Skip to content

Disaster recovery

How long does it take to recover from a ransomware attack?

A phase-by-phase timeline from the ransom note to normal operations, including Microsoft 365 and the NIS2 reporting deadlines that run alongside.

A dark data centre corridor where one server rack in the centre has powered back on, symbolising ransomware recovery

The short answer

Recovery from ransomware usually takes days to weeks. In the Sophos State of Ransomware 2025, 53% of victims had recovered within a week. When attackers had also compromised the backups, only 26% recovered within a week in Sophos' earlier study. Intact, isolated and tested backups are what make the difference.

Key takeaways

  • Sophos found that 53% of ransomware victims recovered within a week in 2025, up from 35% in 2024.
  • With compromised backups, only 26% fully recovered within a week, against 46% with intact backups (Sophos, 2024 study).
  • Recovery has five phases: contain, investigate, rebuild, restore and return to normal; the reporting clock runs alongside from hour one.
  • NIS2 Article 23 requires an early warning within 24 hours, a notification within 72 hours and a final report within one month.
  • You shorten recovery before the attack: immutable backups, an isolated recovery environment, agreed priorities and tested restores.

How long does ransomware recovery take?

For most organisations, between a few days and several weeks. How quickly you recover depends far more on what you prepared than on the ransomware strain, which is why recovery belongs in your disaster recovery plan.

Picture 09:47 on a Monday: SharePoint files start changing extension, a user reports a ransom note, and the service desk phone doesn't stop. Whether you're back by Wednesday or in three weeks was decided months earlier.

Recovery and investigation are not the same clock. The IBM Cost of a Data Breach Report 2025 found that identifying and containing a breach took 241 days on average across all breach types, so plan for systems to be back long before the forensic work is finished.

What are the phases of ransomware recovery?

Recovery runs through five phases, and the reporting duties run in parallel from the first hour. The timings below are planning targets for a prepared organisation, not benchmarks.

PhasePlanning targetWhat happensReporting clock
1. Detect and containFirst hourDeclare the incident, isolate systems, disable compromised accounts, revoke sessionsStart the incident log; NIS2 24-hour clock starts when you become aware
2. Investigate and preserveHours 1–24Find the entry point and scope, preserve logs and evidence, check which backups are cleanNIS2 early warning within 24 hours
3. Rebuild a clean baseDay 1–3Reset credentials, rebuild identity and core infrastructure, recover in an isolated environmentNIS2 notification and GDPR breach notification within 72 hours
4. Restore by priorityDay 1–7Restore critical systems first, then the rest; scan and validate data before reconnectingIntermediate reports if your CSIRT asks
5. Return to normal and learnWeek 2 onwardsMonitor closely, clear the backlog, communicate with customers, hold a lessons-learned reviewNIS2 final report within one month of the notification

The phases follow the incident cycle used in the NCSC's ransomware incident response plan: preparation, identification, containment, eradication, recovery and lessons learned. The NCSC advises putting affected systems in sleep mode rather than switching them off, to preserve evidence.

The reporting clock

Under Article 23(4) of Directive (EU) 2022/2555, essential and important entities send an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of that notification. If personal data is affected, Article 33 of the GDPR adds notification to the supervisory authority within 72 hours where feasible. In the Netherlands the Cyberbeveiligingswet has applied since 15 August 2026. Our NIS2 compliance guide explains who is in scope.

What do the first four hours look like in Microsoft 365?

In Microsoft 365 the first four hours decide whether you restore from a clean point or keep chasing the attacker. Contain identities first, preserve evidence second, then restore by priority.

Minutes 0–15: detect, declare, isolate

  • Confirm the signs: mass file changes in SharePoint or OneDrive, unusual sign-ins, ransom notes.
  • Declare an incident and name one incident lead.
  • Disable suspicious accounts, revoke sessions and isolate affected endpoints.
  • Pause OneDrive sync and Exchange ActiveSync, as Microsoft's ransomware playbook advises, so encryption doesn't spread to other devices.

Minutes 15–60: revoke, preserve, start restoring

  • Reset passwords for privileged accounts and revoke OAuth app consents you don't recognise.
  • Export audit logs before they age out.
  • Pick a restore point from before the first malicious change and start restoring the most critical sites and mailboxes.

Hours 1–4: restore and harden

  • Restore remaining OneDrive accounts, mailboxes and Teams data by priority.
  • Disable legacy authentication, tighten conditional access and external sharing.
  • Check restored data before users reconnect.

Microsoft's own tools have limits. The Microsoft 365 recycle bin keeps deleted items for up to 93 days, and Microsoft documents that OneDrive Files Restore covers "a previous point in time within the last 30 days". If the attack started earlier, or the attacker deleted data with admin rights, you need an independent Microsoft 365 backup. We explain why in availability vs recoverability in Microsoft 365.

What determines how long recovery takes?

Five factors decide the length of recovery, and all of them are under your control before the attack.

