Backups matter. Most San Antonio and Hill Country owners already know that. What catches people off guard is not whether a backup exists—it is whether anyone has practiced the decisions that come after something bad happens.
A ransomware tabletop drill is that practice—not a full restore of every server. In about ninety minutes, a few key people walk through detect → contain → restore decision → communications on your real systems. Coffee and honesty beat slides.
Why untested backups fail when you need them
A backup that has never been restored is a hope, not a plan. Common gaps show up only when someone tries:
- The backup ran, but the restore path needs credentials nobody has written down
- The copy lives on a machine that would also be locked in the same incident
- Files come back, but the line-of-business app will not start without extra steps
- Nobody agrees which systems come first—email, accounting, or the shop floor PC
None of that means you did something foolish. It means restore is a process, and processes need rehearsal. Tabletop drills surface those gaps without waiting for a real crisis on a Friday afternoon in July.
Plain talk on RTO and RPO
Two short ideas guide the conversation.
RTO (recovery time objective) is how long you can afford to be down before the business really hurts. For some shops, half a day of email is annoying. For others, two hours without the estimating system or point-of-sale is a lost week of jobs.
RPO (recovery point objective) is how much recent work you can stand to lose—measured as time since the last good backup. If you back up overnight and something hits at 3 p.m., everything entered that day may be gone unless you have a tighter copy.
You do not need perfect numbers. You need honest ones. In a tabletop, you ask: “If we lost today’s invoices, what happens?” and “Who decides we wipe and restore instead of trying to clean a machine?” Those answers become your RTO and RPO in plain language.
A simple 90-minute walkthrough
Here is a structure AEH often uses with small and mid-size teams. Adjust names to fit your shop.
1. Detect (about 15 minutes)
Someone notices something odd: encrypted files, a ransom note, strange outbound traffic, or a user who cannot open yesterday’s quotes. Who do they tell first—the owner, the office manager, or your IT partner? How do you decide it is ransomware and not a bad update?
Write the first phone call on a sticky note. If that person is out of town, write the backup name too.
2. Contain (about 20 minutes)
The goal is to stop spread without making recovery harder. Typical decisions:
- Which machines come off the network first?
- Do you disable VPN or remote access?
- Who talks to the internet provider or cloud admin if accounts look compromised?
- What do you not do (for example, paying or wiping before evidence and backups are checked)?
Containment is where panic invents shortcuts. A tabletop lets you pick the calm path ahead of time.
3. Restore decision (about 25 minutes)
Now the hard questions:
- Which systems must return first to take orders, pay people, or serve customers?
- Do you restore from last night’s backup, an older clean point, or a cloud copy?
- Who verifies the restore is good before you reconnect machines?
- How does that line up with the RTO and RPO you agreed on?
This is also where managed backup-and-disaster-recovery (BDR) earns its keep. If restores are tested on a schedule, you are not guessing whether last night’s job is usable.
4. Communications (about 20 minutes)
Decide in advance:
- What you tell staff (short, factual, no speculation)
- What you tell customers if email or order entry is down
- Who calls your IT partner, insurer, attorney, or bank if needed
- Who is not authorized to post on social media “from the company”
A one-page contact list beats a scramble through personal phones.
5. Debrief (about 10 minutes)
Capture what was unclear, what docs are missing, and one restore test to schedule. Then stop—value is follow-through, not a longer meeting.
How AEH schedules restore tests under managed BDR
For clients on managed backup and disaster recovery, AEH treats restore testing as part of the ongoing work—not a once-a-year surprise. That usually means:
- Confirming backups complete and are reachable off the primary machines
- Periodically restoring a sample (files, a VM, or a critical app) into a safe test area
- Checking restored data opens and steps match what the tabletop assumed
- Updating the runbook when servers, apps, or owners change
The tabletop and the restore test work together. The drill finds decision gaps. The restore test finds technical gaps. Neither replaces the other.
You already know downtime is expensive. What helps is knowing your people can make the next right call under pressure—without invented scare statistics.
Who should be in the room
Keep the group small: owner or GM, whoever runs the office day to day, someone who knows accounting or job software, and your IT contact. For a Hill Country shop-plus-office, that might be four people. For a multi-site San Antonio firm, add one voice for the other locations. Skip the all-hands theater—this is a working session.
Next step
If you want a calm dry run before you need a real one, AEH Solutions can help structure a ransomware tabletop aligned with how your backups restore—or pair it with a free IT assessment covering access, email, endpoints, and recovery.
Request your free IT assessment or reach out through the contact page. We will keep the conversation practical, local, and free of scare tactics.