determines whether paying is even considered. Removing standing privileged access is a close second because it governs how far the attacker gets.
That must be agreed in advance, in writing, with named individuals and defined authority. Deciding during an incident costs hours, and those are the hours in which encryption spreads.
Tell us the environment and what you are trying to protect.
Send the platforms in scope, current versions, and whether this is a design, a hardening exercise or an active problem. We reply with a written assessment: what we would verify first, which controls are missing against a recognised framework, and what can be fixed by configuration versus what needs new capability. When Swedish Technology can help, we scope the work with sequence, effort and acceptance criteria before you commit.
Request a Security AssessmentSources & evidence
- NIST — Cybersecurity Framework and AI Risk Management Framework — control structure and AI risk vocabulary referenced in governance sections
- MITRE ATT&CK — adversary technique reference used for detection coverage discussion
- UAE Cybersecurity Council — national cybersecurity direction and requirements for UAE entities
- Vendor product documentation — configuration behaviour and platform limits; confirm against your own release
Vendor and product names are trademarks of their respective owners; references are for technical context and do not imply partnership, certification or endorsement unless stated on the vendor's official pages.