  1. Whether your backups survived. This is the single largest factor in the Sophos data. Immutable and air-gapped copies can't be encrypted or deleted by an attacker with admin rights.
  2. Whether you have somewhere clean to restore. Restoring onto compromised servers risks a second encryption. An isolated recovery environment on a separate network lets you restore while forensics continues.
  3. Whether you know what to restore first. A priority list agreed with the business, with dependencies (identity before applications, databases before front ends), saves hours of debate.
  4. Whether the plan has been tested. Untested plans fail on details: missing credentials, outdated runbooks, restores that take five times longer than expected.
  5. Whether you can find the entry point. Until you know how the attacker got in, restored systems are at risk of being compromised again.

Identity matters most at the start. Sophos reports in its State of Ransomware 2026 that 79% of attacks started with an identity-based approach and 56% succeeded in encrypting data, so account containment comes before any restore.

Does paying the ransom speed up recovery?

Usually not. Paying adds a negotiation phase and gives you a decryptor of unknown quality, while you still have to rebuild, clean and validate every system.

  • Decryption runs system by system and can fail on corrupted files.
  • You still need to find the entry point and remove the attacker's access before reconnecting.
  • The NIS2 and GDPR reporting deadlines apply whether or not you pay.

The FBI, the Dutch NCSC and No More Ransom all advise against paying. We set out the evidence in should you pay the ransom?

How do you shorten ransomware recovery time?

Set a realistic recovery time objective (RTO) per system, then build and test the setup that meets it. RTO is how long a system may be down; RPO, the recovery point objective, is how much work you can afford to lose.

  1. Classify systems into critical (hours), important (a day or two) and the rest. Base this on what downtime costs: our cost of downtime model helps.
  2. Protect the backups with immutability and an air-gapped copy, following the 3-2-1-1-0 rule.
  3. Prepare a clean recovery environment so critical VMs can start while the production network is still being investigated.
  4. Write the runbook, including contacts, decision rights, the reporting templates for 24 and 72 hours, and the restore order.
  5. Test it, at least every quarter for critical systems, and record the actual restore times.

Read more about setting targets in RTO and RPO explained.

What to do next

Ransomware recovery takes as long as your preparation allows. With intact backups, a clean place to restore and a tested runbook, recovery takes days; without them, it can take weeks, while the NIS2 and GDPR deadlines keep running.

With Mindtime, backups are immutable with an air-gapped copy, scanned for malware and checked automatically after every job. VMs boot instantly in an isolated recovery environment on a separate, clean network, and critical workloads are restored on a 4-hour SLA. For Microsoft 365 we restore at item level, and our disaster recovery service adds standby infrastructure and automated DR tests every quarter, with evidence for auditors.

Want to see how quickly you could be back? Book a free 15-minute demo.

This article is information, not legal advice.

Frequently asked questions

How long does recovery from a ransomware attack typically take?

Typically from a few days to several weeks. In the Sophos State of Ransomware 2025, 53% of victims had recovered within a week. Organisations whose backups were compromised recovered much more slowly: in Sophos' 2024 study only 26% of them had fully recovered within a week. Full return to normal, including backlog and customer communication, often takes longer than restoring the systems.

What should you do first when ransomware hits Microsoft 365?

Contain identities. Disable suspicious accounts, revoke sessions and tokens, reset privileged passwords and pause OneDrive sync so encryption doesn't spread to other devices. Then export audit logs to preserve evidence. Only start restoring once you've chosen a restore point from before the first malicious change and the attacker's access has been removed.

What are the reporting deadlines after a ransomware attack in the EU?

If you fall under NIS2, Article 23 requires an early warning to your CSIRT or authority within 24 hours of becoming aware of a significant incident, a notification within 72 hours and a final report within one month. If personal data is affected, GDPR Article 33 requires notifying the supervisory authority within 72 hours where feasible. These deadlines run alongside the technical recovery.

Can Microsoft restore my Microsoft 365 data after ransomware?

Only within limits. The Microsoft 365 recycle bin keeps deleted items for up to 93 days, and OneDrive Files Restore can roll back a OneDrive to a point within the last 30 days. If encryption started earlier, an attacker with admin rights deleted data, or you need many users restored to one point in time, you need an independent backup.

What is a realistic RTO after ransomware?

That depends on your preparation, not on a general benchmark. Set an RTO per system class: critical systems in hours, important ones within a day or two, the rest later. Then prove it with a restore test. If a test of a critical system takes longer than its RTO, change the setup, for example with an isolated recovery environment or standby infrastructure.

Sources

  1. The State of Ransomware 2025Sophos, 2025
  2. State of Ransomware 2026Sophos, 2026
  3. The impact of compromised backups on ransomware outcomesSophos, 2024
  4. Cost of a Data Breach Report 2025 (press release)IBM, 2025
  5. 2026 Data Breach Investigations ReportVerizon, 2026
  6. Incidentresponsplan RansomwareNationaal Cyber Security Centrum (NCSC), 2022
  7. Responding to ransomware attacksMicrosoft Learn, 2026 (accessed)
  8. Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van krachtNationaal Cyber Security Centrum (NCSC), 2026
  9. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
  10. Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016
Part ofDisaster Recovery