The Recovery Orange Book

Purpose of the Recovery Orange Book

Mission

Provide a validated IR playbook for IT and Security teams to cleanly and quickly recover from ransomware, as well as prepare for any breaches and post-incident activity.

Vision

  • Provide a comprehensive and actionable IR playbook for IT and Security teams with strong emphasis on during- and post-breach actions for Investigations, communication, and cyber recovery.
  • Deliver concise runbooks, tips, techniques, and checklists that teams can adopt (and customize as needed) to execute under pressure and reuse for training, audits, and continuous improvement.
  • Create a repository of useful details of breaches and chronicling what was learned before, during, and after breaches so other organizations remain prepared and recover quickly and cleanly.

Who can benefit from this hub

IT, Security, Risk, Compliance professionals that deal with backups. SOC and IR analysts may also find it helpful to review against internal plans and troubleshooting in the event of a Ransomware declaration.

How to use this hub

While Ransomware and recovery activities have been going on for a long time, knowledge about recovery is hard to find in a centralized repository. Most of this knowledge still remains as tribal knowledge or with IR firms.

This hub provides in-depth information on investigations and cyber recovery, covering pre-incident and post-incident information as well as activities that will help the team with timely and clean recovery. Use this information, add to it, suggest edits, and help your organization and the broader community.