Ransomware recovery is the work of restoring operations and meeting legal disclosure duties after an extortion attack, and in Texas both clocks start the moment you determine a breach occurred. Most businesses only watch the first one. The second is where the penalties live.
The short version. Contain in the first 4 hours without powering anything off, scope what was taken by hour 24, then restore identity systems before anything else. Texas gives you 60 days to notify affected residents and 30 days to notify the Attorney General once 250 people are involved. Paying rarely returns everything. Our cybersecurity services page covers the prevention half of this.
Nobody reads a ransomware recovery guide on a normal Tuesday. If you are here because a screen in your office is displaying a ransom note, skip down to the containment section and come back for the rest later. If you are here to prepare, you are doing the thing that separates a 5-day recovery from a 5-week one.
What follows is the sequence, the deadlines Texas law stacks on top of it, and figures from published research rather than vendor marketing. It assumes a business somewhere between 20 and 300 employees, no dedicated security team, and a cyber policy nobody has read closely. That describes most of the companies we get called into.
What ransomware recovery actually involves
Ransomware recovery is the process of returning a business to normal operations after an extortion attack, covering containment, forensic scoping, system restoration, and legal notification. It is not a synonym for restoring a backup. Restoring a backup is 1 task inside it, and rarely the one that takes longest.
That distinction matters because of how these attacks changed. Broadcom’s Threat Hunter Team counted 6,182 extortion attacks claimed in 2025, a 23% rise over 2024, but only 4,737 of them involved encryption. Roughly 1 in 4 now skips encryption entirely and runs on stolen data alone. If your recovery plan is a restore procedure, it has no answer at all for the attack that never encrypted anything.
Size offers no cover either. The Verizon 2025 Data Breach Investigations Report found ransomware present in 88% of breaches at small and mid-sized businesses, against 39% at large organizations. Meanwhile the FBI’s Internet Crime Complaint Center logged more than 3,600 ransomware complaints in its 2025 Internet Crime Report, with Akira, Qilin, INC Ransom, BianLian, and Play driving the volume. Texas sits among the handful of states reporting the most cyber-enabled crime and the largest losses.
Why the first 72 hours decide the next 6 months
Two clocks start when the ransom note appears, and almost everyone only watches one.
The restore clock is technical. How fast can you get people working again. Sophos found 53% of victims fully recovered inside 1 week in 2025, up from 35% the year before, so this clock is genuinely getting faster.
The disclosure clock is legal, and it does not care how the restore is going. Texas gives you 60 days from determining a breach occurred to notify affected residents, plus 30 days to notify the Attorney General once 250 or more Texans are involved. That clock starts on a date somebody chooses. Choosing it badly, in either direction, gets expensive.
Here is the honest version of the framing everyone uses, including this post. Recovery does not finish in 72 hours for anybody. What finishes in 72 hours is your ability to change your mind. By then you have either told your insurer or you haven’t, preserved forensic evidence or overwritten it, and either found a clean restore point or discovered you don’t have one. Those doors close early and they close quietly.
| Window | Primary goal | The decision that gets locked in |
|---|---|---|
| Hour 0 to 4 | Contain the spread | Whether forensic evidence survives |
| Hour 4 to 12 | Notify carrier, engage counsel | Whether your cyber policy pays |
| Hour 12 to 24 | Scope what was encrypted and taken | Whether you know if data left the building |
| Hour 24 to 48 | Rebuild identity | Whether the attacker returns through the same door |
| Hour 48 to 72 | Restore revenue systems | How long the business stays unable to bill |
| Day 4 onward | Notify and harden | Whether you clear the Texas 60-day deadline |
Hours 0 to 4, contain the spread without destroying evidence

Containment is the only thing that matters in the first 4 hours. Every minute of attacker access means more encrypted files and more data walking out the door. But the way most people contain makes the following 68 hours considerably worse.
- Isolate, do not power off. Pulling cables or disabling switch ports stops the spread. Shutting a machine down wipes memory, and memory holds the encryption keys, running processes, and attacker tooling. The CISA #StopRansomware Guide treats evidence preservation as part of containment, not a step afterwards.
- Disable the accounts, not just the endpoints. Modern intrusions run on stolen credentials. Quarantine 40 laptops and leave a compromised domain admin account live, and you have relocated the attacker rather than removed them.
