Should systems be rebuilt immediately after ransomware?¶
Rebuilding may be operationally necessary, but it removes malware, memory, sessions, persistence, logs and staging evidence. Recovery urgency and evidential value need a proportionate plan.
Preserve by evidential function¶
Before rebuilding, consider memory and disk, notes, scripts, encrypted samples, authentication and remote-access records, network data, backup activity and security alerts. Not every device requires full imaging.
Preserve representative systems from materially different roles: initial access, staging, management deployment and encryption may each leave unique evidence. Device count alone is a poor selection rule.
Document recovery and verify wider containment¶
Record which systems were rebuilt, when, by whom, from which source and what evidence was lost. If service restoration must proceed immediately, retain alternative provider or central logs.
A clean operating-system image does not revoke compromised accounts, tokens, cloud permissions or management access elsewhere. Validate those routes independently and record the containment evidence, rather than treating rebuild success as incident closure.
Key takeaway
Preserve representative systems according to their incident role before rebuilding, and verify accounts and external access routes separately from device recovery.