Ransomware restore proof
Nine in ten security leaders believe they can recover quickly from a ransomware attack. Among organizations hit by ransomware, only 28% fully recovered all affected data. You close the distance between those numbers by restoring production systems in a clean room, on the clock, with a signed report at the end.
My name is Saša Tomić. I come from the storage world: FlashCore Module firmware at IBM, ICP’s Immutable Blob Storage, and Mainnet Reliability at DFINITY. Now I run restore drills for companies that need proof, not checkmarks.
Who this is for
You run infrastructure at a company where downtime costs more than a drill. Your backups show green checkmarks every morning, and nobody remembers the last full restore of a Tier-1 system. If DORA names you, Article 12(2) makes periodic testing of backup, restoration, and recovery procedures part of the law. If NIS2 names you, Article 21(2)(c) lists business continuity, backup management, and disaster recovery among the measures you must have. Carry cyber insurance, and your underwriter expects restore test results tied to recovery targets. All three end the same way: someone with a stopwatch, restoring your systems.
What you get
Three engagements, each ending with proof a stranger can verify.
1. The restore drill
- We pick 3 to 5 Tier-1 systems and agree on recovery targets before I touch anything.
- I restore them in an isolated environment, from your backups, using your runbooks and your people where you want them involved.
- We measure real RTO and RPO against the targets and log every gap the drill exposes.
- You get a signed evidence pack: what came back, how long it took, what broke first, and what to fix in which order.
2. The vault
Some estates have nothing safe to restore from.
- An immutable, isolated copy of your critical backups: object lock or a hardened repository that an attacker with stolen admin credentials cannot delete.
- A restore runbook written against your actual systems.
- The first restore out of the vault, executed and logged, so the vault never stays untested.
3. Evidence for insurers and auditors
- Restore logs, RTO and RPO measurements, and backup configuration proof, packaged for your carrier questionnaire, your auditor, or DORA Article 12 evidence.
- If you drill quarterly, the evidence stays recent, which is what underwriters want to see at renewal.
Why me
At DFINITY I led Mainnet Reliability for a 1,400-node production network; before that, FlashCore Module firmware at IBM. Career details live on the about page.
How a drill runs
I work remote and async. You get an NDA before I see a single backup. A drill needs read access to your backup infrastructure and an isolated segment to restore into; nothing leaves your environment. Each drill is fixed price, quoted on a short call. Most clients drill quarterly; the first round is where the ugly findings live.
Questions I hear
“Our backup console is all green.” That proves the job ran. It says nothing about whether the data returns, how long it takes, or which dependency fails first. Only a restore proves that.
“Doesn’t our backup vendor already do this?” Your vendor sells backups and grades its own homework. Auditors and carriers won’t take those dashboards as evidence.
“We restored a file once.” A single file is a smoke test. A drill brings back whole systems and times them against the targets in your recovery plan.
“Who sees our data?” Nobody outside your team. The drill runs inside your environment, and the evidence pack stays there.
Next step
Find me on LinkedIn: tell me how many Tier-1 systems you run and the date of your last full restore test. You get a written read on what a first drill would prove, within two days.
Sources
- Veeam, Data Trust and Resilience Report 2026 press release: 90% of security leaders believe they can recover quickly; among organizations hit by ransomware, 28% fully recovered all affected data.
- Sophos, The State of Ransomware 2025: average (mean) recovery cost of $1.53 million, excluding any ransom payment.
- Regulation (EU) 2022/2554 (DORA), Article 12: backup policies and procedures, restoration and recovery procedures and methods; Article 12(2) requires periodic testing of those procedures.
- Directive (EU) 2022/2555 (NIS2), Article 21(2)(c): business continuity, such as backup management and disaster recovery, and crisis management.
- CISA, #StopRansomware Guide: offline, encrypted backups with regularly tested restoration; object lock and immutable storage so ransomware cannot delete backup copies.
- Coalition, Maintaining Credible Data Backups: carrier incident-response case where untested backups forced a ransom payment; test backups every three months.
- Cyber Advisors, Cyber Insurance in 2026: The Controls Underwriters Expect: underwriters expect restore test results tied to RTO and RPO targets, quarterly for Tier-1 systems.