Chapter 15. Restore and Recover
Congratulations. You’ve made it through the containment and eradication phase, which hopefully will be the hardest part. The threat actors have been kicked out, the malware has been cleaned up, and you’ve wiped or replaced all infected systems. Now comes the part that everyone has been waiting for: getting your organization back to normal operations. This is where all that preparation we talked about in earlier chapters pays off.
We will once again mention the slight difference between the words restore and recover. To many people, they mean the same thing, and this book is guilty of sometimes saying the word “recover” when we meant “restore.” But technically, a restore is simply the act of copying the data from a backup of any kind to the system to be restored. A recovery is a more holistic process that includes the restore and all the various actions around it to get your environment back to a good state.
The Goals of Recovery
The obvious goal is getting your organization operational again. Users need to work, customers need to be served, business needs to continue. Speed matters. Everyone from the CEO down is going to be asking when things will be back to normal.
But if speed is your only goal, you’re going to make mistakes. Here’s what you should actually be focused on: getting critical systems back first, not getting infected again, and coming back stronger than you were before.
That second goal—not getting infected again—is the one that keeps ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access