Ransomware recovery is the process of containing a ransomware attack, removing the attacker, restoring systems and data from clean sources, and meeting legal reporting duties. If your Dallas business was just hit, do five things now: isolate affected systems without powering them off, switch to phone or personal channels, call your cyber insurer and a breach lawyer, preserve evidence, and report to the FBI. Do not wipe machines or contact the attackers yet.
This guide walks through those steps in order. It is built on the federal #StopRansomware Guide from CISA, the FBI, NSA and MS-ISAC, on NIST’s current incident response guidance, and on Texas breach notification law. It also draws lessons from the City of Dallas’s own 2023 ransomware recovery.
What Ransomware Recovery Means (and Why It Is Not Just Restoring Backups)
Ransomware recovery is wider than data restoration. A full recovery has four goals: stop the spread, remove every attacker foothold, bring systems back from known-clean sources, and satisfy legal and contractual obligations.
Restoring backups is only the third goal. Businesses that restore first and investigate later often restore the attacker’s access along with their files.
Double extortion: encryption plus data theft
Most modern attacks steal data before encrypting it. CISA calls this “double extortion”: criminals demand payment to unlock systems and to keep stolen data off leak sites. Some groups skip encryption and only threaten to publish.
This matters for recovery because good backups solve the encryption problem but not the data-theft problem. A business with perfect backups may still have a reportable data breach under Texas law.
Why attackers are usually inside for weeks first
The encryption you see is often the last step of a longer intrusion. The City of Dallas found that the Royal ransomware group entered its network through a compromised service account around April 7, 2023, and spent about four weeks exploring and copying roughly 1.169 TB of data before encrypting servers on May 3.
The practical lesson: assume the attacker has had time to create backdoors and new accounts. Recovery must find and close them.
What to Do in the First Hour After a Ransomware Attack
The first hour determines how much spreads and how much evidence survives. These steps follow CISA’s response checklist, adapted for a small or mid-sized business without a full security team.
- Isolate affected systems. Unplug network cables and disconnect Wi-Fi on infected machines. If many systems are affected, disconnect at the switch or firewall. Pause backup and replication jobs so they do not copy encrypted files over good ones.
- Do not power off or wipe — unless you cannot disconnect. Shutting down destroys evidence held in memory. CISA advises powering down only when isolation is impossible.
- Move communications out of band. Attackers often watch email and chat to see whether they have been detected. Use phone calls and personal devices until the investigation clears your systems.
- Call your cyber insurer first, then a breach lawyer. Many policies require you to use their approved responders. Working through counsel can help protect forensic findings under attorney–client privilege.
- Preserve evidence. Photograph the ransom note. Keep logs, firewall data and a list of affected machines. For cloud servers, take volume snapshots.
- Report to law enforcement. File with the FBI (details in the next section). The FBI may know of a working decryptor or the group’s tactics.
- Start an incident log. Record every action, decision and time. You will need it for insurers, regulators and the after-action review.
Mistakes that make ransomware recovery harder
- Wiping and reimaging before forensics, which erases how the attacker got in.
- Restoring backups onto a network that is still compromised.
- Resetting passwords before the attacker is removed, which alerts them and can trigger wider encryption.
- Contacting the criminals directly without counsel, insurer and sanctions screening.
- Assuming “no data was stolen” without checking outbound traffic logs.
[Experience callout — replace with a real, anonymized observation from your team] Example structure: “In [number] North Texas incidents we handled in [year range], the most common delay was [specific issue].” Do not publish this box unless the data is real.
