Free resiliency assessment

Expert guidance, applied to what you already own

← Field Notes index No. 02 Resilience & Recovery Filed · July 2026 9 min read

When ransomware hits, the district stops.

A recovery playbook for schools and local government. Backups are one input; the plan is the sequence, and this is the sequence that brings identity, phones, payroll, transportation and critical services back within hours.

Recovery sequence ready
01Incident brief

The bad morning

The ransomware call rarely starts with “our files are encrypted.” It starts with something more immediate: “the phones are down, the badge readers stopped working, and the cameras are dark.”

When Uvalde CISD confirmed ransomware in September 2025, the district canceled four days of classes because the attack disrupted phones, air-conditioning controls, security cameras, visitor management, and Skyward. A modern district attack takes the data hostage and takes the school day with it.

02Threat model · Why the restore path fails

The attack before the attack

Backups are usually an early target. Modern ransomware crews map the environment, escalate access and locate the recovery infrastructure before they encrypt anything. If the backup plane trusts the same identity system the attacker controls, one stolen administrator account can compromise production and recovery together.

The fix is architectural. At least one recovery copy must be immutable inside its retention window and inaccessible through production credentials. If every copy can be changed by the same administrator, every copy is inside the blast radius.

Shared trust
Production and backup administration use the same identity plane.
One compromise reaches both environments.
Untested recovery
A successful backup job proves data was written, and says little about whether operations can return on time.
Green check, unknown outcome.
Vendor blast radius
The PowerSchool incident showed how one third-party credential can expose data across many districts.
Your plan must include their failure.
03Metrics

The two numbers that matter

Two approved figures, RTO and RPO, turn a backup into an operating commitment.

“We have backups” tells leadership little about when service returns. Leadership needs two approved numbers for every critical workload, and IT needs a timed test showing the environment can meet them.

RTO
Recovery time objective · hours
How long can the service stay unavailable before the district or municipality stops functioning?
RPO
Recovery point objective · lost data
How much recent data can the organization accept losing between the last safe copy and the attack?
04Recovery clock · The first 72 hours

Recover in a rehearsed sequence.

The first 72 hours decide whether this is a hard week or a lost month. These are illustrative targets; your own recovery time comes from rehearsing your own environment with a stopwatch.

Recovery sequenceT+0 → T+72h+
01 T+0 Contain and declare
Minutes matter

Isolate the affected network, call your insurer, counsel and incident-response firm, and move communication to a channel outside the attacker's reach.

Cut lateral movementPreserve evidenceActivate out-of-band communications
02 T+0–4h Restore the foundation
Tier 0 systems

Recover identity and core networking into a clean environment first, because every other system depends on restored trust and connectivity.

Identity servicesDNS, DHCP, and core networkPrivileged access controls
03 T+4–24h Reopen operations
Tier 1 systems

Bring back the systems that determine whether school opens and public services continue. Use the immutable copy as the source of truth.

SIS and payrollPhones and transportationSafety and visitor systems
04 T+24–72h Recover in order
Tier 2 systems

Restore the remaining environment in a business-approved sequence. Validate every workload before reconnecting it to production.

Department applicationsFile servicesValidation and monitoring
05 T+72h+ Validate and close
From restored to recovered

Service comes back before trust does. Confirm eradication with your forensics team, rotate every credential, and keep heightened monitoring in place until the environment has re-earned normal operations.

Forensic close-out and root-cause fixFull credential rotationAfter-action review and plan updates
Recovery principle

Isolate affected systems and restore from a clean, offline backup. CISA's StopRansomware guidance recommends maintaining offline backups and regularly testing their availability and integrity. Read the CISA guide

05Definition of done · Beyond the first 72 hours

Restored service is an early milestone

The restore sequence ends in days. Full recovery takes weeks, and much of it is invisible: proving the attacker is out, proving the data is right, and closing the entry point they used. Re-entry through leftover access is how a two-day outage becomes a repeat incident.

Full recovery is declared on evidence: a forensic close-out, validated data, rotated credentials, a documented timeline for the insurer and the state, and an after-action review that changes the plan.

Eradication proven
Forensics closes the entry point, persistence is hunted down, every credential is rotated, and monitoring watches for re-entry.
The attacker is out, and you can show it.
Data validated
System owners check restored records against known-good points. Grades, payroll, permits: the departments confirm the data is correct as well as present.
Restored data still needs checking.
Readiness rebuilt
A fresh immutable baseline, replication re-enabled, the runbook rewritten with what the incident taught, and the next timed failover on the calendar.
Recovery ends where rehearsal restarts.
06Operating model · Managed recovery, two ways

Recovery already standing by

Build the lifeboat before it is needed.

A district can build all of this in-house. The open question is whether a lean IT team can maintain a second recovery environment, protect it from the production blast radius, rehearse it on a schedule, and keep the documentation current while running everything else. ModernOps offers recovery two ways for that reason.

Model A · Managed DR

Your infrastructure, run with discipline.

Keep the backup and DR investment you already own. ModernOps operates and documents it: immutability verified, restore order written down, restores tested and timed on a schedule, and evidence reports that leadership and insurers can read.
Co-managed on your equipment
Model B · Hosted DRaaS

We run the recovery side for you.

Replication flows to a recovery environment ModernOps hosts and operates: pre-staged, isolated from district credentials, and rehearsed with your team. On the bad morning, failover starts with a call to an engineer who already knows the environment.
Hosted BaaS & DRaaS in PA and AZ
Recovery requirementBuilt during the incidentRun by ModernOps
Clean environmentDesigned under pressurePre-staged and isolated in advance
Recovery copyMay share production trustLocked, immutable snapshots
RTO and RPOAssumed until testedDefined, tested, and timed
Bad-morning supportStart with a new ticketCall an engineer who knows the environment
DocumentationIn one engineer's headRunbooks and test evidence kept current

In either model, recovery stops being a binder and becomes an operation. Replication runs continuously, restores are tested on a schedule and timed, and documentation stays current because keeping it current is part of the job. The results become evidence for leadership, auditors and insurers. Backup is delivered as BaaS on enterprise storage with immutability built in, and failover is covered by DRaaS with defined RTO and RPO.

07Assessment

Could you prove recovery is ready?

The 60-second check
0/5Unmeasured
This is a quick screen rather than a resilience score. Any unchecked item belongs in the recovery plan.
08Primary reading

Sources

Ryan Beglau
Filed from Conshohocken, PA · July 2026
09Before you need it

Find your real recovery window before someone else does.

The free Rapid Infrastructure Resiliency Assessment scores backup, recoverability, immutability and failure tolerance in a few hours. It is remote-first, carries no obligation, and ends with a prioritized list of findings you can act on.

Or call 484-429-9328. You will talk to the engineer who would take the bad-morning call.

← All field notes Field Notes · No. 02 · Ryan Beglau · ModernOps, LLC