Updated: July 20, 2026
Two organisations are hit by the same ransomware on the same morning. One is running again in days with no ransom paid; the other loses weeks and still may not get its data back. The difference is not luck or budget. It is whether the recovery was tested before the attack. This timeline shows how the two paths diverge, hour by hour.

The first hour sets the tone for everything after it. A prepared organisation triggers a rehearsed playbook: roles are already assigned, the reporting clock is understood, and the team acts instead of debating. An unprepared one spends the hour deciding who owns the incident, and every minute lost in that scramble is a minute the attacker keeps. Recovery is won or lost on preparation done long before the alert.
Because modern ransomware targets them first. By the first hour, the tested organisation has confirmed a clean recovery source: copies that are immutable and air-gapped, untouched because the attacker could neither reach nor alter them. The unprepared organisation discovers the opposite, that its backups sat on the same network and were encrypted with everything else. From that moment the two paths cannot converge, because one has trustworthy data to restore and the other does not.
In India, it is the regulator's clock. CERT-In's directions require qualifying incidents, ransomware included, to be reported within six hours of awareness. The prepared organisation has a reporting workflow ready and files in time. The unprepared one, still fighting the fire, misses the window and adds a regulatory exposure to an already bad day. Recovery is not only technical; it is a compliance event with a deadline.
By day three, the tested organisation is back: systems restored into a clean room, scanned and validated for reinfection, and returned to production in waves, with no ransom paid and data intact. The unprepared one is still scrambling, weighing whether to pay, and facing weeks of downtime. The hard statistic behind that path: even among those who pay, a large majority still fail to fully recover their data. The ending was written in preparation, not the panic.
The single line that separates the two timelines is a tested recovery: immutable, air-gapped copies, a clean room to restore into, a rehearsed playbook, and a reporting workflow ready to go. Building and proving that capability is exactly the work Proactive Data Systems does for Indian enterprises: immutable and air-gapped data protection, isolated recovery environments, tested recovery, and CERT-In and DPDP reporting readiness. As a Cisco Preferred Cloud and AI Partner, Dell Platinum Partner and NetApp Preferred Partner with 35 years in enterprise IT and a 24/7 service desk in India, we help CISOs make recovery a fact rather than a hope. Ask Proactive for a cyber recovery readiness assessment.
We'll get back to you shortly.