LEARNING TOPIC
Incident recovery
Prepare response, preserve evidence and prove recovery.
Set recovery-time and data-loss targets
Turn backup frequency into a business decision about how much downtime and lost work are tolerable.
Restore a test file without overwriting the working copy
Prove that a specific backup can deliver usable content through the normal recovery route.
Check who can delete your backups
Find whether an ordinary compromised account could remove the recovery copies you rely on.
Plan a known-good rebuild of an affected computer
List trusted installation sources, recovery data and account changes before reusing a compromised device.
Close an incident with evidence and follow-up actions
Distinguish restored service from a complete response and assign the remaining improvements.
Write a useful first-hour incident note
Capture observations and actions without turning an early suspicion into an unsupported conclusion.
Plan device isolation during a suspected incident
Reduce further connectivity while documenting what isolation can interrupt or change.
Preserve security logs before routine cleanup
Keep a reproducible evidence copy with its collection context and access controls.
Make an incident contact sheet that works offline
Prepare verified contacts and decision owners before email or the network becomes unavailable.
Run a small ransomware tabletop exercise
Practise decisions and recovery dependencies without encrypting files or deploying malware.