Why restoring systems too quickly after a cyber attack can make things worse
When a cyber attack brings critical systems down, the pressure to restore operations can be enormous. Employees cannot work normally. Customers may be waiting. Revenue may be affected. Senior leaders want to know when systems will be available again. Under those circumstances, recovering quickly can feel like the obvious priority.
But restoring systems before you understand what has happened can make things worse.
New guidance from the National Cyber Security Centre (NCSC) on recovering from highly disruptive cyber attacks makes this point explicitly. Where possible, investigation should take place before systems are restored, because understanding how attackers gained access, what they did and whether they still have access is critical to safe recovery.
For businesses responding to a serious cyber incident, speed matters. But speed without sufficient understanding can create an entirely new set of risks.
If you are reading this because your organisation has experienced a cyber incident and is unsure how to respond, contact Zensec immediately.
Why rushing recovery creates risk
A cyber attack is not necessarily over because malicious activity appears to have stopped.
Threat actors may still have valid credentials, remote access or persistence elsewhere within the environment. Accounts may have been compromised or created. Critical data and backups may have been affected without the organisation knowing it yet.
Restoring critical systems without answering those questions can potentially return an attacker to an environment they have already compromised.
The NCSC’s July 2026 guidance warns that rushing recovery before understanding an incident can significantly increase risk. It recommends establishing how attackers gained initial access, how they moved through the environment, what actions they took and whether they maintained access before making recovery decisions.
That investigation is not something delaying recovery. It is part of the recovery process.
Restoring a system is not the same as recovering securely
Disaster recovery has traditionally focused heavily on getting IT systems and data back online.
Cyber recovery introduces another question: can those systems be trusted?
A data backup may exist, but was it accessible to the attacker? An application may be restored, but are the credentials used to access it secure? A server may appear unaffected, but does the organisation understand how the attacker moved through its environment?
The NCSC also advises organisations to assume backups may have been targeted and to seek appropriate assurance that they are uncompromised before relying on them for restoration.
This is why a cyber recovery plan needs to work alongside the organisation’s disaster recovery plan and incident response plan.
The objective is not simply to restore access. It is to restore operations in a way that does not introduce an unacceptable risk of the incident restarting.
Investigation informs recovery
Effective incident response should establish enough information about the cyber attack to make informed recovery decisions.
This may include identifying the initial point of compromise, affected accounts and devices, malicious files, suspicious activity and the extent of access attackers obtained.
It may also require determining whether sensitive information, financial data or other critical data has been accessed or stolen.
The answers can directly affect what happens next.
If stolen credentials were used to gain access, credential resets and stronger access controls may need to form part of recovery. If remote access was compromised, simply restoring the affected server does not resolve the original security breach.
If malicious software remains elsewhere in the environment, reconnecting restored systems could expose them again.
Investigation can also preserve information that may be needed for regulatory requirements, insurance claims or reporting to relevant authorities.
The business still needs to operate
None of this removes the commercial reality facing an organisation during a major cyber incident.
Businesses need to recover.
The challenge is balancing the need to restore operations with the need to do so safely.
One of the most useful concepts in the NCSC guidance is minimum viable operations. Rather than attempting to restore everything immediately, organisations should identify the lowest level of operational capability required to operate safely, meet legal and regulatory obligations and maintain trust.
This changes the recovery question from “How quickly can we switch everything back on?” to: “What do we need to restore first for the business to operate safely?”
That distinction can be critical during a real attack.
Critical systems and the dependencies supporting them should be prioritised according to business need, not simply because they are easiest to restore.
Your recovery priorities should already be known
A serious security incident is a difficult time to discover which IT systems the organisation cannot operate without.
A business impact analysis can help identify critical business operations, the systems and data supporting them and the likely consequences if they become unavailable.
This information should feed directly into business continuity, disaster recovery and cyber recovery planning.
A clear incident response plan should also establish who has authority to make decisions during an incident and how technical, operational and leadership teams will work together.