Who to Call: Reporting a Ransomware Attack in Dallas and Texas
Reporting is free and does not commit you to anything. It also matters later: the US Treasury says it treats prompt reporting to law enforcement as a significant mitigating factor if a ransom payment raises sanctions questions.
| Contact | When to use it | How |
| FBI Dallas Field Office | Any ransomware attack on a North Texas organization | fbi.gov/contact-us/field-offices/dallas |
| FBI Internet Crime Complaint Center (IC3) | Online report for the record and FBI analysis | ic3.gov |
| CISA | Technical help, threat intelligence, voluntary reporting | 1-844-SAY-CISA (729-2472), Central@cisa.gov |
| Texas Attorney General | Required if a breach affects 250+ Texas residents | Online form on the AG’s website (verify URL before publishing) |
| Your cyber insurer | Before hiring vendors or negotiating | Number on your policy |
| Breach counsel | Before notifications or any payment decision | Insurer panel or your own firm |
| HHS Office for Civil Rights | If protected health information is involved | hhs.gov/hipaa |
Texas Legal Deadlines After a Ransomware Attack
Texas sets two separate clocks once a business determines that a breach of sensitive personal information occurred. Both run from the date of that determination, not from the date systems come back online.
The 60-day and 30-day clocks under §521.053
| Duty | Deadline | Trigger | Source |
| Notify affected individuals | As soon as practicable, no later than day 60 | Sensitive personal information of any individual acquired, or reasonably believed acquired | Tex. Bus. & Com. Code §521.053(b) |
| Notify the Texas Attorney General | As soon as practicable, no later than day 30 | Breach involves at least 250 Texas residents | §521.053(i), amended by SB 768 (2023) |
| Notify consumer reporting agencies | Without unreasonable delay | More than 10,000 people notified at one time | §521.053(h) |
Penalties are significant for small firms. A violation of Chapter 521 carries a civil penalty of $2,000 to $50,000. Failing to take reasonable action on the 60-day individual notice adds up to $100 per person per day, capped at $250,000 per breach.
Whether an encryption-only attack counts as a “breach” depends on whether personal data was acquired. That is a legal judgment based on forensic evidence, which is one reason counsel should lead.
Health, financial and multi-state data
Other rules can apply at the same time:
- Healthcare providers and their vendors have HIPAA breach notice duties to individuals and HHS.
- Public companies must disclose material cybersecurity incidents to the SEC on Form 8-K within four business days of determining materiality.
- Customers in other states may trigger those states’ notice laws.
- Contracts with customers or partners often require notice within days.
Should You Pay the Ransom?
The FBI and CISA do not recommend paying, and payment does not guarantee recovery. Microsoft’s guidance notes there is no assurance criminals will deliver a working key, and decryption is often slow and incomplete. The decision belongs to leadership, counsel and the insurer — not IT alone.
What the data says about payment and recovery
- Fewer victims are paying. The Verizon 2026 Data Breach Investigations Report, as summarized by the Cyber Readiness Institute, found 69% of small and mid-sized ransomware victims refused to pay, citing reliable backups.
- Recovery costs exceed most ransoms. Sophos’s State of Ransomware 2025 survey put the average recovery cost, excluding any ransom, at $1.53 million, down from $2.73 million in 2024. Organizations with $250 million or less in revenue saw median demands under $350,000.
- Small businesses are the main target. The same Verizon report found that, where victim size was known, about 96% of ransomware victims were small or mid-sized organizations.
The pattern is consistent: paying rarely removes the need for a full recovery, because the attacker’s access, stolen data and legal duties remain.
OFAC sanctions risk
Paying a ransom can violate US sanctions if the recipient is on a sanctions list or in a sanctioned country. The Treasury Department’s Office of Foreign Assets Control (OFAC) applies strict liability, meaning a business can be penalized even if it did not know. Its September 2021 advisory says strong security practices, prompt reporting to law enforcement and cooperation will weigh heavily in its response.
| Question | If yes | If no |
| Do we have clean, tested backups for critical systems? | Payment is rarely justified for decryption | Assess decryptor options and rebuild cost first |
| Was data stolen? | Paying will not undo the breach or notice duties | Focus on restoration |
| Has counsel screened the group for sanctions? | Proceed with documented decision | Do not pay |
| Has a free decryptor been published? | Check No More Ransom first | Continue assessment |
The Ransomware Recovery Process, Step by Step
NIST’s April 2025 revision of its incident response guidance, SP 800-61 Rev. 3, places response inside the six functions of the NIST Cybersecurity Framework 2.0: Govern, Identify, Protect, Detect, Respond and Recover. For a business in recovery, that translates into four practical phases.
