Ransomware Recovery Readiness: A 90-Minute Review for Orange County Businesses
Reviewed September 28, 2026. A 90-minute review can expose missing contacts, unclear responsibilities, and untested recovery assumptions. It cannot prove that every application will recover within its target time. Use the session to define the evidence you have and the technical tests still needed.
Separate discussion from restoration testing
NIST SP 800-84 distinguishes discussion-based tabletop exercises from functional exercises and tests of systems. A tabletop does not deploy equipment. An actual restore test needs an approved scope, environment, access, rollback plan, and time to validate the application and its data.
For a facilitator’s timed agenda, use our 90-minute disaster recovery tabletop guide. This page focuses on the evidence a business should review before claiming it is ready to recover.
Choose one business service
Select a service such as payroll, order processing, or a customer portal. Identify the accountable business owner, application owner, identity services, database, network, external providers, and essential integrations. A server starting successfully is not the same as the business process working.
Define the recovery objectives
The recovery time objective (RTO) is the target time to restore the required service after a disruption. The recovery point objective (RPO) describes the acceptable data-loss window measured in time. Record who agreed to these targets and which dependencies they include. They are objectives until testing provides evidence that the selected recovery approach can meet them.
Review five evidence areas
- Recovery copies: identify backup locations, retention, protection from deletion, and access requirements. Check the most recent completed restore test, not only backup job status.
- Clean recovery environment: document where systems can be rebuilt without reconnecting untrusted devices or overwriting production data.
- Dependencies: check identity, DNS, network connectivity, licensing, application secrets, and third-party services.
- Decision and communication: name incident leadership, business decision makers, legal and insurer contacts, and a communication channel available if company email fails.
- Business validation: define the transactions and data checks an authorized owner must complete before declaring the service recovered.
Use an illustrative 90-minute review
Spend 15 minutes agreeing on scope and objectives, 20 minutes reviewing recovery evidence, 20 minutes discussing unavailable systems and credentials, 20 minutes identifying dependencies and validation criteria, and 15 minutes assigning corrective actions. Adjust the agenda to your environment; these time boxes are not a restoration SLA.
Schedule the technical test separately
Use authorized personnel and an isolated test environment. Protect production data, prevent unintended external communications, and define stop conditions. Measure elapsed restoration time, data age, dependency failures, and business validation results. Report the conditions and limits of the test. Do not use live malware to simulate ransomware.
CISA recommends protected backups and regular testing of availability and integrity. Its tabletop exercise packages provide scenarios and discussion questions.
Close the findings
Record each gap, its impact, owner, due date, and required proof of closure. Retest affected controls after changes. Avoid claiming a fixed percentage improvement or guaranteed recovery time from a discussion alone.
For recovery planning and testing support, review Technijian’s business continuity services or request an IT assessment.
Original recording
The original recording is retained. Use the reviewed written guidance above for current instructions; the audio and video have not been rerecorded.
