The bad morning
The ransomware call rarely starts with “our files are encrypted.” It starts with something more immediate: “the phones are down, the badge readers stopped working, and the cameras are dark.”
When Uvalde CISD confirmed ransomware in September 2025, the district canceled four days of classes because the attack disrupted phones, air-conditioning controls, security cameras, visitor management, and Skyward. A modern district attack takes the data hostage and takes the school day with it.
The attack before the attack
Backups are usually an early target. Modern ransomware crews map the environment, escalate access and locate the recovery infrastructure before they encrypt anything. If the backup plane trusts the same identity system the attacker controls, one stolen administrator account can compromise production and recovery together.
The fix is architectural. At least one recovery copy must be immutable inside its retention window and inaccessible through production credentials. If every copy can be changed by the same administrator, every copy is inside the blast radius.
The two numbers that matter
“We have backups” tells leadership little about when service returns. Leadership needs two approved numbers for every critical workload, and IT needs a timed test showing the environment can meet them.
Recover in a rehearsed sequence.
The first 72 hours decide whether this is a hard week or a lost month. These are illustrative targets; your own recovery time comes from rehearsing your own environment with a stopwatch.
01 T+0 Contain and declare
Isolate the affected network, call your insurer, counsel and incident-response firm, and move communication to a channel outside the attacker's reach.
02 T+0–4h Restore the foundation
Recover identity and core networking into a clean environment first, because every other system depends on restored trust and connectivity.
03 T+4–24h Reopen operations
Bring back the systems that determine whether school opens and public services continue. Use the immutable copy as the source of truth.
04 T+24–72h Recover in order
Restore the remaining environment in a business-approved sequence. Validate every workload before reconnecting it to production.
05 T+72h+ Validate and close
Service comes back before trust does. Confirm eradication with your forensics team, rotate every credential, and keep heightened monitoring in place until the environment has re-earned normal operations.
Isolate affected systems and restore from a clean, offline backup. CISA's StopRansomware guidance recommends maintaining offline backups and regularly testing their availability and integrity. Read the CISA guide
Restored service is an early milestone
The restore sequence ends in days. Full recovery takes weeks, and much of it is invisible: proving the attacker is out, proving the data is right, and closing the entry point they used. Re-entry through leftover access is how a two-day outage becomes a repeat incident.
Full recovery is declared on evidence: a forensic close-out, validated data, rotated credentials, a documented timeline for the insurer and the state, and an after-action review that changes the plan.
Recovery already standing by
A district can build all of this in-house. The open question is whether a lean IT team can maintain a second recovery environment, protect it from the production blast radius, rehearse it on a schedule, and keep the documentation current while running everything else. ModernOps offers recovery two ways for that reason.
Your infrastructure, run with discipline.
We run the recovery side for you.
| Recovery requirement | Built during the incident | Run by ModernOps |
|---|---|---|
| Clean environment | Designed under pressure | Pre-staged and isolated in advance |
| Recovery copy | May share production trust | Locked, immutable snapshots |
| RTO and RPO | Assumed until tested | Defined, tested, and timed |
| Bad-morning support | Start with a new ticket | Call an engineer who knows the environment |
| Documentation | In one engineer's head | Runbooks and test evidence kept current |
In either model, recovery stops being a binder and becomes an operation. Replication runs continuously, restores are tested on a schedule and timed, and documentation stays current because keeping it current is part of the job. The results become evidence for leadership, auditors and insurers. Backup is delivered as BaaS on enterprise storage with immutability built in, and failover is covered by DRaaS with defined RTO and RPO.