Ransomware Recovery: What Should Every Ohio Credit Union Do Before an Attack?

I once asked a leadership team a question that changed the entire cybersecurity conversation.

“If ransomware encrypted your systems tonight, how would you open tomorrow morning?”

Everyone knew they had backups.

They had cybersecurity tools.

They had an insurance policy.

But when we started talking about what would actually happen at 8:00 the next morning, the answers became less certain.

Who makes the first call?

Which systems get restored first?

How long will recovery take?

Can employees communicate?

How will members be informed?

That’s the problem with ransomware planning.

Too many organizations focus entirely on preventing the attack.

Prevention matters.

But after more than 26 years working in technology, I’ve learned that strong organizations prepare for another possibility too:

What if the attacker gets through?

For a credit union, ransomware recovery should be planned long before an attack. I recommend focusing on six areas: critical systems, protected backups, tested recovery, incident response, communication, and vendor coordination.

1. Decide What Has to Come Back First

During an emergency, everything feels important.

But everything can’t be first.

Before an incident occurs, identify the systems your credit union needs most to serve members.

That may include:

  • Core banking access
  • Network infrastructure
  • Identity and authentication
  • Internet connectivity
  • Microsoft 365
  • Teller operations
  • Loan systems
  • Critical file storage

Then determine the order in which those systems should be restored.

This conversation shouldn’t happen during the attack.

Leadership, operations, IT, and your technology partners should agree on priorities ahead of time.

2. Make Sure Your Backups Can Survive the Attack

I’ve said this throughout this series:

Having a backup isn’t the same as being able to recover.

Ransomware attackers may attempt to compromise backups along with production systems. That means your backup strategy should be designed so a problem in the primary environment doesn’t automatically become a problem everywhere else.

Ask your technology team:

Where are our backups?

How are they protected?

Who can access them?

Could compromised administrator credentials affect them?

How much data could we lose between the last good backup and the attack?

Those answers matter far more than seeing a green “backup successful” message every morning.

3. Test the Recovery

This is where confidence comes from.

Don’t just test whether you can restore one file.

Periodically test whether you can recover meaningful systems and operations.

Time it.

Document what happens.

Identify what doesn’t work.

You might discover an outdated password.

Missing documentation.

A vendor dependency nobody considered.

A recovery process that takes six hours when leadership assumed it took two.

Those discoveries aren’t failures.

They’re exactly why you test.

It’s much better to discover a problem during a scheduled exercise on Wednesday afternoon than during a ransomware incident at 2:00 Sunday morning.

4. Know What Happens During the First Hour

Every credit union should have an incident response plan.

And that plan needs to be usable.

Imagine an employee discovers a ransomware message at 8:05 Monday morning.

What happens at 8:06?

Who gets notified?

Who has authority to make decisions?

Who contacts your technology/security team?

When are legal counsel and appropriate insurance contacts involved?

Who coordinates with critical vendors?

Your response plan should establish roles before emotions are high.

Depending on the circumstances, you may need your technology provider, cybersecurity specialists, insurance resources, legal counsel, compliance personnel, law enforcement, and other professionals involved.

Don’t wait for an emergency to exchange phone numbers.

5. Plan How You’ll Communicate

Technology isn’t the only challenge during ransomware.

Communication can become just as difficult.

What happens if email isn’t available?

How will leadership communicate?

How will employees receive instructions?

Who is authorized to communicate externally?

How will member questions be handled?

A good incident response plan should include alternative communication methods and clearly defined responsibilities.

People need accurate information.

Especially when the situation is changing quickly.

6. Practice With Your Leadership Team

You don’t need to shut down the credit union to test your plan.

Run a tabletop exercise.

Put leadership in a room and give them a scenario:

“It’s 8:15 Monday morning. Multiple employees report they can’t access files. A ransom message appears on several computers. What do we do?”

Then walk through it.

Who calls whom?

What gets disconnected?

Can you reach your documentation if the network is unavailable?

When does the board get involved?

What do you tell employees?

What decisions need outside professional advice?

A 60-to-90-minute tabletop exercise can expose assumptions you didn’t know you were making.

The Question I Want Every Board to Ask

At the next board meeting, don’t simply ask:

“Do we have backups?”

Ask:

“When did we last prove we could recover?”

That’s a much stronger question.

Your board doesn’t need to understand backup architecture or ransomware encryption.

It needs confidence that leadership has identified critical risks, prepared a response, and tested the organization’s ability to recover.

Final Thoughts

No cybersecurity company can promise that ransomware will never reach your organization.

That’s why resilience matters.

Strong cybersecurity helps reduce the likelihood of an attack succeeding.

Strong recovery planning helps reduce the damage if one does.

Know your critical systems.

Protect your backups.

Test recovery.

Document your response.

Prepare your people.

Coordinate your vendors.

Practice before the emergency.

Because the middle of a ransomware attack is the worst possible time to discover that everyone had a different idea of what the plan was.

Your members don’t expect you to predict every cyberattack.

They do expect you to be prepared to protect their trust when something goes wrong.

Would Your Credit Union Be Ready to Recover Tomorrow?

At CTG, we help credit unions look beyond simply having backups and build practical strategies for business continuity, disaster recovery, cybersecurity, incident response, and ransomware preparedness.

For more than 26 years, we’ve helped organizations prepare for technology disruptions before they become emergencies. Our team brings more than 200 years of combined experience, with a vendor-agnostic approach focused on finding the right technology and strategy for your organization.

If you’re not completely confident about what would happen during the first hour—or the first day—of a ransomware incident, let’s find out before an attacker does.

Talk with CTG

Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net

Let’s test the plan, find the gaps, and make sure your credit union is prepared to recover when your members need you most.


Share:

Recent Blog Posts...