Återställning efter ransomware attacker: En studie av praktisk hantering och prioritering av verksamhetskritiska system
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Recovery After Ransomware Attacks : A Study of Practical Response and Prioritization of Critical Systems (English)
Abstract [en]
Ransomware attacks have become one of the most serious threats to organizations' information security, causing extensive operational disruptions and significant economic losses. When an attack occurs, it is rarely possible to restore all systems simultaneously, making it critical to prioritize which systems should be recovered first. Despite this, many organizations lack structured methods for making these prioritization decisions, particularly under the time pressure and uncertainty that characterizes an active incident.
The purpose is to identify the factors that influence the prioritization of IT systems during recovery after ransomware attacks, and to develop a conceptual scoring model that can serve as decision support for organizations in the recovery process. The study is based on a qualitative research strategy with semi-structured interviews conducted with professionals in IT security and incident management, as well as IT managers within the Swedish grocery retail sector.
The results show that organizations primarily identify critical IT systems based on their business processes rather than technical characteristics. The most influential factors in prioritization decisions are economic impact, time criticality in terms of Recovery Time Objective, and system dependencies. Systems such as point-of-sale systems and payment terminals are identified as the most critical within grocery retail, as their failure immediately halts core business operations.
Based on these findings, a conceptual scoring model was developed that evaluates IT systems across six weighted factors, generating a priority score on a scale from 0 to 100. The model was positively received by all respondents, who described it as a useful tool for structuring prioritization decisions, particularly in smaller and medium-sized organizations that lack established frameworks for incident response.
The study contributes both a concrete artifact in the form of the scoring model, and increased understanding of the practical factors that influence IT system prioritization during ransomware recovery within the grocery retail sector.
Abstract [sv]
Ransomware-attacker orsakar omfattande driftstopp och ekonomiska förluster för organisationer. Vid en attack är det sällan möjligt att återställa alla system samtidigt, vilket gör prioritering av IT-system avgörande. Trots detta saknar många organisationer strukturerade metoder för att fatta dessa beslut under tidspress.
Syftet med studien är att identifiera faktorer som påverkar prioritering av IT-system vid återställning efter ransomware-attacker samt att utveckla en konceptuell poängmodell som beslutsstöd. Studien bygger på kvalitativa semistrukturerade intervjuer med yrkesverksamma inom IT-säkerhet och IT-ansvariga inom den svenska dagligvaruhandeln.
Resultaten visar att organisationer identifierar kritiska system utifrån affärsprocesser snarare än tekniska egenskaper. De viktigaste prioriteringsfaktorerna är ekonomisk påverkan, Recovery Time Objective och systemberoenden. Kassasystem och betalterminaler identifieras som mest kritiska då ett avbrott omedelbart stoppar kärnverksamheten.
En poängmodell utvecklades som utvärderar IT-system utifrån sex viktade faktorer och genererar en prioriteringspoäng från 0 till 100. Modellen mottogs positivt av respondenterna och beskrevs som särskilt användbar för mindre organisationer som saknar etablerade ramverk för incidenthantering.
Studien bidrar med en konkret prioriteringsmodell samt ökad förståelse för praktiska faktorer vid ransomware-återställning inom dagligvaruhandeln.
Place, publisher, year, edition, pages
2026.
Keywords [en]
Ransomware, IT recovery, system prioritization, business continuity, disaster recovery, critical systems, decision support
National Category
Information Systems
Identifiers
URN: urn:nbn:se:du-54049OAI: oai:DiVA.org:du-54049DiVA, id: diva2:2078954
Subject / course
Microdata Analysis
2026-06-242026-06-24