- Get off the compromised network to communicate. Assume email and chat are being read. Move the response team to phones and a channel that never touches the affected environment.
- Photograph the note and log timestamps by hand. Screenshot the ransom message, record when each symptom appeared and who saw it. This becomes the insurance claim and, potentially, the regulator’s file.
- Stop scheduled backup jobs immediately. A job running against an encrypted source will cheerfully overwrite your last clean copy. We have watched that destroy a viable restore point around hour 3.
- Call your incident response contact before touching anything else. If you have an MSP or a retained response firm, this is the call. If you don’t, your insurer’s hotline is usually the fastest route to one.
That last one gets skipped for an understandable reason. When systems go down the instinct is to fix them. Resist it for 30 minutes. A well-meant reboot or reimage in hour 2 can erase the only evidence that would have shown whether data left the building, and that one unknown is what turns a contained incident into a full notification event.
Hours 4 to 24, scope the damage and start the clock nobody sees
By hour 4 the spread should be stopped. Now the questions shift from what is happening to what happened, and 3 of them drive everything after.
What did they take
Encryption announces itself. Exfiltration does not, and exfiltration is the half that creates legal exposure. Look at outbound traffic volume in the days before the note, firewall and proxy logs, and transfer tools such as Rclone, MEGAsync, or WinSCP showing up where nobody installed them.
How did they get in
Until you know, every restore is a coin flip. Restoring into an environment that still has the original open door is the most common reason businesses get encrypted a second time in the middle of their own recovery.
How deep did they get into Active Directory
If the attacker reached domain admin, treat the entire identity estate as suspect. Microsoft’s forest recovery guidance frames a compromised domain as something you rebuild rather than restore, and that single call moves your recovery timeline by days.
Somewhere in this window, usually without anyone writing it down, your team determines that a breach occurred. In Texas that determination is the event that starts the 60-day notification clock. Write it down. Record the date, the time, who made the call, and what they knew when they made it. Counsel will ask, your carrier will ask, and if the Attorney General ever asks, an undocumented determination date is the worst available answer.
Your cyber policy also gets decided in this window. Most policies require notice inside a defined period, commonly 24 to 72 hours, and late notice is one of the most reliable ways to get a claim reduced. Many also require panel counsel and panel forensics. Hire your own firm first and you may well end up paying for it yourself.
Hours 24 to 72, restore in an order that gets you billing again

Restore order is the least documented part of ransomware recovery and the part where prepared teams separate from hopeful ones. The instinct is to restore whatever generates the loudest complaints, which is almost always email. It is almost never the right first move. Work in this sequence instead.
- Build a clean environment first. A recovery network isolated from production, fresh operating system media, current patches. Restoring into the environment that was just compromised reinfects you inside a day.
- Identity before everything else. Domain controllers, Entra ID, privileged accounts, MFA enrollment. Reset every credential including service accounts and the ones nobody remembers owning. Every system restored afterwards authenticates against this, so it has to be trustworthy first.
- Backup infrastructure second. Verify the backup server itself is clean before trusting a single file it hands you. Sophos found 94% of ransomware victims had attackers attempt to compromise their backups, and 57% of those attempts worked.
- Then the systems your revenue runs through. Line of business applications, the ERP, the practice management system, whatever you invoice from. Cash flow does not pause while IT is busy.
- Then communications. Email and phones matter, and they will be the loudest request in the building, but a company that can email and cannot invoice is still not operating.
- Then everything else, with monitoring already in place. Bring back remaining file shares and workstations only once endpoint detection is deployed and logging is turned up, so any dormant persistence shows itself early.
Test each restored system before it rejoins production. A restore that quietly carries a scheduled task or a registry run key is not a recovery, it is a postponement. Keep a written running log of what was restored, from which backup date, and who verified it clean. That log is the difference between a 3-week insurance claim and a 3-month one. If you have never mapped which systems have to come back in which order, business continuity versus disaster recovery is the planning distinction that produces that map.
Should you pay the ransom
Every owner asks this around hour 6, and the data has moved decisively against paying.
