How Long Does Recovery from Ransomware Actually Take?
“How long until we’re back?” It is the first question every director asks during a ransomware attack, and the honest answer is rarely the one they want. Recovery from ransomware is usually measured in days to weeks, and sometimes months, not hours. Understanding why, and what actually drives the timeline, is the difference between a realistic recovery and a rushed one that fails.
This guide gives an honest picture of how long ransomware recovery really takes for a UK SME, and what makes it faster or slower. It is a companion to our full cyber incident response plan guide and our ransomware response checklist.
Why it takes longer than people expect
The instinct is to think of recovery as “restore the backup and carry on”. In reality, safe recovery has several stages that cannot be safely skipped, and rushing any of them risks reinfection. You have to understand how the attacker got in, make sure they are actually gone, rebuild or clean affected systems, rotate credentials, validate your backups, restore data, and reconnect in controlled stages while watching closely. Skip the “make sure they’re gone” part and you can be encrypted again within days.
What drives the timeline
| Factor | Faster recovery | Slower recovery |
|---|---|---|
| Backups | Recent, isolated, tested and known-clean | Missing, encrypted, untested or compromised |
| Scope | One machine or a contained area | Servers, hypervisors and multiple sites |
| Identity | Microsoft 365 / Active Directory unaffected | Identity platform compromised, so trust must be rebuilt |
| Preparation | A tested plan and rehearsed roles | Writing the plan during the incident |
| Dwell time | Attacker caught quickly | Attacker present for weeks, so backups may be tainted |
| Rebuild vs restore | Clean restore from good backups | Systems must be rebuilt from scratch to be trusted |
A realistic sense of the phases
Every incident is different, so treat these as rough shapes rather than promises:
- First hours: contain the spread, protect backups, stop the bleeding. This is about control, not recovery.
- First days: understand the scope, confirm how the attacker got in, and make sure they are gone. Bring in specialists and your insurer. This investigation phase is what people underestimate.
- Days to weeks: rebuild or clean affected systems, rotate credentials and secrets, validate backups, and restore business-critical services first through a controlled recovery gate.
- Weeks to months: restore the rest, return fully to normal, and strengthen your defences so it cannot happen the same way again.
Most SMEs can get their minimum viable operation, the few things the business absolutely needs, running within days if they prepared. Full recovery, everything back to normal, commonly takes weeks. Where identity is compromised or backups are gone, it can take considerably longer.
The backup trap
The most common reason recovery drags on is backups that turn out to be unusable, or a backup that predates the visible encryption but already contains the attacker’s foothold. A backup is not automatically clean just because it was taken before the files locked up, because attackers often lurk for weeks before triggering the ransomware. Validating what you restore is part of the recovery, not an optional extra, and it is why testing your disaster recovery plan in advance pays off so heavily.
How to make recovery faster, before it happens
Recovery time is decided long before the attack. The businesses that recover in days rather than months are the ones that prepared:
- Recent, isolated backups that ransomware cannot reach, with tested restores.
- MFA and strong controls on identity, so the attacker cannot take the keys to everything.
- A tested incident plan with clear roles and authority.
- Good logging, so investigation is fast rather than guesswork.
- A known recovery order, so you are not deciding priorities under pressure.
The free Cyber Incident Response Toolkit helps you put these in place before you need them.
Would you recover in days, or months?
The honest answer depends on decisions you can make now: isolated backups, tested restores, protected identity and a rehearsed plan. We can review where you stand and give you a prioritised list to shorten your recovery long before you ever need it.
Frequently asked questions
Usually days to weeks, and sometimes months, rather than hours. Most prepared SMEs can get their most critical services running within days, with full recovery commonly taking weeks. Where identity is compromised or backups are missing or tainted, it can take considerably longer.
Because safe recovery has stages you cannot skip: understand how the attacker got in, confirm they are gone, rotate credentials, validate the backup, and reconnect in controlled stages. Restoring everything immediately, on top of an attacker you have not evicted, risks being encrypted again within days.
Not automatically. Attackers often lurk in a network for weeks before triggering the encryption, so a backup taken during that window may already contain their access. You need to validate what you restore, which is why testing your disaster recovery in advance matters so much.
Preparation, almost entirely. Recent, isolated, tested backups; strong controls and MFA on identity; a tested incident plan with clear roles; good logging; and a known recovery order. These decisions, made before an attack, are what separate a days-long recovery from a months-long one.
Related reading: the full Cyber Incident Response Plan guide, the ransomware response checklist, and the free Cyber Incident Response Toolkit.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


