Case 2B172E · GRC · L4 Advanced
Ransomware Hits the Backup Server
Practise as: Incident drill
Live alertAt 03:10 the Veeam server and 40 VMs are encrypted; the last clean offsite copy is 30 hours old but your ERP has a documented RPO of 4 hours.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Activate IR and DR plans; isolate affected segments and stop replication so encryption does not spread to replicas.
- Use the BIA to restore in MTD order: identity (AD) and core network first, then ERP, then lower-tier systems.
- Restore into a clean, isolated environment and scan backups for persistence; if AD was compromised, reset krbtgt twice first.
- RPO is breached (30h vs 4h): quantify lost transactions, plan manual re-entry, and tell leadership plainly.
- Post-incident: immutable/air-gapped backups, separate backup admin credentials, regular restore tests against RPO.
If the interviewer pushes back
- Leadership asks whether to pay for the decryptor to recover the missing 26 hours. How do you frame that decision?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.