Sophos recorded 49% of victims paying in 2025, down from 56%. Verizon puts it more starkly, with 64% of victims now refusing, up from 50% two years earlier, and a median ransom payment that fell to $115,000. Payment also underperforms its reputation badly. Decryptors arrive broken, partial, or so slow that restoring from backup would have finished first. And in a double extortion case you are buying a promise to delete stolen data from people whose entire business model is breaking promises.
| Your situation | Is paying justified | Why |
|---|---|---|
| Clean, tested, offline backups exist | Almost never | Restoring is faster and you keep the evidence intact |
| Backups encrypted or never restore-tested | This is the conversation to have with counsel | The scenario where the 8x recovery cost shows up |
| Data exfiltrated, systems recoverable | Not a recovery decision | Notification duties apply whether or not you pay |
| Life safety or regulated patient care at risk | A legal and clinical call, not an IT one | Bring counsel and the carrier in immediately |
| Sanctioned group involved | Potentially unlawful | US sanctions exposure sits with the payer and any facilitator |
Sophos also surfaced something worth sitting with. Only 54% of victims used backups to restore in 2025, the lowest share in 6 years. Not because backups stopped working, but because attackers now go after them first. So the honest version of “we have backups” is a question rather than a statement. When did you last restore from them, into an isolated environment, with a stopwatch running?
We used to answer that question with our own marketing. Immutable copies, offsite replication, all true and all verifiable. Then we started timing full restores as a scheduled exercise and found that some environments we would have called ready needed roughly twice as long as anyone expected, almost entirely because of dependency order rather than the backups themselves. The backups were fine. The plan wrapped around them was not.
What Texas law adds to a ransomware recovery

Texas layers its own requirements on top of everything above, and they run on their own schedule.
Under the Texas Identity Theft Enforcement and Protection Act, Chapter 521 of the Business and Commerce Code, a business must notify affected individuals without unreasonable delay and no later than 60 days after determining a breach occurred. Where 250 or more Texas residents are affected, the Attorney General must be notified within 30 days. Civil penalties run from $2,000 to $50,000 per violation, with further exposure up to $250,000 per breach for failing to give the required notice.
The newer piece works in your favor. Senate Bill 2610 took effect on September 1, 2025 and gives Texas businesses with fewer than 250 employees a safe harbor against exemplary damages, provided they had a recognized cybersecurity program running before the incident. The required framework scales with headcount. Under 20 employees means basic measures such as a password policy and awareness training. From 20 to 99 employees means CIS Controls Implementation Group 1. From 100 to 249 means a full framework like NIST CSF, ISO 27001, or NIST SP 800-171.
The safe harbor is narrow. It does not stop compensatory damages, class actions, or regulatory enforcement. But it is one of the very few things about a breach that gets decided before the breach, which makes it worth handling on a calm afternoon rather than during a recovery. Our Texas SB 2610 compliance guide walks through the framework tiers in detail.
Sector rules stack on top rather than replacing any of this. Healthcare organizations carry HIPAA’s own notification duty and the 500-record threshold that triggers notice to HHS and the media. Defense contractors carry DFARS incident reporting. Financial firms answer to their examiners. All of those run alongside the Texas requirement, not instead of it.
What ransomware recovery actually costs
Sophos put the average recovery cost at $1.53 million in 2025, down sharply from $2.73 million the year before. That is a global, largely enterprise figure and it will not map onto a 60-person firm in Katy or Richardson. Treat the direction as the useful part, not the absolute number.
Where the money goes transfers much better. Forensic investigation bills at specialist day rates. Legal counsel bills through the whole notification process. Notification itself costs per record once credit monitoring is included. Overtime and contract labor pile up across the restore. Then there is the line almost nobody budgets, which is the revenue you never billed while systems were dark. Our cost of IT downtime breakdown shows how to calculate that number for your own operation.
The clearest cost lever in the published research is backup integrity. Sophos found organizations whose backups were compromised faced a recovery bill roughly 8 times higher than those whose backups came through intact, and were close to twice as likely to pay a ransom. One control, an order of magnitude of difference. That is the strongest argument we know of for treating disaster recovery in Texas as a security control rather than an IT housekeeping task.
6 mistakes that turn a 5-day recovery into a 5-week one
- Powering machines off to stop the spread. Kills volatile evidence and usually accomplishes nothing that network isolation had not already handled.