Phase 1 — Contain and investigate
Forensic investigators determine how the attacker got in, which accounts they used, what they touched and whether data left the network. CISA’s checklist tells responders to hunt for new admin accounts, unusual VPN logins, tools such as Cobalt Strike, unexpected remote-management software and signs of large outbound transfers.
This phase also identifies “precursor” malware. A ransomware event is often evidence of an earlier, unresolved compromise.
Phase 2 — Eradicate and rebuild identity
Remove every persistence mechanism the investigation found. Then reset credentials across the environment, starting with domain admin, service and backup accounts. In Windows environments, Active Directory often needs careful recovery because attackers target domain controllers to spread ransomware.
CISA’s sequence matters here: reset passwords after the environment is cleaned, so the attacker cannot simply capture the new ones.
Phase 3 — Restore from clean backups
Restore in business-priority order, not technical order. A Dallas distributor might restore order processing and payroll before file shares.
- Pick a restore point from before the intrusion began, not just before encryption.
- Scan backup data for malware before restoring.
- Restore into an isolated network segment first.
- Rebuild servers from “golden images” — preconfigured, known-clean system templates — rather than repairing infected machines.
- Move systems into production only after they pass validation.
Phase 4 — Validate, monitor and learn
Watch restored systems closely for several weeks. Endpoint detection and response (EDR) tools and centralized logging help catch any foothold the investigation missed. Close the incident only when your designated IT or security lead confirms the criteria are met.
Finish with a written after-action review. It should name the entry point, the delays, what worked and the specific controls being added.
How Long Does Ransomware Recovery Take? A Dallas Case Study
Ransomware recovery usually takes weeks, not days, for an organization with many systems. The timeline depends on backup quality, how far the attacker spread and how quickly decisions get made.
The City of Dallas offers a documented local benchmark. According to its after-action report, as reported by SecurityWeek and TechTarget:
| Milestone | Date |
| Attacker gains access via compromised service account | About April 7, 2023 |
| Ransomware encryption begins | May 3, 2023 |
| First critical server (financial) restored | May 9, 2023 |
| Last affected server (waste management) restored | June 13, 2023 |
| Personal data breach reported to Texas Attorney General | August 7, 2023 |
Restoring all servers took just over five weeks. The city council approved $8.5 million for the response, and staff spent close to 40,000 hours on it.
A small business has far fewer systems than a city with more than 860 applications. But the pattern scales down: weeks of hidden access, data theft before encryption, critical systems first, and legal notices months after the attack.
How to Choose Ransomware Recovery Services in Dallas
The right partner can investigate, rebuild and coordinate with counsel and insurers. Before an incident, check these points:
- Insurer approval. Is the firm on your cyber insurance panel? If not, will your insurer pay for it?
- Forensics and recovery under one plan. Can they investigate and rebuild, or will you coordinate two vendors?
- Local response capacity. Can they put people on site in the Dallas–Fort Worth area within a stated time if needed?
- Clear scope and retainer terms. What is covered in the first 72 hours, and at what rate?
- Experience with your systems. Microsoft 365, Active Directory, VMware, cloud, line-of-business apps.
- Evidence handling. Do they follow chain-of-custody practices that will hold up for insurers and courts?
- References. Can they connect you with a past client in a similar industry?
[Service description — replace with verified facts about [Company]] State what [Company] actually provides (for example, incident response retainer, forensic investigation, backup restoration, Microsoft 365 recovery), your service area, and how to reach your response line. Avoid claims such as “fastest” or “guaranteed” unless you can prove them.
