Open cardosec

Case 2B172E · GRC · L4 Advanced

Ransomware Hits the Backup Server

Practise as: Incident drill

Live alertAt 03:10 the Veeam server and 40 VMs are encrypted; the last clean offsite copy is 30 hours old but your ERP has a documented RPO of 4 hours.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Activate IR and DR plans; isolate affected segments and stop replication so encryption does not spread to replicas.
  2. Use the BIA to restore in MTD order: identity (AD) and core network first, then ERP, then lower-tier systems.
  3. Restore into a clean, isolated environment and scan backups for persistence; if AD was compromised, reset krbtgt twice first.
  4. RPO is breached (30h vs 4h): quantify lost transactions, plan manual re-entry, and tell leadership plainly.
  5. Post-incident: immutable/air-gapped backups, separate backup admin credentials, regular restore tests against RPO.

If the interviewer pushes back

  • Leadership asks whether to pay for the decryptor to recover the missing 26 hours. How do you frame that decision?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.