- Restoring before scoping. You reopen the original door, and the second encryption event lands while everybody is running on 4 hours of sleep.
- Notifying the carrier late. Late notice is a standard denial reason. Read your policy’s notice window now, at your desk, not at 2 AM with a ransom note on screen.
- Treating exfiltration as an IT question. Whether data left the building is a legal determination with a statutory deadline behind it. Counsel makes that call, not the server team.
- Restoring the loudest system first. Email is not revenue. Restore in dependency order and publish the plan so people stop asking where they sit in the queue.
- Declaring victory when systems come back. Persistence routinely survives a restore. Without 30 to 60 days of elevated monitoring afterwards, you find out about it the expensive way.
How Uprite handles ransomware recovery for Texas businesses

We are a managed IT and security provider, not a dedicated digital forensics firm, and it is worth being straight about that line. In a serious incident, forensic imaging and attribution belong with a specialist firm, usually one your carrier has already approved. What we handle is everything around it, which happens to be most of the recovery timeline.
Our help desk is staffed by technicians rather than dispatchers, so the person who picks up can begin containment instead of routing you somewhere. Average first response runs about 5 minutes across all clients, backed by a sub-10-minute triage commitment. During an active incident the gap between acknowledgment and action is the entire game.
We run offices in Houston, San Antonio, Dallas, and Katy, so an engineer can be physically in front of a rack when isolation has to happen at the hardware level rather than through a console. Uprite has supported Texas businesses since 1999 and earned a 7th consecutive MSP 501 recognition in 2026 at No. 264.
For the prevention side, our ransomware protection playbook covers the layered controls that stop most of this before it starts. Metro security teams sit at cybersecurity services in Dallas, cybersecurity services in San Antonio, and managed security services in Houston.
Find out how your recovery would actually go
We will run a recovery readiness review covering restore point verification, identity blast radius, your insurance notice window, and your Texas notification path, written up as a plan you can hand straight to your team. You keep the review whether or not you ever work with us. Call (866) 570-3065 to book it.
What Texas business owners ask us after a ransomware attack
How long does ransomware recovery take?
Most businesses are back to normal operations within 1 to 3 weeks. Sophos found 53% of victims fully recovered inside a week in 2025, while 18% needed more than a month. The biggest single variable is whether your backups survived the attack, followed closely by how quickly identity systems were rebuilt from clean media.
What should I do in the first hour of a ransomware attack?
Isolate affected systems from the network without powering them off, disable compromised accounts, and call your incident response contact. Leaving machines running preserves forensic evidence held in memory. Move team communication off the affected network, and stop any scheduled backup jobs before they overwrite your last clean restore point.
Does Texas require me to report a ransomware attack?
Yes, when sensitive personal information was compromised. Texas requires notice to affected individuals no later than 60 days after you determine a breach occurred, plus notice to the Attorney General within 30 days if 250 or more Texas residents are affected. Penalties reach $50,000 per violation and up to $250,000 per breach for failing to notify.
Is it ever worth paying the ransom?
Rarely, and never as a first response. 64% of victims now refuse to pay according to Verizon’s 2025 DBIR, and organizations that do pay typically recover only part of their data. Payment becomes a serious option only when backups are gone and a legal, clinical, or safety consequence outweighs the odds. That call belongs to counsel and your carrier.
Will my cyber insurance cover ransomware recovery?
Usually, provided you follow the policy process. Most policies cover forensics, legal counsel, notification, and business interruption. They also require prompt notice, commonly within 24 to 72 hours, and often mandate their own panel vendors. Late notice and self-selected vendors are 2 of the most common reasons claims get reduced or denied outright.
Can data be recovered without paying the ransom?
Often, yes. Clean offline or immutable backups are the primary route and the fastest one. Free decryptors exist for some older strains through the No More Ransom project, though rarely for current families. Where neither works, recovery means rebuilding systems and accepting data loss back to your last verified restore point.
How do I know the attacker is really gone?
You verify it rather than assume it. Rebuild identity from clean media, reset every credential including service accounts, and run elevated monitoring for at least 30 to 60 days after recovery. Persistence mechanisms such as scheduled tasks and registry run keys routinely survive a restore, which is why re-encryption during recovery is so common.