Building a Ransomware Recovery Plan Before the Next Attack
A ransomware recovery plan is a written, tested set of decisions made before an attack: who leads, who to call, which systems come back first, and where clean backups live. CISA recommends keeping a printed and offline copy, because attackers often encrypt the plan along with everything else.
Backups that survive ransomware
Attackers now deliberately target backups to force payment. A widely used benchmark is the 3-2-1-1-0 rule:
- 3 copies of data
- 2 different storage types
- 1 copy off-site
- 1 copy offline, air-gapped or immutable (cannot be changed or deleted)
- 0 errors in regular restore tests
Microsoft also recommends protecting the documents you need to recover — network diagrams, restore procedures and system inventories — because attackers target those too.
Controls that stop the most common entry points
The Dallas attack began with a compromised account, a pattern seen widely. The Verizon 2026 DBIR, as summarized by the Cyber Readiness Institute, reported that half of ransomware victims with prior credential exposure had credentials stolen within 95 days before the attack. Priority controls include:
- Multi-factor authentication on email, VPN, remote access and admin accounts, using phishing-resistant methods where possible.
- No remote desktop (RDP) exposed to the internet.
- Fast patching of internet-facing devices such as VPNs and firewalls.
- Separate admin accounts and least-privilege access.
- EDR on all servers and endpoints, monitored around the clock (in-house or through a managed detection and response provider).
- Network segmentation so one infected laptop cannot reach every server.
Test the plan
Run a tabletop exercise at least once a year with leadership, IT, legal and communications. CISA publishes free tabletop exercise packages. Also run a real restore test for at least one critical system each quarter and record how long it takes. That measured time is your actual recovery time objective (RTO), whatever the plan says.
Ransomware Recovery FAQs
Can you recover from ransomware without paying?
Yes, if clean and recent backups exist and the attacker is fully removed first. Free decryptors also exist for some older variants on the No More Ransom project. Paying does not guarantee a working key, and it does not reverse data theft.
What is the first thing to do after a ransomware attack?
Isolate infected systems from the network without powering them off. Then switch to out-of-band communication, call your cyber insurer and breach counsel, and preserve evidence before anyone wipes or rebuilds machines.
How much does ransomware recovery cost?
Costs vary widely by size and preparation. Sophos’s 2025 survey reported an average of $1.53 million excluding ransom, while the City of Dallas budgeted $8.5 million. Small businesses typically spend less in total but more relative to revenue.
Do I have to report a ransomware attack in Texas?
If sensitive personal information was acquired, yes. Texas requires notice to affected individuals within 60 days and to the Attorney General within 30 days when 250 or more Texans are affected. Reporting to the FBI is voluntary but strongly advised.
Is it illegal to pay a ransom?
Paying is not generally illegal in the US, but paying a sanctioned person or group can violate OFAC rules, even unknowingly. Have counsel screen the group and document the decision before any payment.
Does cyber insurance cover ransomware recovery?
Many policies cover forensics, legal fees, restoration, notification and business interruption, sometimes ransom too. Coverage often depends on calling the insurer early and using approved vendors. Check your policy’s exclusions and security requirements, such as MFA.
Will antivirus remove ransomware?
Antivirus can stop known ransomware files but rarely removes a human attacker who has stolen credentials and installed backdoors. Recovery needs a forensic investigation, credential resets and rebuilds from clean images.
How do I know my backups are clean?
Use a restore point from before the intrusion began, which forensics can identify. Scan backups for malware and restore into an isolated segment first. Immutable or offline backups are far less likely to have been tampered with.
Key Points for Dallas Business Leaders
Ransomware recovery succeeds when the order is right: contain, investigate, remove the attacker, then restore. Texas deadlines start when you determine a breach occurred, so legal counsel belongs in the first call, not the last. Paying rarely shortens recovery and can create sanctions risk.
The most effective step is preparation. Tested, immutable backups and multi-factor authentication turn a business-ending event into a difficult week.