Without a clear plan, pressure can drive decisions.
With the right preparation, decisions can instead be based on business impact, risk and evidence from the investigation.
Backups are critical, but they are not the whole recovery plan
Reliable data backup remains a critical part of cyber resilience, particularly during ransomware attacks and other incidents involving data loss.
But having backups does not guarantee straightforward recovery.
Attackers increasingly target backup systems, and restoring data does not necessarily address the way a cyber criminal gained access in the first place.
Backups may also restore data without restoring all of the applications, identity services and other dependencies required for business operations.
A good recovery plan therefore considers the wider environment rather than treating backup restoration as the end of the process.
Organisations should know where critical data is stored, how quickly it can be restored and what security checks need to happen before restored systems reconnect to the wider environment.
Recovery may take longer than leaders expect
One of the more important messages in the NCSC guidance is that recovery from a highly disruptive cyber attack is rarely a rapid technical fix.
The NCSC says organisations can operate with limited or unavailable IT services for weeks and that full recovery can take many months.
That can be difficult for leadership teams to accept when financial loss and operational pressure are increasing by the day.
However, pushing technical teams to recover faster than the investigation and assurance process allows can increase the possibility of further security incidents.
The aim should be to recover as quickly and safely as possible.
Sometimes that means accepting temporary workarounds or limited services while investigation and recovery continue.
Preparation makes safe recovery faster
The answer is not to accept slow recovery.
It is to do more preparation before a cyber incident occurs.
Organisations with an established incident response plan, tested disaster recovery procedures, a clear understanding of critical systems and reliable backups are better placed to make decisions quickly when an attack happens.
Regular risk assessment and security testing can identify weaknesses before threat actors exploit them. Security patches, multi factor authentication, appropriate access controls and employee training can reduce exposure to common cyber threats such as phishing emails, fraudulent emails and credential theft.
But even the best protection cannot guarantee that a business will never experience a cyber attack.
Preparation therefore needs to cover both prevention and recovery.
Businesses should know who they will call, which systems will be prioritised, how backups will be assessed and what evidence will be required before systems are considered safe.
Recovery should reduce the risk of the next attack
The final objective of cyber recovery should not be to recreate exactly what existed before the incident.
A cyber attack may expose outdated software, weak access controls, inadequate security policies or gaps in monitoring that contributed to the original compromise.
Restoring those weaknesses in exactly the same way can leave the organisation vulnerable to future attacks.
Recovery creates an opportunity to address vulnerabilities, strengthen controls and improve the organisation’s overall security posture.
That could include applying security patches, reviewing remote access, strengthening multi factor authentication, changing privileged credentials or improving monitoring for suspicious activity.
The goal is not simply to get back to where the business was.
It is to recover into a more secure position.
The fastest recovery is not always the safest
During a cyber attack, pressure to restore operations is understandable.
But recovery decisions made without understanding the incident can create additional risk.
The NCSC’s latest guidance reinforces an important principle: investigation, containment and recovery need to work together.
Organisations need to understand whether attackers still have access, whether backups and critical systems can be trusted and what the business genuinely needs to restore first.
With the right preparation, businesses can recover quickly without sacrificing the assurance needed to prevent the same incident from starting again.
Because after a serious cyber attack, success is not measured by how quickly everything is switched back on.
It is measured by whether the business can restore operations safely and with confidence.
How Zensec can help
Zensec is an NCSC-assured Cyber Incident Response provider, helping organisations investigate, contain and recover from serious cyber security incidents.
Our incident response specialists can help establish how attackers gained access, understand the extent of compromise and provide the evidence needed to make informed recovery decisions.
We also help organisations prepare before an incident through cyber incident response planning, security assessments and testing designed to identify gaps before they become part of a real attack.
If your organisation is experiencing a cyber incident, or you want to strengthen your cyber recovery plan before one occurs, contact Zensec.

